03 CIS Controls v8
The CIS Critical Security Controls v8 provide a prioritized set of practical cybersecurity safeguards organizations can implement to reduce common and significant cyber risks.
Where frameworks such as NIST CSF help organizations structure cybersecurity outcomes and NIST RMF provides a formal risk-management lifecycle, the CIS Controls focus heavily on:
What SecuritySafeguards ShouldWe Actually Implement?The framework organizes cybersecurity practices into 18 Controls covering areas such as:
Assets
Software
Data
Configuration
Accounts
Access
Vulnerabilities
Logging
Email
Malware
Recovery
Networks
Monitoring
Awareness
Service Providers
Applications
Incident Response
Penetration TestingA major feature of CIS Controls is the use of:
Implementation Groups
IG1
IG2
IG3These help organizations prioritize safeguards according to their cybersecurity risk, resources, complexity, and operational requirements.
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the purpose of CIS Controls v8.
-
understand the structure of the 18 CIS Controls.
-
understand CIS Safeguards.
-
understand Implementation Groups.
-
differentiate IG1, IG2, and IG3.
-
understand how organizations prioritize CIS safeguards.
-
understand enterprise asset management.
-
understand software asset management.
-
understand data protection.
-
understand secure configuration.
-
understand account management.
-
understand access-control management.
-
understand vulnerability management.
-
understand audit-log management.
-
understand email and web protections.
-
understand malware defenses.
-
understand data recovery.
-
understand network infrastructure management.
-
understand network monitoring and defense.
-
understand security awareness.
-
understand service-provider management.
-
understand application software security.
-
understand incident-response management.
-
understand penetration testing.
-
perform a CIS Controls gap assessment.
-
map CIS safeguards to enterprise controls.
-
build a CIS implementation roadmap.
-
develop CIS-based security metrics.
-
integrate CIS Controls into enterprise GRC.
1. What Are the CIS Controls?
Section titled “1. What Are the CIS Controls?”CIS Controls are a prioritized set of cybersecurity practices designed to help organizations defend against common cyber threats.
Conceptually:
Cyber Threats ↓Security Risks ↓CIS Controls ↓Safeguards ↓Implementation ↓Risk ReductionThe emphasis is strongly operational.
Organizations can use the Controls to determine:
What ShouldWe Protect?
What SafeguardsShould Exist?
What ShouldWe Implement First?
How Can WeMeasure Progress?2. CIS Controls Structure
Section titled “2. CIS Controls Structure”CIS Controls v8 contains:
18 Controls ↓Safeguards ↓Implementation GroupsA Control represents a major cybersecurity capability.
A Safeguard represents a specific recommended security action.
3. The 18 CIS Controls
Section titled “3. The 18 CIS Controls”The Controls are:
01 Inventory and Control of Enterprise Assets
02 Inventory and Control of Software Assets
03 Data Protection
04 Secure Configuration of Enterprise Assets and Software
05 Account Management
06 Access Control Management
07 Continuous Vulnerability Management
08 Audit Log Management
09 Email and Web Browser Protections
10 Malware Defenses
11 Data Recovery
12 Network Infrastructure Management
13 Network Monitoring and Defense
14 Security Awareness and Skills Training
15 Service Provider Management
16 Application Software Security
17 Incident Response Management
18 Penetration TestingTogether they provide a broad operational cybersecurity baseline.
4. CIS Safeguards
Section titled “4. CIS Safeguards”Each Control contains specific Safeguards.
For example:
Control ↓Account Management ↓Safeguards ↓Account Inventory
Dormant Account Handling
Administrator Account Management
Service Account ManagementThe Controls tell you the security area.
The Safeguards describe what should be implemented.
5. Why Prioritization Matters
Section titled “5. Why Prioritization Matters”Organizations rarely have unlimited:
Budget
People
Technology
TimeTrying to implement everything simultaneously often results in:
Too Many Projects ↓Weak Prioritization ↓Slow Implementation ↓Limited Risk ReductionCIS addresses this using Implementation Groups.
