Skip to main content
Category: Risk Management

Foundational Controls

Also known as: Foundational CIS Controls, Foundational CIS Critical Security Controls
Simply put

Foundational Controls are a group of security measures within the CIS Critical Security Controls that build on top of the most basic protections to defend against more sophisticated, but still common, cyber attacks. They help organizations strengthen their defenses and protect networks and sensitive data beyond essential hygiene. In the CIS Controls version 7 structure, these were positioned as a distinct tier following the basic controls.

Formal definition

In the CIS Critical Security Controls (v7) taxonomy, Foundational Controls refer to the ten controls (Controls 7 through 16) that follow the six Basic Controls and precede the Organizational Controls. They are intended to address more advanced but still prevalent threats after essential cyber hygiene has been established through the Basic Controls. Practitioners should note that the CIS Controls were restructured in later versions, which reorganized safeguards and moved away from the Basic/Foundational/Organizational grouping; the Foundational designation is specific to the version 7 framework and should not be conflated with the Basic Controls (asset inventory, vulnerability management, etc.) or with organizational governance measures, which occupy separate tiers.

Why it matters

Foundational Controls matter because basic cyber hygiene alone does not stop the more sophisticated attacks that organizations routinely face. Once an organization has established essential protections through the Basic Controls, the Foundational Controls in the CIS Critical Security Controls (v7) provide the next layer of defense, helping to strengthen networks and protect sensitive data against threats that are more advanced but still common. This tiered progression reflects a practical reality: security maturity is built in stages, and skipping ahead to complex measures before basic hygiene is in place tends to produce gaps rather than resilience.

For security leaders, the value of the Foundational designation is largely one of sequencing and prioritization. It signals which safeguards to address after the fundamentals but before organizational governance measures, giving resource-constrained teams a defensible order of operations. This is particularly useful in engagements where an organization has limited maturity and needs a structured path rather than an undifferentiated list of every possible control.

Practitioners should be careful, however, because the Foundational designation is specific to CIS Controls version 7. Later versions of the CIS Controls were restructured and moved away from the Basic, Foundational, and Organizational grouping. Treating the Foundational tier as a current, universal category can mislead teams about the scope and priority of these controls, so any use of the term should be anchored to the version 7 framework it belongs to.

Who it's relevant to

Virtual and Fractional CISOs
Security leaders advising organizations with limited maturity can use the Foundational Controls as a sequencing tool, helping clients prioritize the next layer of defenses after basic hygiene is established. In these engagements, the vCISO typically directs and advises on which controls to pursue, while accountability for implementation and security decisions remains with the client organization. When referencing this tier, they should confirm whether the client is working from CIS Controls v7 or a later restructured version.
Organizations Building Security Programs
Enterprises that have implemented essential cyber hygiene and are ready to strengthen their networks and protect sensitive data against more sophisticated attacks are the primary intended audience for these controls. The value depends on organizational maturity: Foundational Controls presuppose that the Basic Controls are already in place, so they are most useful to teams that have moved past initial hygiene and need a structured next step.
Compliance and Risk Practitioners
Those mapping their organization's controls to the CIS Critical Security Controls need to distinguish the Foundational tier from the Basic and Organizational tiers to avoid misclassifying safeguards. They should also recognize that the Foundational designation is specific to version 7 and that later versions reorganized the safeguards, which affects how a program is documented and communicated to auditors and stakeholders.

Inside Foundational Controls

Baseline Security Measures
Foundational controls, as the term is used generically in security leadership contexts, refer to the essential, entry-level safeguards an organization is expected to have in place before pursuing more advanced capabilities. Note that the specific meaning varies by source: in the CIS Controls taxonomy 'Foundational' is a formally defined category distinct from 'Basic' and 'Organizational' controls, so practitioners should confirm which framework and version a given reference intends.
Terminology Caution
The phrase 'foundational controls' is frequently used loosely to mean 'the basics,' but this generic usage does not map to the CIS Controls' formal 'Foundational' category. In earlier CIS Controls versions, the safeguards commonly described as fundamental hygiene (such as asset inventory and vulnerability management) fall under the 'Basic' category, while the 'Foundational' designation covers a separate, more advanced set. Entries and engagements should state explicitly which definition is in use to avoid misclassifying safeguards.
Governance Positioning
Within a virtual CISO engagement, establishing or reviewing baseline controls is typically framed as a governance and risk-prioritization exercise rather than hands-on implementation. A vCISO generally advises on which controls to prioritize, sequences them against organizational risk, and directs internal or third-party teams to implement them; the vCISO does not usually administer the underlying tools or perform operational tasks unless explicitly contracted.
Maturity Dependency
The value and applicability of any set of baseline controls depend heavily on organizational maturity. What constitutes a reasonable starting point for a small, low-maturity organization may differ substantially from a larger regulated entity, so a vCISO typically tailors the baseline to the client's risk profile, resources, and stakeholder cooperation.

