Skip to content

03 CIS Controls v8

The CIS Critical Security Controls v8 provide a prioritized set of practical cybersecurity safeguards organizations can implement to reduce common and significant cyber risks.

Where frameworks such as NIST CSF help organizations structure cybersecurity outcomes and NIST RMF provides a formal risk-management lifecycle, the CIS Controls focus heavily on:

What Security
Safeguards Should
We Actually Implement?

The framework organizes cybersecurity practices into 18 Controls covering areas such as:

Assets
Software
Data
Configuration
Accounts
Access
Vulnerabilities
Logging
Email
Malware
Recovery
Networks
Monitoring
Awareness
Service Providers
Applications
Incident Response
Penetration Testing

A major feature of CIS Controls is the use of:

Implementation Groups
IG1
IG2
IG3

These help organizations prioritize safeguards according to their cybersecurity risk, resources, complexity, and operational requirements.

By the end of this lesson, you will be able to:

  • Explain the purpose of CIS Controls v8.

  • understand the structure of the 18 CIS Controls.

  • understand CIS Safeguards.

  • understand Implementation Groups.

  • differentiate IG1, IG2, and IG3.

  • understand how organizations prioritize CIS safeguards.

  • understand enterprise asset management.

  • understand software asset management.

  • understand data protection.

  • understand secure configuration.

  • understand account management.

  • understand access-control management.

  • understand vulnerability management.

  • understand audit-log management.

  • understand email and web protections.

  • understand malware defenses.

  • understand data recovery.

  • understand network infrastructure management.

  • understand network monitoring and defense.

  • understand security awareness.

  • understand service-provider management.

  • understand application software security.

  • understand incident-response management.

  • understand penetration testing.

  • perform a CIS Controls gap assessment.

  • map CIS safeguards to enterprise controls.

  • build a CIS implementation roadmap.

  • develop CIS-based security metrics.

  • integrate CIS Controls into enterprise GRC.

CIS Controls are a prioritized set of cybersecurity practices designed to help organizations defend against common cyber threats.

Conceptually:

Cyber Threats
Security Risks
CIS Controls
Safeguards
Implementation
Risk Reduction

The emphasis is strongly operational.

Organizations can use the Controls to determine:

What Should
We Protect?
What Safeguards
Should Exist?
What Should
We Implement First?
How Can We
Measure Progress?

CIS Controls v8 contains:

18 Controls
Safeguards
Implementation Groups

A Control represents a major cybersecurity capability.

A Safeguard represents a specific recommended security action.

The Controls are:

01 Inventory and Control
of Enterprise Assets
02 Inventory and Control
of Software Assets
03 Data Protection
04 Secure Configuration
of Enterprise Assets
and Software
05 Account Management
06 Access Control Management
07 Continuous Vulnerability
Management
08 Audit Log Management
09 Email and Web Browser
Protections
10 Malware Defenses
11 Data Recovery
12 Network Infrastructure
Management
13 Network Monitoring
and Defense
14 Security Awareness
and Skills Training
15 Service Provider
Management
16 Application Software
Security
17 Incident Response
Management
18 Penetration Testing

Together they provide a broad operational cybersecurity baseline.

Each Control contains specific Safeguards.

For example:

Control
Account Management
Safeguards
Account Inventory
Dormant Account Handling
Administrator Account Management
Service Account Management

The Controls tell you the security area.

The Safeguards describe what should be implemented.

Organizations rarely have unlimited:

Budget
People
Technology
Time

Trying to implement everything simultaneously often results in:

Too Many Projects
Weak Prioritization
Slow Implementation
Limited Risk Reduction

CIS addresses this using Implementation Groups.

CIS Controls use three Implementation Groups:

IG1
IG2
IG3

They provide progressive levels of cybersecurity safeguards.

IG1 represents foundational cybersecurity safeguards.

It is intended to establish essential cyber hygiene.

Think:

Know Your Assets
Know Your Software
Protect Accounts
Secure Systems
Patch Vulnerabilities
Protect Data
Maintain Backups

IG1 is the starting point.

An organization may have:

Small IT Team
Limited Security Staff
Standard Business Systems
Cloud SaaS
Moderate Data Sensitivity

Its first objective should be establishing strong fundamental safeguards.

IG2 builds on IG1.

Organizations in this group typically have:

Multiple Departments
More Complex Infrastructure
Dedicated IT / Security Roles
Sensitive Information
Regulatory Requirements
Greater Operational Dependencies

IG2 requires broader and more formal security capabilities.

IG3 represents organizations requiring stronger protections against sophisticated threats.

