home / guides / cis-critical-security-controls

Frameworks and controls · Center for Internet Security

CIS Critical Security Controls

A prioritized set of 18 controls, with implementation groups that scale to organization size.

Who this applies to

Organizations that want concrete, ordered technical safeguards and a way to measure progress.

What to know

  • Version 8 contains 18 controls, from inventory of assets and data protection to incident response and penetration testing.
  • Implementation Groups 1, 2, and 3 let a small organization start with essential cyber hygiene and add rigor as it grows.
  • The controls map to other frameworks, which helps when you answer to more than one standard.

What to do

  • Start with Implementation Group 1 and finish it before moving on.
  • Track coverage per safeguard so progress is visible.
  • Use the mappings to reuse evidence across audits.