Foundational Controls
Foundational Controls are a group of security measures within the CIS Critical Security Controls that build on top of the most basic protections to defend against more sophisticated, but still common, cyber attacks. They help organizations strengthen their defenses and protect networks and sensitive data beyond essential hygiene. In the CIS Controls version 7 structure, these were positioned as a distinct tier following the basic controls.
In the CIS Critical Security Controls (v7) taxonomy, Foundational Controls refer to the ten controls (Controls 7 through 16) that follow the six Basic Controls and precede the Organizational Controls. They are intended to address more advanced but still prevalent threats after essential cyber hygiene has been established through the Basic Controls. Practitioners should note that the CIS Controls were restructured in later versions, which reorganized safeguards and moved away from the Basic/Foundational/Organizational grouping; the Foundational designation is specific to the version 7 framework and should not be conflated with the Basic Controls (asset inventory, vulnerability management, etc.) or with organizational governance measures, which occupy separate tiers.
Why it matters
Foundational Controls matter because basic cyber hygiene alone does not stop the more sophisticated attacks that organizations routinely face. Once an organization has established essential protections through the Basic Controls, the Foundational Controls in the CIS Critical Security Controls (v7) provide the next layer of defense, helping to strengthen networks and protect sensitive data against threats that are more advanced but still common. This tiered progression reflects a practical reality: security maturity is built in stages, and skipping ahead to complex measures before basic hygiene is in place tends to produce gaps rather than resilience.
For security leaders, the value of the Foundational designation is largely one of sequencing and prioritization. It signals which safeguards to address after the fundamentals but before organizational governance measures, giving resource-constrained teams a defensible order of operations. This is particularly useful in engagements where an organization has limited maturity and needs a structured path rather than an undifferentiated list of every possible control.
Practitioners should be careful, however, because the Foundational designation is specific to CIS Controls version 7. Later versions of the CIS Controls were restructured and moved away from the Basic, Foundational, and Organizational grouping. Treating the Foundational tier as a current, universal category can mislead teams about the scope and priority of these controls, so any use of the term should be anchored to the version 7 framework it belongs to.
Who it's relevant to
Inside Foundational Controls
Common questions
Answers to the questions practitioners most commonly ask about Foundational Controls.