Examples may include:

Critical Infrastructure
Large Financial Institutions
Defense Organizations
High-Value Technology Companies
Highly Sensitive Environments

These organizations may face:

Targeted Attacks
Advanced Threat Actors
Significant Regulatory Exposure
Large-Scale Business Impact

Conceptually:

IG1
Essential Cyber Hygiene
IG2
Expanded Safeguards
IG3
Advanced Safeguards

IG2 includes IG1 expectations.

IG3 builds further upon them.

Do not choose IG3 simply because:

IG3
Sounds Better

Consider:

Business Risk
Data Sensitivity
Threat Environment
Organization Size
Operational Complexity
Regulatory Requirements

13. Control 1 — Inventory and Control of Enterprise Assets

Section titled “13. Control 1 — Inventory and Control of Enterprise Assets”

Organizations must understand which assets exist.

Examples:

Servers
Endpoints
Laptops
Mobile Devices
Network Devices
Virtual Machines
Cloud Resources
IoT Devices

You cannot reliably:

Secure
Patch
Monitor
Assess
Recover

an asset you do not know exists.

Unknown Asset
Unknown Vulnerability
Unknown Exposure

A useful inventory may contain:

Asset ID
Asset Name
Type
Owner
Location
IP Address
Business Service
Criticality
Status

Organizations should detect:

Unknown Devices
Unauthorized Servers
Unmanaged Cloud Resources
Shadow IT

and establish processes for handling them.

Every important asset should have:

Business Owner
Technical Owner

where appropriate.

Classify assets according to business importance.

Example:

Tier 1
Mission Critical
Tier 2
Business Critical
Tier 3
Important
Tier 4
Standard

19. Control 2 — Inventory and Control of Software Assets

Section titled “19. Control 2 — Inventory and Control of Software Assets”

Organizations must understand what software is installed and authorized.

Examples:

Operating Systems
Applications
Agents
Browser Extensions
Libraries
Cloud Software
SaaS Applications

Maintain:

Software
Version
Publisher
Asset
Owner
Approval
Support Status

Identify:

Unapproved Software
Pirated Software
Unsupported Software
End-of-Life Software
High-Risk Applications

Without software visibility:

Vulnerability
Affected Software Unknown
Exposure Unknown
Remediation Delayed

Organizations should understand and protect important information throughout its lifecycle.

Create
Store
Process
Transmit
Archive
Destroy

Identify important data such as:

Customer Data
Employee Data
Payment Data
Financial Data
Health Data
Intellectual Property
Authentication Data

Example:

Public
Internal
Confidential
Restricted

Potential safeguards include:

Encryption
Access Control
Data Loss Prevention
Retention
Secure Disposal
Data Segmentation
Backup

Protection should follow classification.

Example:

Restricted Data
Encryption
Restricted Access
Monitoring
Controlled Retention

28. Control 4 — Secure Configuration of Enterprise Assets and Software

Section titled “28. Control 4 — Secure Configuration of Enterprise Assets and Software”

Default configurations are rarely sufficient for enterprise security.

Organizations should establish:

Secure Baselines

for:

Endpoints
Servers
Network Devices
Cloud Platforms
Applications
Mobile Devices

Example:

Windows Server
Security Baseline

may define:

Password Settings
Logging
Firewall
Services
Encryption
Remote Access

Over time:

Secure Baseline
Changes
Configuration Drift
Security Weakness

Organizations should detect and remediate drift.

Use:

Baseline
Deploy
Monitor
Detect Drift
Remediate

Organizations must manage accounts throughout their lifecycle.

Create
Modify
Review
Disable
Delete

Inventory:

User Accounts
Administrator Accounts
Service Accounts
Shared Accounts
Application Accounts
Emergency Accounts

Dormant accounts create unnecessary attack paths.

Example:

Employee Leaves
Account Remains Active
Credential Compromise
Unauthorized Access

Maintain:

Account
Identity
Owner
Type
Privilege
Status
Last Used

Service accounts require particular attention because they may have:

Long-Lived Credentials
High Privileges
Weak Ownership
Limited Monitoring

37. Control 6 — Access Control Management

Section titled “37. Control 6 — Access Control Management”

Account existence and access authorization are different concerns.

Access control focuses on:

Who Can Access What?

Users should receive:

Minimum Access
Required
for Their Role
Request
Approval
Provision
Use
Review
Revoke

Strong authentication should be applied according to risk, particularly for:

Administrative Access
Remote Access
Cloud Access
Sensitive Applications

Privileged accounts should receive stronger governance.

Examples:

MFA
PAM
Session Monitoring
Just-in-Time Access
Access Reviews

42. Control 7 — Continuous Vulnerability Management

Section titled “42. Control 7 — Continuous Vulnerability Management”

Organizations must continuously identify and remediate vulnerabilities.

