Skip to main content
Category: Compliance Frameworks & Standards

CIS Controls

Also known as: CIS Controls, CIS Critical Security Controls, Critical Security Controls, CIS Controls v8, CIS CSC
Simply put

The CIS Controls are a prioritized set of recommended security best practices that organizations can use to strengthen their defenses against common cyber attacks. They focus on foundational security hygiene, covering areas such as protecting devices, data, identities, and infrastructure. They are published by the Center for Internet Security and are often used as a practical starting point for building a security program.

Formal definition

The CIS Critical Security Controls (formerly known as the Critical Security Controls) are a prescriptive, prioritized, and simplified set of cyber defense best practices maintained by the Center for Internet Security. The current major release is v8, with an incremental v8.1 update; practitioners should confirm the specific version referenced in any given engagement, as control groupings and mappings may vary by release. The Controls address domains including identity, data, devices, and infrastructure, and can be mapped to other frameworks and standards. A virtual CISO may use the CIS Controls to assess maturity, prioritize remediation, and structure a security roadmap, but adopting the Controls supports improved security posture rather than guaranteeing breach prevention or compliance with any specific regulation; realized value depends on organizational maturity, scope, and consistent implementation.

Why it matters

The CIS Controls give organizations a prioritized, opinionated answer to a question that overwhelms many security programs: where to start. Rather than presenting an exhaustive checklist, the Controls concentrate on foundational security hygiene, protecting devices, data, identities, and infrastructure, so that limited resources are directed at the measures most likely to reduce exposure to common attacks. For organizations without a mature security function, this prioritization is often more valuable than the individual controls themselves, because it establishes a defensible sequence for building defenses.

The Controls also matter because they are practical and mappable. Published by the Center for Internet Security, they can be aligned to other frameworks and standards, which allows a security leader to use a single implementation effort to inform multiple governance and readiness conversations. This makes the CIS Controls a useful shared language between technical teams and executives, translating security activity into a structured roadmap that business stakeholders can follow.

It is important to be precise about what adopting the Controls does and does not do. Implementing the CIS Controls supports an improved security posture and essential cyber hygiene, but it does not guarantee breach prevention or compliance with any specific regulation. Realized value depends on organizational maturity, defined scope, and consistent, ongoing implementation rather than a one-time adoption exercise.

Who it's relevant to

Organizations building a security program from an early stage
Companies without an established security function often struggle to prioritize among competing needs. The CIS Controls offer a practical starting point by concentrating on foundational hygiene, giving these organizations a defensible sequence for their first investments. The benefit depends heavily on organizational maturity and consistent follow-through rather than on adoption alone.
Virtual and fractional CISOs
A virtual CISO may use the CIS Controls to assess maturity, prioritize remediation, and structure a security roadmap at the governance and strategy level. Because control groupings and mappings vary by version, a vCISO should confirm whether an engagement references v8 or the v8.1 update, including the added Governance function. The vCISO advises and directs; operational implementation typically remains with the client's teams unless separately scoped.
Executives and boards seeking a shared risk language
Because the Controls translate security activity into a prioritized, structured roadmap, they help non-technical leaders understand where the organization stands and what comes next. This supports security's role as a business risk and governance function rather than a purely technical one, while making clear that accountability for decisions rests with the organization's officers.
Teams pursuing framework alignment or readiness
Organizations that need to align with or map to other frameworks and standards can use the CIS Controls as a common implementation base, since they are designed to be mapped elsewhere. It is important to distinguish supporting readiness from asserting certification, implementing the Controls does not by itself guarantee compliance with any specific regulation.

Inside CIS Controls

Prioritized Safeguards
The CIS Controls organize security actions into a set of controls, each broken down into specific safeguards (formerly called sub-controls). These are prioritized to help organizations focus on high-impact defensive measures first rather than attempting everything at once.
Implementation Groups (IGs)
The framework defines Implementation Groups (IG1, IG2, IG3) that tier safeguards by organizational size, resources, and risk profile. IG1 represents basic cyber hygiene for smaller or less-resourced organizations, while IG2 and IG3 add safeguards for organizations with greater complexity and risk exposure.
Version 8 Restructuring
CIS Controls version 8 consolidated the prior control set and reorganized safeguards around activities and tasks rather than around who manages the device. The incremental v8.1 update (2024) refined the controls and introduced alignment with a Governance security function, reflecting the growing emphasis on governance alongside technical safeguards.
Security Functions Alignment
The v8.1 update maps safeguards to security functions consistent with broader frameworks, adding Governance as a function alongside operational and technical activities. This helps organizations connect the controls to governance and oversight responsibilities, not only technical execution.
Framework Mappings
The CIS Controls are commonly mapped to other frameworks and standards such as NIST CSF and ISO 27001, allowing organizations to use the controls as an implementation-focused layer that supports readiness efforts without itself constituting a certification.
Governance and Advisory Relevance
For security leadership engagements, the CIS Controls serve as a prioritized reference a virtual CISO or fractional CISO may use to advise on program development, gap assessment, and roadmap prioritization. The controls describe what to do; accountability for implementing and operating them typically remains with the client organization.

Common questions

Answers to the questions practitioners most commonly ask about CIS Controls.

