CIS Critical Security Controls

The prioritized, free control catalogue that tells a resource-constrained organization what to secure first.

StandardCIS Controls v8.1
Applies toAny organization that needs a concrete, ordered to-do list for cyber defence; especially practical for small and mid-sized businesses.
When it appliesVoluntary; commonly adopted as an internal baseline, referenced in cyber insurance questionnaires and assessments.
Official textCIS Controls at CIS

Most security frameworks tell you how to think. The CIS Controls tell you what to do, in order, for free. That combination is why they have become the default technical baseline for organizations without a security department, and the quiet backbone of many consultants’ assessment templates.

The shape of the catalogue

Version 8.1 organizes defence into 18 controls, each broken into specific safeguards. The controls read like an honest priority list of how breaches actually happen: know your hardware and software (inventories come first for a reason), manage data, configure things securely, control accounts and admin privileges, patch, defend against malware, back up, log, secure email and browsers, train people, manage vendors, test. Nothing exotic leads the list; the catalogue’s core argument is that unglamorous hygiene, done thoroughly, defeats the large majority of real attacks.

Implementation Groups: the honest on-ramp

The best design decision in the Controls is the Implementation Group structure. IG1, a subset of the safeguards, is defined as essential cyber hygiene, deliberately scoped so a small business without dedicated security staff can achieve it. IG2 and IG3 layer on for organizations with more data, exposure, and resources. This is the antidote to framework paralysis: a 40-person integrator does not need a maturity model, it needs IG1, and IG1 is achievable. For consultants, “assess against IG1, remediate, then reassess” is an engagement a small client can afford and actually complete.

Why the security trade specifically should care

Two angles. As practitioners: integrators and alarm companies hold remote access into hundreds of client sites, which makes their own hygiene a supply chain issue; IG1 applied to your own shop is table stakes for credibly selling security. As advisors: the physical security assessment that ends with camera and door recommendations increasingly gets asked “and what about cyber?” The Controls, particularly IG1, give a physical-side consultant a defensible, sourced answer without inventing a framework. Pairing them with hardening the security systems themselves, per our network hardening guide, covers both directions.

What trips people up

Treating the 18 controls as a checkbox sprint instead of working the safeguards within the relevant IG. Skipping the inventories because they are boring, which quietly breaks everything downstream (you cannot patch or configure what you have not enumerated). And version drift in paperwork: questionnaires still reference v7 numbering, and control numbers moved in v8, so cite the version when you claim conformance.

How it fits

The Controls are a what-to-do catalogue. The NIST CSF is a how-to-organize framework, and CIS publishes mappings between them; many organizations run CSF for structure with CIS safeguards as the technical content. When certification proof is required, ISO 27001 is the certifiable layer on top.

Related guides

This is a plain-language guide, not the standard. It paraphrases and interprets; it does not reproduce the text. Requirements change between editions and provinces modify the codes that reference them. For design, installation, or compliance decisions, work from the current official text and your authority having jurisdiction.

References

  1. CIS Critical Security ControlsCenter for Internet Security · retrieved 2026-07-24
  2. CIS Controls Implementation GroupsCenter for Internet Security · retrieved 2026-07-24

Last updated 2026-07-24.