Discover
Assess
Prioritize
Remediate
Validate

Scan:

Endpoints
Servers
Network Devices
Cloud Assets
Applications

according to organizational scope and risk.

Do not prioritize only using:

CVSS Score

Consider:

Exploitability
Internet Exposure
Asset Criticality
Threat Intelligence
Business Impact
Critical CVE
+
Internet-Facing Server
+
Active Exploitation
+
Critical Application

should receive high remediation priority.

Example:

Severity Example SLA
Critical 7 Days
High 30 Days
Medium 60 Days
Low 90 Days

Actual SLAs should reflect organizational risk.

Logs provide visibility into system activity.

Sources include:

Identity
Endpoints
Servers
Applications
Databases
Cloud
Network Devices
Security Tools
Systems
Logs
Central Collection
SIEM
Detection
Investigation

Examples:

Authentication
Privilege Changes
Administrative Activity
Security Events
Configuration Changes
Data Access

Retention should consider:

Security Needs
Investigation Requirements
Legal Requirements
Compliance Requirements

Systems should use consistent time sources.

Otherwise:

Event A
10:05
Event B
09:57
Event C
10:01

can complicate incident reconstruction.

52. Control 9 — Email and Web Browser Protections

Section titled “52. Control 9 — Email and Web Browser Protections”

Email and browsers are common attack vectors.

Threats include:

Phishing
Malicious Attachments
Malicious Links
Drive-By Downloads
Credential Theft

Possible safeguards include:

Spam Filtering
Attachment Analysis
URL Filtering
Authentication Protections
Anti-Phishing Controls

Manage:

Supported Browsers
Extensions
Updates
Security Settings
Malicious Sites

Organizations should prevent or control malicious software.

Examples:

Endpoint Protection
EDR
Anti-Malware
Application Controls
Behavior Detection
Prevent
Detect
Contain
Investigate
Remediate

Security teams should understand:

Which Devices
Are Protected?
Which Are Not?
Are Agents Healthy?
Are Signatures Current?

Organizations must be able to restore data and services.

Backup
Protect
Test
Restore

Consider:

Critical Systems
Backup Frequency
Retention
Encryption
Isolation
Recovery Requirements

A successful backup does not automatically mean:

Recovery
Will Work

Organizations should test restoration.

Measure:

Restore Success
Recovery Time
Data Integrity
RTO Achievement
RPO Achievement

Backups should be protected against:

Deletion
Modification
Encryption
Administrative Compromise

63. Control 12 — Network Infrastructure Management

Section titled “63. Control 12 — Network Infrastructure Management”

Network infrastructure should be securely managed.

Examples:

Routers
Switches
Firewalls
Wireless
VPN
Cloud Networks

Maintain:

Device
Owner
Location
Version
Configuration
Support Status

Use practices such as:

Secure Administration
MFA
Configuration Baselines
Patch Management
Central Logging

66. Control 13 — Network Monitoring and Defense

Section titled “66. Control 13 — Network Monitoring and Defense”

Organizations should monitor network activity for malicious or suspicious behavior.

Capabilities may include:

IDS
IPS
NDR
Firewall Monitoring
Traffic Analysis
DNS Monitoring
Network Traffic
Security Sensors
Detection
SIEM / SOC
Investigation

Networks should be segmented according to:

Risk
Trust
Business Function
Data Sensitivity
Internet
DMZ
Application Tier
Database Tier

is preferable to unrestricted flat connectivity for sensitive systems.

70. Control 14 — Security Awareness and Skills Training

Section titled “70. Control 14 — Security Awareness and Skills Training”

Technology alone cannot manage all cybersecurity risk.

Employees should understand:

Phishing
Passwords
MFA
Data Handling
Incident Reporting
Social Engineering

Different roles require different skills.

Examples:

Developers
→ Secure Coding
Administrators
→ Privileged Security
Executives
→ Cyber Risk
Finance
→ Fraud Awareness

Possible metrics:

Training Completion
Phishing Simulation Results
Reporting Rate
Repeat Failures

73. Control 15 — Service Provider Management

Section titled “73. Control 15 — Service Provider Management”

Organizations depend heavily on external providers.

Examples:

Cloud Providers
SaaS Vendors
Managed Security Providers
Payment Providers
IT Suppliers
Identify
Classify
Assess
Contract
Monitor
Offboard

Classify providers according to:

Data Access
System Access
Business Dependency
Service Criticality
Regulatory Impact

Contracts may include:

Security Requirements
Incident Notification
Audit Rights
Data Protection
Subcontractor Requirements
Termination Requirements

High-risk providers may require ongoing monitoring for:

Security Incidents
Control Changes
Compliance Changes
Financial Risk
Service Disruption

78. Control 16 — Application Software Security

Section titled “78. Control 16 — Application Software Security”

Applications should be designed and maintained securely.