6. Implementation Groups
Section titled “6. Implementation Groups”CIS Controls use three Implementation Groups:
IG1 ↓IG2 ↓IG3They provide progressive levels of cybersecurity safeguards.
7. IG1 — Essential Cyber Hygiene
Section titled “7. IG1 — Essential Cyber Hygiene”IG1 represents foundational cybersecurity safeguards.
It is intended to establish essential cyber hygiene.
Think:
Know Your Assets
Know Your Software
Protect Accounts
Secure Systems
Patch Vulnerabilities
Protect Data
Maintain BackupsIG1 is the starting point.
8. IG1 Organization Example
Section titled “8. IG1 Organization Example”An organization may have:
Small IT Team
Limited Security Staff
Standard Business Systems
Cloud SaaS
Moderate Data SensitivityIts first objective should be establishing strong fundamental safeguards.
9. IG2 — Expanded Security Program
Section titled “9. IG2 — Expanded Security Program”IG2 builds on IG1.
Organizations in this group typically have:
Multiple Departments
More Complex Infrastructure
Dedicated IT / Security Roles
Sensitive Information
Regulatory Requirements
Greater Operational DependenciesIG2 requires broader and more formal security capabilities.
10. IG3 — Advanced Security Program
Section titled “10. IG3 — Advanced Security Program”IG3 represents organizations requiring stronger protections against sophisticated threats.
Examples may include:
Critical Infrastructure
Large Financial Institutions
Defense Organizations
High-Value Technology Companies
Highly Sensitive EnvironmentsThese organizations may face:
Targeted Attacks
Advanced Threat Actors
Significant Regulatory Exposure
Large-Scale Business Impact11. Implementation Group Relationship
Section titled “11. Implementation Group Relationship”Conceptually:
IG1Essential Cyber Hygiene ↓IG2Expanded Safeguards ↓IG3Advanced SafeguardsIG2 includes IG1 expectations.
IG3 builds further upon them.
12. Implementation Groups Are Risk-Based
Section titled “12. Implementation Groups Are Risk-Based”Do not choose IG3 simply because:
IG3Sounds BetterConsider:
Business Risk
Data Sensitivity
Threat Environment
Organization Size
Operational Complexity
Regulatory Requirements13. Control 1 — Inventory and Control of Enterprise Assets
Section titled “13. Control 1 — Inventory and Control of Enterprise Assets”Organizations must understand which assets exist.
Examples:
Servers
Endpoints
Laptops
Mobile Devices
Network Devices
Virtual Machines
Cloud Resources
IoT Devices14. Why Asset Inventory Matters
Section titled “14. Why Asset Inventory Matters”You cannot reliably:
Secure
Patch
Monitor
Assess
Recoveran asset you do not know exists.
Unknown Asset ↓Unknown Vulnerability ↓Unknown Exposure15. Enterprise Asset Register
Section titled “15. Enterprise Asset Register”A useful inventory may contain:
Asset ID
Asset Name
Type
Owner
Location
IP Address
Business Service
Criticality
Status16. Unauthorized Assets
Section titled “16. Unauthorized Assets”Organizations should detect:
Unknown Devices
Unauthorized Servers
Unmanaged Cloud Resources
Shadow ITand establish processes for handling them.
17. Asset Ownership
Section titled “17. Asset Ownership”Every important asset should have:
Business Owner
Technical Ownerwhere appropriate.
18. Asset Criticality
Section titled “18. Asset Criticality”Classify assets according to business importance.
Example:
Tier 1Mission Critical
Tier 2Business Critical
Tier 3Important
Tier 4Standard19. Control 2 — Inventory and Control of Software Assets
Section titled “19. Control 2 — Inventory and Control of Software Assets”Organizations must understand what software is installed and authorized.
