Back to Frameworks
CIS Controls
Center for Internet Security

CIS Controls v8

A prioritized set of 18 critical security controls that actually work. Unlike some frameworks that live in documentation, CIS Controls are designed to be implemented, measured, and maintained. They represent the most common attack patterns and the most effective defenses.

The Control Categories

1-6
Basic Controls
Essential controls every organization should implement

Inventory, software management, data protection, secure configurations, account management, and access control. These six controls address the most common attack vectors.

7-16
Foundational Controls
Technical controls that improve security posture

Vulnerability management, audit logs, email and web protections, malware defenses, network defenses, and data loss prevention. These build on the basics.

17-18
Organizational Controls
Processes and people-focused controls

Security awareness training, application security testing, incident response management, and penetration testing. These require organizational commitment.

The Controls (Implementation Group 1)

Implementation Group 1 represents the essential minimum for every organization. These 43 safeguards address the most widespread and dangerous cyber threats with controls that are achievable for organizations with limited resources.

1
Inventory of Enterprise Assets
Basic
Actively manage all enterprise assets connected to the infrastructure, including operating systems, applications, data, and cloud/virtualized assets.

What It Means in Practice

Common Gaps We See

  • - Forgotten test servers still on the network
  • - Personal devices connected to corporate WiFi
  • - Cloud instances launched for projects and never documented
  • - Legacy systems kept running 'temporarily' for five years

3 safeguards in this control

2
Inventory of Software Assets
Basic
Actively manage all software on the network so only authorized software is installed and executed.

What It Means in Practice

Know what software is running on every asset. This includes operating systems, applications, drivers, and scripts. Unauthorized or unpatched software is a primary attack vector.

Common Gaps We See

  • - Employees installing unapproved productivity tools
  • - Old versions of software with known vulnerabilities
  • - Browser plugins and extensions not tracked
  • - Software installed for one project and forgotten

2 safeguards in this control

3
Data Protection
Basic
Develop processes and technical controls to identify, classify, handle, retain, and dispose of data.

What It Means in Practice

Identify sensitive data, understand where it lives, and protect it through its entire lifecycle. This includes encryption, access controls, and proper disposal.

Common Gaps We See

  • - Sensitive data in unprotected S3 buckets
  • - PII in spreadsheets with broad sharing permissions
  • - No data classification policy
  • - Former employees with persistent access

9 safeguards in this control

4
Secure Configuration of Enterprise Assets
Basic
Establish and maintain secure configuration of enterprise assets and software.

What It Means in Practice

Harden systems by removing unnecessary services, protocols, and accounts. Default configurations are rarely secure. Change them before deployment.

Common Gaps We See

  • - Default passwords on network equipment
  • - Unnecessary services running (Telnet, FTP, RDP exposed)
  • - Firewall rules that allow too much traffic
  • - No baseline configuration for new systems

5 safeguards in this control

5
Account Management
Basic
Use processes and tools to assign and manage authorization to enterprise assets to legitimate users.

What It Means in Practice

Control who has access to what. This means managing accounts, privileges, and access rights throughout the employee lifecycle, from onboarding to departure.

Common Gaps We See

  • - Shared accounts with no audit trail
  • - Excessive privileges granted during projects and not revoked
  • - No formal account review process
  • - Service accounts with admin privileges

6 safeguards in this control

6
Access Control Management
Basic
Use processes and tools to create, assign, manage, and revoke access credentials and privileges.

What It Means in Practice

Implement the principle of least privilege. Users should have only the access needed to do their job, nothing more. Review access rights regularly.

Common Gaps We See

  • - Standing admin privileges instead of just-in-time access
  • - No privileged access management system
  • - Shared admin passwords across systems
  • - Inadequate monitoring of privileged account usage

5 safeguards in this control

7
Continuous Vulnerability Management
Foundational
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets.

What It Means in Practice

Find weaknesses before attackers do. Regular vulnerability scanning and penetration testing help identify patches and configurations that need attention.

Common Gaps We See

  • - Vulnerability scans run quarterly instead of continuously
  • - Critical vulnerabilities not patched within 72 hours
  • - No risk-based prioritization of findings
  • - Remediation tracked in spreadsheets instead of a system

4 safeguards in this control

8
Audit Log Management
Foundational
Collect, alert, review, and retain audit logs of events that could help detect or recover from attack.

What It Means in Practice

Log collection and monitoring enables detection of anomalies and provides evidence for investigations. Logs should cover authentication, privileged actions, and critical system events.

Common Gaps We See

  • - Logs retained for only 30 days
  • - Critical systems not generating logs
  • - No alerting on suspicious patterns
  • - Logs not protected from tampering

6 safeguards in this control

9
Email and Web Browser Protections
Foundational
Improve the protection and detection of attacks from email and web vectors.

What It Means in Practice

Email and web browsing are primary attack vectors. Implement filters, sandboxing, and protections to reduce the risk of phishing and drive-by downloads.

Common Gaps We See

  • - No email filtering for malware
  • - Outdated web browser on endpoints
  • - No protection against malicious links
  • - Users not trained to spot phishing

6 safeguards in this control

10
Malware Defenses
Foundational
Prevent or control the installation, spread, and execution of malicious code.

What It Means in Practice

Endpoint protection goes beyond traditional antivirus. Modern malware defenses include endpoint detection and response, application control, and regular signature updates.

Common Gaps We See

  • - Signatures not updated regularly
  • - No behavior-based detection
  • - Endpoints not instrumented for EDR
  • - Isolated malware found years later in backup

5 safeguards in this control

Ready to assess your CIS Controls implementation?

ABC of Cyber maps your current controls to the CIS framework and identifies the gaps most likely to hurt you.