CIS Controls v8
A prioritized set of 18 critical security controls that actually work. Unlike some frameworks that live in documentation, CIS Controls are designed to be implemented, measured, and maintained. They represent the most common attack patterns and the most effective defenses.
The Control Categories
Inventory, software management, data protection, secure configurations, account management, and access control. These six controls address the most common attack vectors.
Vulnerability management, audit logs, email and web protections, malware defenses, network defenses, and data loss prevention. These build on the basics.
Security awareness training, application security testing, incident response management, and penetration testing. These require organizational commitment.
The Controls (Implementation Group 1)
Implementation Group 1 represents the essential minimum for every organization. These 43 safeguards address the most widespread and dangerous cyber threats with controls that are achievable for organizations with limited resources.
What It Means in Practice
Common Gaps We See
- - Forgotten test servers still on the network
- - Personal devices connected to corporate WiFi
- - Cloud instances launched for projects and never documented
- - Legacy systems kept running 'temporarily' for five years
3 safeguards in this control
What It Means in Practice
Know what software is running on every asset. This includes operating systems, applications, drivers, and scripts. Unauthorized or unpatched software is a primary attack vector.
Common Gaps We See
- - Employees installing unapproved productivity tools
- - Old versions of software with known vulnerabilities
- - Browser plugins and extensions not tracked
- - Software installed for one project and forgotten
2 safeguards in this control
What It Means in Practice
Identify sensitive data, understand where it lives, and protect it through its entire lifecycle. This includes encryption, access controls, and proper disposal.
Common Gaps We See
- - Sensitive data in unprotected S3 buckets
- - PII in spreadsheets with broad sharing permissions
- - No data classification policy
- - Former employees with persistent access
9 safeguards in this control
What It Means in Practice
Harden systems by removing unnecessary services, protocols, and accounts. Default configurations are rarely secure. Change them before deployment.
Common Gaps We See
- - Default passwords on network equipment
- - Unnecessary services running (Telnet, FTP, RDP exposed)
- - Firewall rules that allow too much traffic
- - No baseline configuration for new systems
5 safeguards in this control
What It Means in Practice
Control who has access to what. This means managing accounts, privileges, and access rights throughout the employee lifecycle, from onboarding to departure.
Common Gaps We See
- - Shared accounts with no audit trail
- - Excessive privileges granted during projects and not revoked
- - No formal account review process
- - Service accounts with admin privileges
6 safeguards in this control
What It Means in Practice
Implement the principle of least privilege. Users should have only the access needed to do their job, nothing more. Review access rights regularly.
Common Gaps We See
- - Standing admin privileges instead of just-in-time access
- - No privileged access management system
- - Shared admin passwords across systems
- - Inadequate monitoring of privileged account usage
5 safeguards in this control
What It Means in Practice
Find weaknesses before attackers do. Regular vulnerability scanning and penetration testing help identify patches and configurations that need attention.
Common Gaps We See
- - Vulnerability scans run quarterly instead of continuously
- - Critical vulnerabilities not patched within 72 hours
- - No risk-based prioritization of findings
- - Remediation tracked in spreadsheets instead of a system
4 safeguards in this control
What It Means in Practice
Log collection and monitoring enables detection of anomalies and provides evidence for investigations. Logs should cover authentication, privileged actions, and critical system events.
Common Gaps We See
- - Logs retained for only 30 days
- - Critical systems not generating logs
- - No alerting on suspicious patterns
- - Logs not protected from tampering
6 safeguards in this control
What It Means in Practice
Email and web browsing are primary attack vectors. Implement filters, sandboxing, and protections to reduce the risk of phishing and drive-by downloads.
Common Gaps We See
- - No email filtering for malware
- - Outdated web browser on endpoints
- - No protection against malicious links
- - Users not trained to spot phishing
6 safeguards in this control
What It Means in Practice
Endpoint protection goes beyond traditional antivirus. Modern malware defenses include endpoint detection and response, application control, and regular signature updates.
Common Gaps We See
- - Signatures not updated regularly
- - No behavior-based detection
- - Endpoints not instrumented for EDR
- - Isolated malware found years later in backup
5 safeguards in this control
Ready to assess your CIS Controls implementation?
ABC of Cyber maps your current controls to the CIS framework and identifies the gaps most likely to hurt you.