Examples:
Operating Systems
Applications
Agents
Browser Extensions
Libraries
Cloud Software
SaaS Applications20. Software Inventory
Section titled “20. Software Inventory”Maintain:
Software
Version
Publisher
Asset
Owner
Approval
Support Status21. Unauthorized Software
Section titled “21. Unauthorized Software”Identify:
Unapproved Software
Pirated Software
Unsupported Software
End-of-Life Software
High-Risk Applications22. Why Software Inventory Matters
Section titled “22. Why Software Inventory Matters”Without software visibility:
Vulnerability ↓Affected Software Unknown ↓Exposure Unknown ↓Remediation Delayed23. Control 3 — Data Protection
Section titled “23. Control 3 — Data Protection”Organizations should understand and protect important information throughout its lifecycle.
Create ↓Store ↓Process ↓Transmit ↓Archive ↓Destroy24. Data Inventory
Section titled “24. Data Inventory”Identify important data such as:
Customer Data
Employee Data
Payment Data
Financial Data
Health Data
Intellectual Property
Authentication Data25. Data Classification
Section titled “25. Data Classification”Example:
Public
Internal
Confidential
Restricted26. Data Protection Measures
Section titled “26. Data Protection Measures”Potential safeguards include:
Encryption
Access Control
Data Loss Prevention
Retention
Secure Disposal
Data Segmentation
Backup27. Data Handling
Section titled “27. Data Handling”Protection should follow classification.
Example:
Restricted Data ↓Encryption ↓Restricted Access ↓Monitoring ↓Controlled Retention28. Control 4 — Secure Configuration of Enterprise Assets and Software
Section titled “28. Control 4 — Secure Configuration of Enterprise Assets and Software”Default configurations are rarely sufficient for enterprise security.
Organizations should establish:
Secure Baselinesfor:
Endpoints
Servers
Network Devices
Cloud Platforms
Applications
Mobile Devices29. Configuration Baseline
Section titled “29. Configuration Baseline”Example:
Windows ServerSecurity Baselinemay define:
Password Settings
Logging
Firewall
Services
Encryption
Remote Access30. Configuration Drift
Section titled “30. Configuration Drift”Over time:
Secure Baseline ↓Changes ↓Configuration Drift ↓Security WeaknessOrganizations should detect and remediate drift.
31. Configuration Management
Section titled “31. Configuration Management”Use:
Baseline ↓Deploy ↓Monitor ↓Detect Drift ↓Remediate32. Control 5 — Account Management
Section titled “32. Control 5 — Account Management”Organizations must manage accounts throughout their lifecycle.
Create ↓Modify ↓Review ↓Disable ↓Delete33. Account Types
Section titled “33. Account Types”Inventory:
User Accounts
Administrator Accounts
Service Accounts
Shared Accounts
Application Accounts
Emergency Accounts34. Dormant Accounts
Section titled “34. Dormant Accounts”Dormant accounts create unnecessary attack paths.
Example:
Employee Leaves ↓Account Remains Active ↓Credential Compromise ↓Unauthorized Access35. Account Inventory
Section titled “35. Account Inventory”Maintain:
Account
Identity
Owner
Type
Privilege
Status
Last Used36. Service Accounts
Section titled “36. Service Accounts”Service accounts require particular attention because they may have:
Long-Lived Credentials
High Privileges
Weak Ownership
Limited Monitoring37. Control 6 — Access Control Management
Section titled “37. Control 6 — Access Control Management”Account existence and access authorization are different concerns.
Access control focuses on:
Who Can Access What?38. Least Privilege
Section titled “38. Least Privilege”Users should receive:
Minimum AccessRequiredfor Their Role39. Access Control Lifecycle
Section titled “39. Access Control Lifecycle”Request ↓Approval ↓Provision ↓Use ↓Review ↓Revoke40. MFA
Section titled “40. MFA”Strong authentication should be applied according to risk, particularly for:
Administrative Access
Remote Access
Cloud Access
Sensitive Applications41. Privileged Access
Section titled “41. Privileged Access”Privileged accounts should receive stronger governance.
Examples:
MFA
PAM
Session Monitoring
Just-in-Time Access
Access Reviews42. Control 7 — Continuous Vulnerability Management
Section titled “42. Control 7 — Continuous Vulnerability Management”Organizations must continuously identify and remediate vulnerabilities.
