What are the CIS Controls?
CIS Controls is a framework of 18 prioritised security controls from the Center for Internet Security, an American non-profit organisation. The current version, v8.1 from 2024, contains 153 concrete measures ("safeguards") spread across the 18 controls: from hardware and software inventory to logging, backup and incident response. (You occasionally see "the 18 controls" shortened to "version 18", but there is no version 18; the number refers to the number of controls.)
The framework's hallmark is that it is prioritised and measurable: it does not just tell you what good security is, but in what order you should build it.
The 18 controls: an overview
Broadly, the controls cover: 1) inventory of devices, 2) inventory of software, 3) data protection, 4) secure configuration, 5) account management, 6) access management, 7) continuous vulnerability management, 8) logging, 9) email and browser protection, 10) defence against malware, 11) data recovery, 12) network infrastructure, 13) network monitoring, 14) awareness training, 15) supplier management, 16) application security, 17) incident response and 18) penetration testing.
Note the order: the first controls are about knowing what you have. You cannot protect devices and systems you do not know about, and shadow IT is exactly where attacks often start.
IG1, IG2 and IG3: start in the right place
All 153 safeguards are divided into three implementation groups:
- IG1: 56 foundational safeguards, which CIS calls essential cyber hygiene. Realistic for any SMB and designed to stop the most widespread attacks: phishing, ransomware and abuse of stolen passwords.
- IG2: builds on top, for companies with more complex IT and sensitive data.
- IG3: full depth for organisations with a high risk profile or regulatory requirements.
For most Danish SMBs the message is simple: implement IG1 first. It is a manageable, concrete list, and it moves more security per krone than any single product.
CIS Controls vs. ISO 27001 and NIS2
ISO 27001 describes a management system for information security: processes, roles and risk management. CIS Controls is the technical checklist that tells you what actually needs to be in place. They complement each other: many use CIS Controls as the practical content of an ISO or NIS2 programme, and CIS maintains official mappings to both. If you are covered by NIS2, CIS Controls is one of the fastest routes from legal requirements to action. See also IT compliance.
How MI Support IT can help
We use CIS Controls as the backbone of our security reviews: a structured assessment of where you stand on each control, and a prioritised plan for the gaps. We then implement and operate the controls as a fixed part of your IT security, from MFA and patching to backup with restore testing. Contact us if you want to be measured against IG1.