The lifecycle includes:

Requirements
Design
Development
Testing
Deployment
Maintenance

Practices may include:

Secure Coding
Code Review
SAST
DAST
Dependency Scanning
Secrets Detection

Common issues include:

Injection
Broken Access Control
Weak Authentication
Insecure Configuration
Vulnerable Dependencies
Secrets Exposure

Modern applications rely heavily on third-party components.

Maintain:

Component Inventory
Version
Vulnerability Status
Owner

An SBOM can improve visibility into software components and dependencies.

Conceptually:

Application
Components
Libraries
Versions
Known Vulnerabilities

83. Control 17 — Incident Response Management

Section titled “83. Control 17 — Incident Response Management”

Organizations need defined processes for handling cybersecurity incidents.

Prepare
Detect
Triage
Contain
Eradicate
Recover
Improve

Define:

Roles
Responsibilities
Escalation
Communication
Technical Procedures
External Contacts

Example:

SEV-1
Critical
SEV-2
High
SEV-3
Medium
SEV-4
Low

Test response capabilities through:

Tabletop Exercises
Technical Simulations
Recovery Exercises

After incidents:

What Happened?
Why?
What Worked?
What Failed?
What Must Change?

Penetration testing validates whether security weaknesses can be exploited.

It complements:

Vulnerability Scanning
Configuration Assessment
Control Testing

89. Vulnerability Scan vs Penetration Test

Section titled “89. Vulnerability Scan vs Penetration Test”
Vulnerability Scan
Find Potential
Weaknesses

while:

Penetration Test
Validate Exploitable
Attack Paths

May include:

External Infrastructure
Internal Infrastructure
Web Applications
APIs
Cloud
Wireless

within authorized scope.

Before testing define:

Scope
Authorization
Timing
Allowed Techniques
Excluded Systems
Contacts
Escalation

Document:

Finding
Attack Path
Evidence
Impact
Risk
Recommendation

After remediation:

Finding
Fix
Retest
Close

The Controls should not operate independently.

Example attack:

Phishing Email
Credential Theft
Account Compromise
Privileged Access
Malware
Data Exfiltration

Multiple CIS Controls contribute to defense.

Control 9
Email Protection
Control 14
Security Awareness
Control 5
Account Management
Control 6
Access Control
Control 10
Malware Defense
Control 8
Logging
Control 13
Monitoring
Control 17
Incident Response

This is defense in depth.

Controls should connect to risks.

Example:

Risk:
Ransomware

Relevant Controls:

04 Secure Configuration
07 Vulnerability Management
08 Audit Logging
10 Malware Defenses
11 Data Recovery
13 Network Defense
14 Awareness
17 Incident Response
18 Penetration Testing

A risk register may contain:

Risk
CIS Control
Safeguard
Control Owner
Effectiveness
Residual Risk

The frameworks complement each other.

Conceptually:

NIST CSF
Desired Cybersecurity
Outcomes
CIS Controls
Operational Safeguards

NIST CSF outcome:

Assets Are
Managed

CIS implementation:

Control 1
Inventory and Control
of Enterprise Assets

RMF may determine:

What Controls
Are Required
for a System?

CIS Controls can provide additional practical cybersecurity guidance and implementation priorities.

Organizations may map CIS safeguards to ISO 27001 controls.

Example:

CIS Asset Management
Enterprise Control
ISO 27001
Asset-Related Requirements

Several CIS Controls align conceptually with PCI DSS areas such as:

Secure Configuration
Access Control
Logging
Vulnerability Management
Malware Protection
Penetration Testing

Mapping should always account for the exact requirements of each framework.

Instead of implementing separate controls for every framework:

NIST Control
ISO Control
PCI Control
CIS Safeguard

organizations can establish:

Enterprise Control
Mapped to
NIST
ISO
PCI DSS
CIS

A practical assessment follows:

Define Scope
Determine IG
Identify Applicable Safeguards
Assess Implementation
Collect Evidence
Identify Gaps
Assess Risk
Create Roadmap

Scope may include:

Enterprise
Business Unit
Cloud Environment
Critical Service
Application
Subsidiary

106. Step 2 — Determine Implementation Group

Section titled “106. Step 2 — Determine Implementation Group”

Consider:

Risk
Resources
Data Sensitivity
Complexity
Threat Environment

Maintain:

Control
Safeguard
Applicability
Owner
Status
Evidence

Possible statuses:

Implemented
Partially Implemented
Not Implemented
Not Applicable

Evidence may include:

Configurations
Policies
Inventories
Logs
Reports
Tickets
Screenshots
System Exports

Example:

Safeguard:
Enterprise Asset Inventory
Status:
Partial
Gap:
Cloud Assets
Not Automatically Discovered

Determine:

What Could
Happen Because
of This Gap?