Discover ↓Assess ↓Prioritize ↓Remediate ↓Validate43. Vulnerability Scanning
Section titled “43. Vulnerability Scanning”Scan:
Endpoints
Servers
Network Devices
Cloud Assets
Applicationsaccording to organizational scope and risk.
44. Prioritize Vulnerabilities
Section titled “44. Prioritize Vulnerabilities”Do not prioritize only using:
CVSS ScoreConsider:
Exploitability
Internet Exposure
Asset Criticality
Threat Intelligence
Business Impact45. Example
Section titled “45. Example”Critical CVE +Internet-Facing Server +Active Exploitation +Critical Applicationshould receive high remediation priority.
46. Vulnerability SLA
Section titled “46. Vulnerability SLA”Example:
| Severity | Example SLA |
|---|---|
| Critical | 7 Days |
| High | 30 Days |
| Medium | 60 Days |
| Low | 90 Days |
Actual SLAs should reflect organizational risk.
47. Control 8 — Audit Log Management
Section titled “47. Control 8 — Audit Log Management”Logs provide visibility into system activity.
Sources include:
Identity
Endpoints
Servers
Applications
Databases
Cloud
Network Devices
Security Tools48. Logging Architecture
Section titled “48. Logging Architecture”Systems ↓Logs ↓Central Collection ↓SIEM ↓Detection ↓Investigation49. Important Events
Section titled “49. Important Events”Examples:
Authentication
Privilege Changes
Administrative Activity
Security Events
Configuration Changes
Data Access50. Log Retention
Section titled “50. Log Retention”Retention should consider:
Security Needs
Investigation Requirements
Legal Requirements
Compliance Requirements51. Time Synchronization
Section titled “51. Time Synchronization”Systems should use consistent time sources.
Otherwise:
Event A10:05
Event B09:57
Event C10:01can complicate incident reconstruction.
52. Control 9 — Email and Web Browser Protections
Section titled “52. Control 9 — Email and Web Browser Protections”Email and browsers are common attack vectors.
Threats include:
Phishing
Malicious Attachments
Malicious Links
Drive-By Downloads
Credential Theft53. Email Security
Section titled “53. Email Security”Possible safeguards include:
Spam Filtering
Attachment Analysis
URL Filtering
Authentication Protections
Anti-Phishing Controls54. Browser Security
Section titled “54. Browser Security”Manage:
Supported Browsers
Extensions
Updates
Security Settings
Malicious Sites55. Control 10 — Malware Defenses
Section titled “55. Control 10 — Malware Defenses”Organizations should prevent or control malicious software.
Examples:
Endpoint Protection
EDR
Anti-Malware
Application Controls
Behavior Detection56. Malware Protection Lifecycle
Section titled “56. Malware Protection Lifecycle”Prevent ↓Detect ↓Contain ↓Investigate ↓Remediate57. Central Management
Section titled “57. Central Management”Security teams should understand:
Which DevicesAre Protected?
Which Are Not?
Are Agents Healthy?
Are Signatures Current?58. Control 11 — Data Recovery
Section titled “58. Control 11 — Data Recovery”Organizations must be able to restore data and services.
Backup ↓Protect ↓Test ↓Restore59. Backup Strategy
Section titled “59. Backup Strategy”Consider:
Critical Systems
Backup Frequency
Retention
Encryption
Isolation
Recovery Requirements60. Backup Is Not Recovery
Section titled “60. Backup Is Not Recovery”A successful backup does not automatically mean:
RecoveryWill WorkOrganizations should test restoration.
61. Recovery Testing
Section titled “61. Recovery Testing”Measure:
Restore Success
Recovery Time
Data Integrity
RTO Achievement
RPO Achievement62. Ransomware Resilience
Section titled “62. Ransomware Resilience”Backups should be protected against:
Deletion
Modification
Encryption
Administrative Compromise63. Control 12 — Network Infrastructure Management
Section titled “63. Control 12 — Network Infrastructure Management”Network infrastructure should be securely managed.
