CIS Controls Logo

CIS Controls: Enhancing Cybersecurity Posture

The Center for Internet Security (CIS) Controls is a set of best practices designed to help organizations improve their cybersecurity posture. It provides a prioritized framework of actions that organizations can implement to mitigate the most common cyber threats.

History of CIS Controls

The CIS Controls were developed in 2008 by a group of cybersecurity experts and practitioners who recognized the need for a standardized approach to cybersecurity. Originally known as the SANS Top 20 Critical Security Controls, the framework was rebranded as the CIS Controls in 2015. Over the years, the controls have been updated and refined to address the evolving landscape of cybersecurity threats. The latest version, CIS Controls Version 8, was released in May 2021, reflecting the current state of cybersecurity and the latest threats organizations face.

Key Features

The CIS Controls consist of a set of 18 controls that are categorized into three implementation groups (IGs) based on the resources and capabilities of an organization:

  1. Basic Controls (IG1): These are fundamental security controls that all organizations should implement to defend against the most common cyber attacks.

    • Inventory of Authorized and Unauthorized Devices
    • Inventory of Authorized and Unauthorized Software
    • Secure Configurations for Hardware and Software on Mobile Devices, Laptops, Workstations, and Servers
    • Continuous Vulnerability Management
    • Controlled Use of Administrative Privileges
  2. Foundational Controls (IG2): These controls build upon the basic controls and are suitable for organizations with more resources.

    • Email and Web Browser Protections
    • Malware Defenses
    • Application Software Security
    • Incident Response Management
    • Penetration Tests and Red Team Exercises
  3. Organizational Controls (IG3): These are advanced controls designed for organizations with a mature cybersecurity posture.

    • Security Awareness and Skills Training
    • Application Security Testing
    • Data Recovery Capabilities
    • Security Incident Response
    • Security Management and Governance

Common Use Cases

CIS Controls are widely used across various sectors, including government, healthcare, finance, and education. Here are some common use cases:

Conclusion

The CIS Controls represent a practical and actionable framework for organizations looking to enhance their cybersecurity efforts. By implementing these controls, organizations can better protect themselves against cyber threats, reduce vulnerabilities, and improve their overall security posture.

Supported File Formats

The CIS Controls framework and associated documents are typically available in various formats: - PDF - HTML - DOCX - Markdown

Supported File Formats