Does adopting the CIS Controls mean a virtual CISO can guarantee my organization won't be breached?
No. The CIS Controls are a prioritized set of safeguards intended to reduce the likelihood and impact of common attacks, but no control framework and no vCISO engagement can guarantee breach prevention. A virtual CISO typically uses the CIS Controls to help prioritize risk-reduction efforts and improve defensive posture, while accountability for security decisions and residual risk generally remains with the client organization and its officers. Outcomes depend heavily on organizational maturity, consistent implementation, and ongoing operational execution that often falls outside a strategic advisory engagement.
Are the CIS Controls the same as a compliance framework like ISO 27001 or SOC 2 that produces a certification?
Not exactly. The CIS Controls are a prescriptive, prioritized set of technical and process safeguards, whereas frameworks such as ISO 27001 or attestations such as SOC 2 involve formal certification or audit processes. Implementing the CIS Controls can support readiness for those efforts and often maps to other frameworks, but adopting them does not by itself produce a certification or attestation. A virtual CISO may use the CIS Controls to build a foundation and to inform broader compliance work, while being careful to distinguish supporting readiness from asserting certified compliance.
How does a virtual CISO typically use the Implementation Groups (IG1, IG2, IG3) when applying the CIS Controls?
The Implementation Groups are tiers that help scope which safeguards are most appropriate based on an organization's resources, risk profile, and data sensitivity. In many engagements, a virtual CISO assesses the client's maturity and risk exposure to recommend a starting Implementation Group, often beginning with foundational cyber hygiene safeguards before progressing to more advanced ones. The vCISO generally advises on and prioritizes these safeguards rather than performing the hands-on configuration or tooling work, which typically falls to internal teams or contracted operational providers unless explicitly scoped.
Where should we start if we're adopting the CIS Controls for the first time?
A common approach is to begin with an assessment of your current state against the safeguards, then focus first on foundational cyber hygiene, which is often associated with the lowest Implementation Group. A virtual CISO can help translate the results into a prioritized roadmap aligned to your risk tolerance and business objectives. The value of this exercise depends on access to stakeholders, accurate asset and data inventories, and client cooperation, since implementation is an operational effort that typically extends beyond the advisory role.
Does implementing the CIS Controls require us to replace our security tools or hire a full security team?
Not necessarily. The CIS Controls describe safeguards and outcomes rather than mandating specific products, so many can be addressed with existing tools, configuration changes, and process improvements. It is also a mistake to assume that adopting the Controls, or engaging a virtual CISO, replaces an entire security team; a vCISO provides strategy, governance, and prioritization, while ongoing operational tasks such as monitoring and tool administration typically require internal staff or contracted providers. The appropriate mix varies by organizational size, maturity, and defined scope.
Can a virtual CISO handle the day-to-day implementation and monitoring of the CIS Controls for us?
Generally not as part of a standard advisory engagement. A virtual CISO typically directs and advises on which safeguards to implement and in what order, but hands-on operational work such as deploying tooling, ongoing monitoring, and remediation execution is usually out of scope unless explicitly contracted. Conflating a vCISO with a managed security service provider is a common mistake; the vCISO focuses on governance and executive-level guidance, while operational delivery is often handled by internal teams or separate service providers coordinated by the vCISO.

Common misconceptions

Implementing the CIS Controls guarantees compliance with regulations or achieves certification against standards like ISO 27001, SOC 2, or PCI DSS.
The CIS Controls can support readiness and are often mapped to other frameworks, but adopting them does not by itself certify or guarantee compliance with any regulation or standard. Compliance and certification involve separate audit, attestation, or assessment processes. A virtual CISO engagement referencing the controls typically supports readiness rather than asserting a compliant or certified state.
The CIS Controls are a purely technical checklist that a security team implements without leadership or governance involvement.
Security leadership is a governance and business risk function, not only a technical one. The v8.1 update's alignment with a Governance security function reflects that oversight, prioritization, and accountability matter as much as technical execution. In many engagements, a virtual CISO advises on governance and prioritization while the client organization retains accountability for decisions and operational implementation.
A virtual CISO who recommends the CIS Controls will also operate them, such as administering tools or monitoring safeguards day to day.
A virtual CISO generally provides strategy, governance, and program guidance and does not typically perform hands-on operational tasks such as tool administration or continuous monitoring unless explicitly contracted. The CIS Controls describe defensive activities, but who executes and operates them depends on the defined engagement scope and the organization's own resources.

Best practices

Confirm you are working from the current release, including the incremental v8.1 update (2024), and account for its refinements and the addition of the Governance security function when building or reviewing a security program.
Use Implementation Groups (IG1, IG2, IG3) to right-size adoption to the organization's size, resources, and risk profile rather than attempting all safeguards at once, starting with IG1 basic cyber hygiene where appropriate.
Treat framework mappings to NIST CSF and ISO 27001 as a way to support readiness efforts, and clearly distinguish between supporting readiness and asserting certification or guaranteed compliance in client communications.
Define engagement scope explicitly, separating advisory and governance guidance a virtual CISO provides from any hands-on operational execution of safeguards, which typically remains with the client's team unless contracted otherwise.
Prioritize safeguards based on the organization's risk profile and maturity, since the value of adopting the controls depends on organizational maturity, client cooperation, and access to relevant stakeholders and data.
Reinforce that accountability for security decisions and their implementation generally remains with the client organization and its officers, with the virtual CISO advising and directing rather than assuming legal or regulatory accountability.