Examples:
Routers
Switches
Firewalls
Wireless
VPN
Cloud Networks64. Network Device Inventory
Section titled “64. Network Device Inventory”Maintain:
Device
Owner
Location
Version
Configuration
Support Status65. Secure Network Management
Section titled “65. Secure Network Management”Use practices such as:
Secure Administration
MFA
Configuration Baselines
Patch Management
Central Logging66. Control 13 — Network Monitoring and Defense
Section titled “66. Control 13 — Network Monitoring and Defense”Organizations should monitor network activity for malicious or suspicious behavior.
Capabilities may include:
IDS
IPS
NDR
Firewall Monitoring
Traffic Analysis
DNS Monitoring67. Network Monitoring Model
Section titled “67. Network Monitoring Model”Network Traffic ↓Security Sensors ↓Detection ↓SIEM / SOC ↓Investigation68. Segmentation
Section titled “68. Segmentation”Networks should be segmented according to:
Risk
Trust
Business Function
Data Sensitivity69. Example
Section titled “69. Example”Internet ↓DMZ ↓Application Tier ↓Database Tieris preferable to unrestricted flat connectivity for sensitive systems.
70. Control 14 — Security Awareness and Skills Training
Section titled “70. Control 14 — Security Awareness and Skills Training”Technology alone cannot manage all cybersecurity risk.
Employees should understand:
Phishing
Passwords
MFA
Data Handling
Incident Reporting
Social Engineering71. Role-Based Training
Section titled “71. Role-Based Training”Different roles require different skills.
Examples:
Developers→ Secure Coding
Administrators→ Privileged Security
Executives→ Cyber Risk
Finance→ Fraud Awareness72. Awareness Metrics
Section titled “72. Awareness Metrics”Possible metrics:
Training Completion
Phishing Simulation Results
Reporting Rate
Repeat Failures73. Control 15 — Service Provider Management
Section titled “73. Control 15 — Service Provider Management”Organizations depend heavily on external providers.
Examples:
Cloud Providers
SaaS Vendors
Managed Security Providers
Payment Providers
IT Suppliers74. Service Provider Lifecycle
Section titled “74. Service Provider Lifecycle”Identify ↓Classify ↓Assess ↓Contract ↓Monitor ↓Offboard75. Vendor Criticality
Section titled “75. Vendor Criticality”Classify providers according to:
Data Access
System Access
Business Dependency
Service Criticality
Regulatory Impact76. Vendor Security Requirements
Section titled “76. Vendor Security Requirements”Contracts may include:
Security Requirements
Incident Notification
Audit Rights
Data Protection
Subcontractor Requirements
Termination Requirements77. Continuous Vendor Monitoring
Section titled “77. Continuous Vendor Monitoring”High-risk providers may require ongoing monitoring for:
Security Incidents
Control Changes
Compliance Changes
Financial Risk
Service Disruption78. Control 16 — Application Software Security
Section titled “78. Control 16 — Application Software Security”Applications should be designed and maintained securely.
The lifecycle includes:
Requirements ↓Design ↓Development ↓Testing ↓Deployment ↓Maintenance79. Secure Development
Section titled “79. Secure Development”Practices may include:
Secure Coding
Code Review
SAST
DAST
Dependency Scanning
Secrets Detection80. Application Vulnerabilities
Section titled “80. Application Vulnerabilities”Common issues include:
Injection
Broken Access Control
Weak Authentication
Insecure Configuration
Vulnerable Dependencies
Secrets Exposure81. Software Dependencies
Section titled “81. Software Dependencies”Modern applications rely heavily on third-party components.
Maintain:
Component Inventory
Version
Vulnerability Status
Owner82. Software Bill of Materials
Section titled “82. Software Bill of Materials”An SBOM can improve visibility into software components and dependencies.
Conceptually:
Application ↓Components ↓Libraries ↓Versions ↓Known Vulnerabilities83. Control 17 — Incident Response Management
Section titled “83. Control 17 — Incident Response Management”Organizations need defined processes for handling cybersecurity incidents.