Example:

Unknown Cloud Asset
Unpatched Vulnerability
Internet Exposure
Compromise

Document:

Gap
Risk
Action
Owner
Priority
Due Date
Status
Gap Risk Action Priority
Unknown cloud assets Unmanaged exposure Deploy discovery Critical
Admin MFA incomplete Account compromise Enforce MFA Critical
Unsupported software Exploitation Upgrade/remove High
Recovery tests missing Recovery failure Test backups High

Do not prioritize based only on:

Safeguard Number

Use:

Risk
Asset Criticality
Threat Exposure
Business Impact
Dependencies

A practical roadmap may begin with:

Asset Visibility
Software Visibility
Identity
Secure Configuration
Vulnerability Management
Logging
Endpoint Protection
Recovery
Monitoring
Incident Response

Prioritize:

Enterprise Assets
Software Assets
Data
Accounts
Service Providers

117. Phase 2 — Establish Basic Protection

Section titled “117. Phase 2 — Establish Basic Protection”

Implement:

Secure Configuration
Access Controls
MFA
Patch Management
Malware Defense
Backups

Implement:

Logging
Central Monitoring
Network Monitoring
Vulnerability Scanning

Develop:

Incident Response
Recovery Testing
Security Awareness
Vendor Governance

Use:

Application Testing
Penetration Testing
Control Testing
Continuous Monitoring

Useful metrics may include:

Asset Inventory Coverage
Software Inventory Coverage
MFA Coverage
Secure Configuration Coverage
Vulnerability SLA Compliance
Logging Coverage
EDR Coverage
Backup Success
Recovery Test Success
Training Completion
Vendor Assessment Coverage
Incident Response Exercise Completion
Managed Assets
────────────── × 100
Known Assets
MFA-Protected Accounts
────────────────────── × 100
Applicable Accounts
Vulnerabilities
Remediated Within SLA
────────────────────── × 100
Applicable Vulnerabilities
Critical Systems
Sending Required Logs
────────────────────── × 100
Critical Systems
Successful Recovery Tests
───────────────────────── × 100
Recovery Tests Performed

Example:

CIS SECURITY DASHBOARD
Asset Coverage 98%
Software Coverage 95%
MFA Coverage 99%
EDR Coverage 98%
Critical Patch SLA 92%
Logging Coverage 94%
Recovery Test Success 90%

Do not stop at percentages.

Highlight material gaps.

Example:

1. 12 internet-facing assets
remain outside central inventory.
2. 4 privileged accounts
do not enforce MFA.
3. 8 critical vulnerabilities
remain past SLA.
4. 2 critical systems
failed recovery testing.

A useful reporting model:

Healthy
Degraded
Failed
Unknown

Example:

CIS Compliance:
96%

may hide:

Privileged MFA:
FAILED

Risk significance matters more than the average.

Assign owners for each major control area.

Example:

CIS Control Example Owner
Enterprise Assets IT Operations
Software Assets IT Operations
Data Protection Data Security
Secure Configuration Security Engineering
Account Management IAM
Vulnerability Management Vulnerability Management
Audit Logs SOC
Incident Response SOC / CSIRT

Each safeguard should have traceable evidence.

Safeguard
Implementation
Evidence
Assessment
Result

Where possible, automate evidence for controls such as:

Asset Inventory
Software Inventory
MFA
Configuration
Vulnerabilities
Logging
Endpoint Protection
Backups

Requirement:

All Managed Endpoints
Must Have EDR

Automation:

Endpoint Inventory
EDR Platform
Coverage Comparison
Daily Control Status

Example:

Yesterday:
100% EDR Coverage
Today:
98%

The decrease should trigger investigation.

Sometimes a safeguard cannot be implemented immediately.

