Skip to main content

Compliance

What are the CIS Controls?

CIS Controls are 18 prioritised security controls that give you a concrete order of work for IT security. See how to get started.

In short

CIS Controls (CIS Critical Security Controls) is a globally recognised framework of 18 prioritised security controls, published by the American non-profit Center for Internet Security.

The current version 8.1 contains 153 concrete measures, called safeguards, spread across controls such as hardware and software inventory, secure configuration, access management, backup and incident response. The framework's strength is its prioritisation: the three implementation groups IG1, IG2 and IG3 tell you precisely where to start, and IG1, with 56 foundational safeguards, is described as essential cyber hygiene that stops the vast majority of common attacks.

Where ISO 27001 describes a management system, CIS Controls is a technical to-do list, and the two complement each other well, just as the controls can be mapped to the NIS2 requirements. MI Support IT uses CIS Controls as a practical checklist in security reviews at Danish SMBs and implements the controls as ongoing operations.

Back to the glossary

What are the CIS Controls?

CIS Controls is a framework of 18 prioritised security controls from the Center for Internet Security, an American non-profit organisation. The current version, v8.1 from 2024, contains 153 concrete measures ("safeguards") spread across the 18 controls: from hardware and software inventory to logging, backup and incident response. (You occasionally see "the 18 controls" shortened to "version 18", but there is no version 18; the number refers to the number of controls.)

The framework's hallmark is that it is prioritised and measurable: it does not just tell you what good security is, but in what order you should build it.

The 18 controls: an overview

Broadly, the controls cover: 1) inventory of devices, 2) inventory of software, 3) data protection, 4) secure configuration, 5) account management, 6) access management, 7) continuous vulnerability management, 8) logging, 9) email and browser protection, 10) defence against malware, 11) data recovery, 12) network infrastructure, 13) network monitoring, 14) awareness training, 15) supplier management, 16) application security, 17) incident response and 18) penetration testing.

Note the order: the first controls are about knowing what you have. You cannot protect devices and systems you do not know about, and shadow IT is exactly where attacks often start.

IG1, IG2 and IG3: start in the right place

All 153 safeguards are divided into three implementation groups:

  • IG1: 56 foundational safeguards, which CIS calls essential cyber hygiene. Realistic for any SMB and designed to stop the most widespread attacks: phishing, ransomware and abuse of stolen passwords.
  • IG2: builds on top, for companies with more complex IT and sensitive data.
  • IG3: full depth for organisations with a high risk profile or regulatory requirements.

For most Danish SMBs the message is simple: implement IG1 first. It is a manageable, concrete list, and it moves more security per krone than any single product.

CIS Controls vs. ISO 27001 and NIS2

ISO 27001 describes a management system for information security: processes, roles and risk management. CIS Controls is the technical checklist that tells you what actually needs to be in place. They complement each other: many use CIS Controls as the practical content of an ISO or NIS2 programme, and CIS maintains official mappings to both. If you are covered by NIS2, CIS Controls is one of the fastest routes from legal requirements to action. See also IT compliance.

How MI Support IT can help

We use CIS Controls as the backbone of our security reviews: a structured assessment of where you stand on each control, and a prioritised plan for the gaps. We then implement and operate the controls as a fixed part of your IT security, from MFA and patching to backup with restore testing. Contact us if you want to be measured against IG1.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.