Prepare ↓Detect ↓Triage ↓Contain ↓Eradicate ↓Recover ↓Improve84. Incident Response Plan
Section titled “84. Incident Response Plan”Define:
Roles
Responsibilities
Escalation
Communication
Technical Procedures
External Contacts85. Incident Classification
Section titled “85. Incident Classification”Example:
SEV-1Critical
SEV-2High
SEV-3Medium
SEV-4Low86. Incident Exercises
Section titled “86. Incident Exercises”Test response capabilities through:
Tabletop Exercises
Technical Simulations
Recovery Exercises87. Lessons Learned
Section titled “87. Lessons Learned”After incidents:
What Happened?
Why?
What Worked?
What Failed?
What Must Change?88. Control 18 — Penetration Testing
Section titled “88. Control 18 — Penetration Testing”Penetration testing validates whether security weaknesses can be exploited.
It complements:
Vulnerability Scanning
Configuration Assessment
Control Testing89. Vulnerability Scan vs Penetration Test
Section titled “89. Vulnerability Scan vs Penetration Test”Vulnerability Scan ↓Find PotentialWeaknesseswhile:
Penetration Test ↓Validate ExploitableAttack Paths90. Penetration Testing Scope
Section titled “90. Penetration Testing Scope”May include:
External Infrastructure
Internal Infrastructure
Web Applications
APIs
Cloud
Wirelesswithin authorized scope.
91. Rules of Engagement
Section titled “91. Rules of Engagement”Before testing define:
Scope
Authorization
Timing
Allowed Techniques
Excluded Systems
Contacts
Escalation92. Penetration Testing Findings
Section titled “92. Penetration Testing Findings”Document:
Finding
Attack Path
Evidence
Impact
Risk
Recommendation93. Remediation Validation
Section titled “93. Remediation Validation”After remediation:
Finding ↓Fix ↓Retest ↓Close94. How the CIS Controls Work Together
Section titled “94. How the CIS Controls Work Together”The Controls should not operate independently.
Example attack:
Phishing Email ↓Credential Theft ↓Account Compromise ↓Privileged Access ↓Malware ↓Data ExfiltrationMultiple CIS Controls contribute to defense.
95. Defense Example
Section titled “95. Defense Example”Control 9Email Protection ↓Control 14Security Awareness ↓Control 5Account Management ↓Control 6Access Control ↓Control 10Malware Defense ↓Control 8Logging ↓Control 13Monitoring ↓Control 17Incident ResponseThis is defense in depth.
96. CIS Controls and Enterprise Risk
Section titled “96. CIS Controls and Enterprise Risk”Controls should connect to risks.
Example:
Risk:RansomwareRelevant Controls:
04 Secure Configuration
07 Vulnerability Management
08 Audit Logging
10 Malware Defenses
11 Data Recovery
13 Network Defense
14 Awareness
17 Incident Response
18 Penetration Testing97. CIS Controls and Risk Register
Section titled “97. CIS Controls and Risk Register”A risk register may contain:
Risk
CIS Control
Safeguard
Control Owner
Effectiveness
Residual Risk98. CIS Controls and NIST CSF
Section titled “98. CIS Controls and NIST CSF”The frameworks complement each other.
Conceptually:
NIST CSF ↓Desired CybersecurityOutcomes ↓CIS Controls ↓Operational Safeguards99. Example
Section titled “99. Example”NIST CSF outcome:
Assets AreManagedCIS implementation:
Control 1Inventory and Controlof Enterprise Assets100. CIS Controls and NIST RMF
Section titled “100. CIS Controls and NIST RMF”RMF may determine:
What ControlsAre Requiredfor a System?CIS Controls can provide additional practical cybersecurity guidance and implementation priorities.
101. CIS Controls and ISO 27001
Section titled “101. CIS Controls and ISO 27001”Organizations may map CIS safeguards to ISO 27001 controls.
Example:
CIS Asset Management ↓Enterprise Control ↑ISO 27001Asset-Related Requirements102. CIS Controls and PCI DSS
Section titled “102. CIS Controls and PCI DSS”Several CIS Controls align conceptually with PCI DSS areas such as:
Secure Configuration
Access Control
Logging
Vulnerability Management
Malware Protection
Penetration TestingMapping should always account for the exact requirements of each framework.