Document:

Safeguard
Reason
Risk
Compensating Control
Owner
Approval
Expiration
System:
Legacy Application
Gap:
MFA Unsupported
Compensating Controls:
Restricted Network
PAM Gateway
Monitoring
Expiration:
90 Days

138. Exceptions Should Not Become Permanent

Section titled “138. Exceptions Should Not Become Permanent”

Monitor:

Exception Age
Renewals
Risk
Remediation

139. Common Mistake — Implement Controls Without Inventory

Section titled “139. Common Mistake — Implement Controls Without Inventory”

Without accurate inventories:

Coverage Metrics
Cannot Be Trusted

140. Common Mistake — Treat CIS as a Checklist

Section titled “140. Common Mistake — Treat CIS as a Checklist”

Weak:

Safeguard
Yes
Complete

Better:

Safeguard
Implementation
Evidence
Effectiveness
Risk

Organizations may create unnecessary complexity by trying to implement advanced safeguards before basic hygiene is reliable.

Build the foundation first.

142. Common Mistake — Tool Equals Control

Section titled “142. Common Mistake — Tool Equals Control”

Buying:

EDR

does not automatically mean:

Malware Defense
Effective

Evaluate:

Coverage
Configuration
Monitoring
Response

143. Common Mistake — Ignore Cloud Assets

Section titled “143. Common Mistake — Ignore Cloud Assets”

Modern inventories must include:

Cloud VMs
Containers
Serverless
Cloud Databases
SaaS
Cloud Identities

where applicable.

144. Common Mistake — Vulnerability Scanning Without Remediation

Section titled “144. Common Mistake — Vulnerability Scanning Without Remediation”
Scan
Find
Report

is incomplete.

Use:

Scan
Prioritize
Remediate
Validate

145. Common Mistake — Backup Without Testing

Section titled “145. Common Mistake — Backup Without Testing”

A backup that cannot be restored provides little resilience.

146. Common Mistake — Logs Without Monitoring

Section titled “146. Common Mistake — Logs Without Monitoring”
Collect Logs

is different from:

Detect Threats

147. Common Mistake — Training Everyone Identically

Section titled “147. Common Mistake — Training Everyone Identically”

Role-based risks require role-based training.

148. Common Mistake — Ignore Service Providers

Section titled “148. Common Mistake — Ignore Service Providers”

Outsourcing a service does not automatically remove organizational risk.

149. Common Mistake — Penetration Test as Annual Checkbox

Section titled “149. Common Mistake — Penetration Test as Annual Checkbox”

Penetration testing should feed:

Findings
Remediation
Retesting
Security Improvement

Risk:

Ransomware

Relevant CIS Controls include:

01 Asset Inventory
02 Software Inventory
04 Secure Configuration
05 Account Management
06 Access Control
07 Vulnerability Management
08 Audit Logging
09 Email Protection
10 Malware Defense
11 Data Recovery
13 Network Defense
14 Awareness
17 Incident Response
18 Penetration Testing

151. End-to-End Example — Privileged Account Compromise

Section titled “151. End-to-End Example — Privileged Account Compromise”

Risk:

Administrator
Account Compromise

Controls:

05 Account Management
06 Access Control
08 Audit Logging
13 Monitoring
17 Incident Response

Safeguards may include:

Admin Inventory
MFA
Least Privilege
Central Logging
Monitoring

152. End-to-End Example — Unknown Cloud Asset

Section titled “152. End-to-End Example — Unknown Cloud Asset”
Developer Creates
Cloud VM
Not Added
to Inventory
Not Scanned
Not Patched
Internet Exposed
Compromise

Relevant Controls:

01 Enterprise Assets
04 Secure Configuration
07 Vulnerability Management
08 Logging
13 Monitoring

153. End-to-End Example — Critical Vendor

Section titled “153. End-to-End Example — Critical Vendor”
Critical SaaS Provider
Customer Data
Business Dependency

Relevant controls include:

03 Data Protection
15 Service Provider Management
17 Incident Response
Executive Governance
Cyber Risk
CIS Implementation Group
18 CIS Controls
Safeguards
Enterprise Controls
Technical Implementation
Evidence
Monitoring
Risk Reporting
  • asset inventory maintained.

  • cloud assets included.

  • ownership defined.

  • unauthorized assets detected.

  • asset criticality maintained.

  • software inventory maintained.

  • authorized software defined.

  • unsupported software identified.

  • unauthorized software addressed.

  • sensitive data identified.

  • data classified.

  • access restricted.

  • encryption implemented where required.

  • retention established.

  • secure disposal established.

  • secure baselines defined.

  • endpoints covered.

  • servers covered.

  • cloud configurations covered.

  • configuration drift monitored.

  • account inventory maintained.

  • dormant accounts managed.

  • administrator accounts controlled.

  • service accounts governed.

  • account lifecycle established.

  • least privilege implemented.

  • MFA implemented based on risk.

  • privileged access controlled.

  • access reviews performed.

  • access removed when no longer required.

  • vulnerability scanning established.

  • scope complete.