Common questions

Answers to the questions practitioners most commonly ask about Foundational Controls.

Are foundational controls the same as the CIS 'Foundational' control category?
Not necessarily, and this is a common point of confusion. The term 'foundational controls' is often used generically to mean the baseline security measures an organization should establish first. This informal usage does not map cleanly to any specific tier in a published framework, and it should not be assumed to correspond to a particular numbered control group. When a provider or document uses the phrase, it is worth confirming whether they mean a general baseline or a defined category within a specific version of a named framework, since the meaning may vary by provider and by the framework edition being referenced.
Does implementing foundational controls make an organization compliant or certified?
No. Establishing foundational controls typically supports readiness and reduces risk, but implementation on its own does not confer compliance with a regulation or certification against a standard. Compliance and certification generally require formal assessment, evidence, and in some cases an accredited audit, depending on the regime involved. A virtual CISO can help direct and prioritize control work that supports these goals, but describing foundational controls as guaranteeing a compliant or certified outcome would overstate what the work delivers.
How should an organization decide which foundational controls to implement first?
Prioritization usually depends on the organization's risk profile, existing maturity, and the assets and data most critical to the business. In many engagements a virtual CISO helps sequence work by identifying where the greatest exposure exists and where quick, sustainable improvements are feasible. The right ordering can vary by organization, so a blanket sequence should be treated with caution. The value of this exercise depends heavily on stakeholder cooperation and accurate visibility into the current environment.
Who is accountable for foundational controls once a virtual CISO helps implement them?
The virtual CISO typically advises on, directs, and helps establish these controls, but organizational and legal accountability for security decisions generally remains with the client organization and its officers unless a contract specifies otherwise. Operational ownership of the controls after implementation usually rests with internal teams or contracted providers. It is important to define, in scope discussions, who maintains each control over time so that responsibility does not lapse after the initial engagement work.
Does a virtual CISO operate foundational controls day to day?
Generally no. A virtual CISO provides strategy, governance, and program-level guidance, and typically does not perform hands-on operational tasks such as ongoing monitoring, tool administration, or routine maintenance unless those activities are explicitly contracted. Foundational controls often require sustained operational effort, so organizations should plan for who will run and maintain them, whether internal staff, a managed provider, or another party, rather than assuming the vCISO fills that role.
What determines whether foundational control work delivers lasting value?
Sustained value tends to depend on organizational maturity, defined scope, access to relevant stakeholders, and the client's willingness to maintain controls after they are established. Foundational controls that are implemented but not operated, updated, or governed over time can degrade in effectiveness. Clear ownership, a defined maintenance approach, and alignment between security guidance and business priorities are typically what allow the initial work to remain useful beyond the engagement.

Common misconceptions

'Foundational controls' and 'basic controls' are the same thing in every framework.
This is not universally true. In the CIS Controls taxonomy, 'Basic,' 'Foundational,' and 'Organizational' are distinct categories, and the safeguards often assumed to be 'foundational' in casual conversation may actually be classified as 'Basic.' Practitioners should specify the framework and version being referenced rather than treating the label as interchangeable across sources.
Implementing foundational or baseline controls guarantees compliance or prevents breaches.
Baseline controls reduce exposure and support readiness for frameworks such as NIST CSF, ISO 27001, SOC 2, or PCI DSS, but they do not by themselves confer certification or guarantee that a breach will not occur. Compliance and certification depend on formal assessment against a specific standard, and outcomes may vary by provider, scope, and the client's own execution.
A virtual CISO personally deploys and operates an organization's baseline controls.
A vCISO typically advises on, prioritizes, and directs the establishment of baseline controls at a strategic and governance level. Hands-on deployment, tool administration, and ongoing operation are generally out of scope and remain with internal staff or contracted providers unless the engagement explicitly includes them. Accountability for security decisions typically remains with the client organization and its officers.

Best practices

Before using the term 'foundational controls' in scoping documents or reports, confirm and state which framework and version you mean, since the label carries a specific formal meaning in the CIS Controls that differs from casual 'the basics' usage.
Prioritize and sequence baseline controls against the client's actual risk profile and maturity rather than applying a generic checklist, and document the rationale for the chosen order.
Define clearly in the engagement scope what the vCISO will advise and direct versus what the client or a third party will implement and operate, so responsibility and accountability boundaries are unambiguous.
Frame baseline controls as supporting readiness for relevant frameworks or regulations, and avoid representing their implementation as a guarantee of certification or breach prevention.
Use qualified, verifiable language when describing controls to stakeholders, distinguishing what a given control category actually covers from common assumptions about it.
Reassess the baseline periodically as organizational maturity, stakeholder cooperation, and risk change, since a control set appropriate at one stage may need to expand or shift over time.