  • vulnerabilities prioritized.

  • remediation SLAs defined.

  • remediation validated.

  • logging requirements defined.

  • critical logs collected.

  • centralized logging established.

  • retention defined.

  • time synchronization maintained.

  • email filtering implemented.

  • malicious URLs controlled.

  • browser configurations managed.

  • unsupported browsers restricted.

  • endpoint protection deployed.

  • coverage monitored.

  • agents healthy.

  • detections monitored.

  • malware incidents investigated.

  • backups configured.

  • backups protected.

  • restoration tested.

  • RTO/RPO considered.

  • recovery failures remediated.

  • network inventory maintained.

  • configurations secured.

  • administrative access protected.

  • network devices patched.

  • network logs collected.

  • network monitoring established.

  • suspicious traffic detected.

  • critical networks covered.

  • segmentation implemented based on risk.

  • baseline training established.

  • role-based training implemented.

  • phishing awareness included.

  • completion monitored.

  • effectiveness measured.

  • provider inventory maintained.

  • criticality assigned.

  • assessments performed.

  • contractual requirements established.

  • providers monitored.

  • offboarding defined.

  • secure development process defined.

  • code reviewed.

  • security testing performed.

  • dependencies monitored.

  • secrets protected.

  • IR plan maintained.

  • roles assigned.

  • escalation defined.

  • exercises conducted.

  • lessons learned tracked.

  • testing scope defined.

  • authorization documented.

  • testing performed.

  • findings risk-rated.

  • remediation tracked.

  • retesting performed.

After completing this lesson, you should be able to create:

01 CIS Controls Scope
02 Implementation Group Assessment
03 CIS Safeguard Register
04 Enterprise Asset Inventory
05 Software Asset Inventory
06 Data Inventory
07 Secure Configuration Register
08 Account Inventory
09 Access Control Matrix
10 Vulnerability Register
11 Logging Coverage Matrix
12 Malware Defense Coverage
13 Recovery Readiness Assessment
14 Network Security Assessment
15 Security Awareness Matrix
16 Service Provider Register
17 Application Security Assessment
18 Incident Response Readiness Assessment
19 Penetration Testing Register
20 CIS Gap Assessment
21 CIS Remediation Register
22 CIS Control-to-Risk Mapping
23 CIS-to-Framework Mapping
24 CIS Executive Dashboard
25 CIS Implementation Roadmap

Practical Activity — Determine the Implementation Group

Section titled “Practical Activity — Determine the Implementation Group”

Scenario:

Organization:
Online Financial Services Company
Employees:
2,000
Environment:
AWS
Microsoft 365
SaaS
Remote Workforce
Data:
Customer PII
Financial Information
Security Team:
Dedicated SOC
Security Engineering
GRC

Determine whether the organization should primarily operate toward:

IG1
IG2
IG3

Document your reasoning based on:

Threat
Data
Complexity
Business Impact
Resources

Practical Activity — Perform CIS Gap Assessment

Section titled “Practical Activity — Perform CIS Gap Assessment”

Assess:

Control 1
Asset Inventory
Control 5
Account Management
Control 6
Access Control
Control 7
Vulnerability Management
Control 8
Logging
Control 11
Recovery

For each record:

Current State
Evidence
Gap
Risk
Owner
Recommended Action

Practical Activity — Build a Remediation Roadmap

Section titled “Practical Activity — Build a Remediation Roadmap”

Findings:

12 Unknown Cloud Assets
4 Admin Accounts Without MFA
8 Critical Vulnerabilities Past SLA
20 Endpoints Without EDR
2 Failed Recovery Tests

Prioritize the findings based on:

Threat Exposure
Asset Criticality
Business Impact
Likelihood
Dependencies

Do not prioritize based simply on the number of findings.

Practical Activity — Map CIS to Enterprise Risks

Section titled “Practical Activity — Map CIS to Enterprise Risks”

Map appropriate CIS Controls to:

Ransomware
Credential Theft
Cloud Misconfiguration
Data Breach
Third-Party Compromise
Service Disruption

Then identify:

Preventive Controls
Detective Controls
Responsive Controls
Recovery Controls

When using CIS Controls, ask:

Do We Know
Every Important Asset?
Do We Know
What Software
Is Running?
Do We Know
Where Sensitive
Data Exists?
Are Systems
Securely Configured?
Do We Know
Every Account?
Is Access
Least Privilege?
Is MFA
Implemented?
Are Vulnerabilities
Continuously Identified?
Are Critical
Vulnerabilities
Remediated Quickly?
Are Important
Events Logged?
Can We
Detect Attacks?
Are Endpoints
Protected?
Can We
Recover Data?
Have We
Tested Recovery?
Are Networks
Securely Managed?
Can We
Monitor Network
Threats?
Are Employees
Security Aware?
Are Critical
Vendors Governed?
Are Applications
Developed Securely?
Can We
Respond to Incidents?
Do We
Test Our Defenses?
Which Implementation
Group Is Appropriate?
Which Safeguards
Matter Most?
What Evidence
Shows They Work?
Which Controls
Are Failing?
What Risk
Does That Create?
Who Owns
the Remediation?
Are We
Measuring Activity?
Or Are We
Reducing Risk?

That is the mindset of a GRC professional using CIS Controls v8.

  • CIS Controls v8 provides 18 prioritized cybersecurity Controls.

  • Each Control contains practical Safeguards.

  • Implementation Groups help organizations prioritize safeguards.

  • IG1 establishes essential cyber hygiene.

  • IG2 builds stronger security capabilities for more complex organizations.

  • IG3 addresses organizations facing more sophisticated or significant risks.

  • Organizations should select implementation priorities based on risk.

  • Asset and software inventories form the foundation for many other controls.

  • Data must be identified and protected throughout its lifecycle.

  • Secure configuration baselines reduce unnecessary exposure.

  • Account and access-control management are related but distinct disciplines.

  • Vulnerability management requires discovery, prioritization, remediation, and validation.

  • Logging must support security monitoring and investigation.

  • Email and browser protections reduce common attack paths.

  • Malware defense requires coverage, monitoring, and response.

  • Backup alone does not prove recoverability.

  • Network infrastructure requires secure configuration and administration.

  • Network monitoring provides visibility into malicious activity.

  • Security awareness should include role-based training.

  • Service-provider security must be managed throughout the vendor lifecycle.

  • Application security should be integrated into the software-development lifecycle.

  • Incident-response capability must be planned and exercised.

  • Penetration testing validates exploitable attack paths.

  • CIS Controls can be mapped to NIST CSF, NIST RMF, ISO 27001, PCI DSS, and enterprise common controls.

  • Control implementation should be supported by evidence.

  • Automation can improve continuous control monitoring.

  • Control gaps should be evaluated according to risk rather than simple percentages.

  • CIS Controls should be used as an operational risk-reduction framework rather than a checklist.

Before continuing, make sure you can answer:

  1. What are the CIS Controls?

  2. How many CIS Controls exist in v8?

  3. What is a CIS Safeguard?

  4. What are Implementation Groups?

  5. What is IG1?

  6. What is IG2?

  7. What is IG3?

  8. How should an organization select its Implementation Group?

  9. Why is enterprise asset inventory foundational?

  10. Why is software inventory important?

  11. What is data classification?

  12. What is configuration drift?

  13. What is account lifecycle management?

  14. How does account management differ from access control?

  15. What is least privilege?

  16. Why is MFA important?

  17. What is continuous vulnerability management?

  18. Why should vulnerability priority consider more than CVSS?

  19. Why is centralized logging useful?

  20. Why is time synchronization important?

  21. What risks do email and browsers introduce?

  22. What is malware defense?

  23. Why must backups be tested?

  24. What is network infrastructure management?

  25. What is network monitoring and defense?

  26. Why is network segmentation useful?

  27. Why should security training be role-based?

  28. What is service-provider management?

  29. Why should vendor criticality be defined?

  30. What is application software security?

  31. What is an SBOM?

  32. What is incident-response management?

  33. Why should incident-response exercises be performed?

  34. How does penetration testing differ from vulnerability scanning?

  35. What are rules of engagement?

  36. Why should penetration-test findings be retested?

  37. How can CIS Controls support NIST CSF?

  38. How can CIS Controls support enterprise common controls?

  39. Why can overall implementation percentages be misleading?

  40. Why should CIS Controls be treated as a risk-reduction program rather than a checklist?

➡️ Next: 04 — COBIT 2019

In the next lesson, you will move from operational cybersecurity safeguards into enterprise governance of information and technology.

You will learn how COBIT 2019 helps organizations connect:

Enterprise Objectives
Stakeholder Needs
Governance
Information & Technology
Management Objectives
Controls & Processes
Performance
Business Value

You will explore the COBIT governance and management domains:

EDM
Evaluate, Direct and Monitor
APO
Align, Plan and Organize
BAI
Build, Acquire and Implement
DSS
Deliver, Service and Support
MEA
Monitor, Evaluate and Assess

and understand how GRC professionals use COBIT to connect technology governance, enterprise risk, compliance, controls, assurance, performance, and executive oversight.

➡️ Next: 04 — COBIT 2019