103. Common Control Model
Section titled “103. Common Control Model”Instead of implementing separate controls for every framework:
NIST Control
ISO Control
PCI Control
CIS Safeguardorganizations can establish:
Enterprise Control ↓Mapped to ↓NIST
ISO
PCI DSS
CIS104. CIS Controls Assessment
Section titled “104. CIS Controls Assessment”A practical assessment follows:
Define Scope ↓Determine IG ↓Identify Applicable Safeguards ↓Assess Implementation ↓Collect Evidence ↓Identify Gaps ↓Assess Risk ↓Create Roadmap105. Step 1 — Define Scope
Section titled “105. Step 1 — Define Scope”Scope may include:
Enterprise
Business Unit
Cloud Environment
Critical Service
Application
Subsidiary106. Step 2 — Determine Implementation Group
Section titled “106. Step 2 — Determine Implementation Group”Consider:
Risk
Resources
Data Sensitivity
Complexity
Threat Environment107. Step 3 — Build Safeguard Register
Section titled “107. Step 3 — Build Safeguard Register”Maintain:
Control
Safeguard
Applicability
Owner
Status
Evidence108. Step 4 — Assess Implementation
Section titled “108. Step 4 — Assess Implementation”Possible statuses:
Implemented
Partially Implemented
Not Implemented
Not Applicable109. Step 5 — Collect Evidence
Section titled “109. Step 5 — Collect Evidence”Evidence may include:
Configurations
Policies
Inventories
Logs
Reports
Tickets
Screenshots
System Exports110. Step 6 — Identify Gaps
Section titled “110. Step 6 — Identify Gaps”Example:
Safeguard:Enterprise Asset Inventory
Status:Partial
Gap:Cloud AssetsNot Automatically Discovered111. Step 7 — Assess Risk
Section titled “111. Step 7 — Assess Risk”Determine:
What CouldHappen Becauseof This Gap?Example:
Unknown Cloud Asset ↓Unpatched Vulnerability ↓Internet Exposure ↓Compromise112. Step 8 — Build Improvement Roadmap
Section titled “112. Step 8 — Build Improvement Roadmap”Document:
Gap
Risk
Action
Owner
Priority
Due Date
Status113. Example Improvement Register
Section titled “113. Example Improvement Register”| Gap | Risk | Action | Priority |
|---|---|---|---|
| Unknown cloud assets | Unmanaged exposure | Deploy discovery | Critical |
| Admin MFA incomplete | Account compromise | Enforce MFA | Critical |
| Unsupported software | Exploitation | Upgrade/remove | High |
| Recovery tests missing | Recovery failure | Test backups | High |
114. Prioritize by Risk
Section titled “114. Prioritize by Risk”Do not prioritize based only on:
Safeguard NumberUse:
Risk
Asset Criticality
Threat Exposure
Business Impact
Dependencies115. CIS Implementation Roadmap
Section titled “115. CIS Implementation Roadmap”A practical roadmap may begin with:
Asset Visibility ↓Software Visibility ↓Identity ↓Secure Configuration ↓Vulnerability Management ↓Logging ↓Endpoint Protection ↓Recovery ↓Monitoring ↓Incident Response116. Phase 1 — Know the Environment
Section titled “116. Phase 1 — Know the Environment”Prioritize:
Enterprise Assets
Software Assets
Data
Accounts
Service Providers117. Phase 2 — Establish Basic Protection
Section titled “117. Phase 2 — Establish Basic Protection”Implement:
Secure Configuration
Access Controls
MFA
Patch Management
Malware Defense
Backups118. Phase 3 — Establish Visibility
Section titled “118. Phase 3 — Establish Visibility”Implement:
Logging
Central Monitoring
Network Monitoring
Vulnerability Scanning119. Phase 4 — Improve Resilience
Section titled “119. Phase 4 — Improve Resilience”Develop:
Incident Response
Recovery Testing
Security Awareness
Vendor Governance120. Phase 5 — Validate Security
Section titled “120. Phase 5 — Validate Security”Use:
Application Testing
Penetration Testing
Control Testing
Continuous Monitoring121. CIS Metrics
Section titled “121. CIS Metrics”Useful metrics may include:
Asset Inventory Coverage
Software Inventory Coverage
MFA Coverage
Secure Configuration Coverage
Vulnerability SLA Compliance
Logging Coverage
EDR Coverage
Backup Success
Recovery Test Success
Training Completion
Vendor Assessment Coverage
Incident Response Exercise Completion122. Asset Coverage Metric
Section titled “122. Asset Coverage Metric”Managed Assets────────────── × 100Known Assets123. MFA Coverage
Section titled “123. MFA Coverage”MFA-Protected Accounts────────────────────── × 100Applicable Accounts124. Vulnerability SLA Compliance
Section titled “124. Vulnerability SLA Compliance”VulnerabilitiesRemediated Within SLA────────────────────── × 100Applicable Vulnerabilities125. Logging Coverage
Section titled “125. Logging Coverage”Critical SystemsSending Required Logs────────────────────── × 100Critical Systems126. Recovery Test Success
Section titled “126. Recovery Test Success”Successful Recovery Tests───────────────────────── × 100Recovery Tests Performed127. CIS Executive Dashboard
Section titled “127. CIS Executive Dashboard”Example:
CIS SECURITY DASHBOARD
Asset Coverage 98%
Software Coverage 95%
MFA Coverage 99%
EDR Coverage 98%
Critical Patch SLA 92%
Logging Coverage 94%
Recovery Test Success 90%Do not stop at percentages.
Highlight material gaps.
128. Management Attention
Section titled “128. Management Attention”Example:
1. 12 internet-facing assets remain outside central inventory.
2. 4 privileged accounts do not enforce MFA.
3. 8 critical vulnerabilities remain past SLA.
4. 2 critical systems failed recovery testing.129. CIS Control Health
Section titled “129. CIS Control Health”A useful reporting model:
Healthy
Degraded
Failed
Unknown130. Avoid Average-Only Reporting
Section titled “130. Avoid Average-Only Reporting”Example:
CIS Compliance:96%may hide:
Privileged MFA:FAILEDRisk significance matters more than the average.
131. Control Ownership
Section titled “131. Control Ownership”Assign owners for each major control area.
Example:
| CIS Control | Example Owner |
|---|---|
| Enterprise Assets | IT Operations |
| Software Assets | IT Operations |
| Data Protection | Data Security |
| Secure Configuration | Security Engineering |
| Account Management | IAM |
| Vulnerability Management | Vulnerability Management |
| Audit Logs | SOC |
| Incident Response | SOC / CSIRT |
132. Control Evidence
Section titled “132. Control Evidence”Each safeguard should have traceable evidence.
Safeguard ↓Implementation ↓Evidence ↓Assessment ↓Result133. Continuous Monitoring
Section titled “133. Continuous Monitoring”Where possible, automate evidence for controls such as:
Asset Inventory
Software Inventory
MFA
Configuration
Vulnerabilities
Logging
Endpoint Protection
Backups134. Example Automated Control
Section titled “134. Example Automated Control”Requirement:
All Managed EndpointsMust Have EDRAutomation:
Endpoint Inventory ↓EDR Platform ↓Coverage Comparison ↓Daily Control Status135. Control Drift
Section titled “135. Control Drift”Example:
Yesterday:100% EDR Coverage
Today:98%The decrease should trigger investigation.
136. Exceptions
Section titled “136. Exceptions”Sometimes a safeguard cannot be implemented immediately.
Document:
Safeguard
Reason
Risk
Compensating Control
Owner
Approval
Expiration137. Example Exception
Section titled “137. Example Exception”System:Legacy Application
Gap:MFA Unsupported
Compensating Controls:Restricted NetworkPAM GatewayMonitoring
Expiration:90 Days138. Exceptions Should Not Become Permanent
Section titled “138. Exceptions Should Not Become Permanent”Monitor:
Exception Age
Renewals
Risk
Remediation139. Common Mistake — Implement Controls Without Inventory
Section titled “139. Common Mistake — Implement Controls Without Inventory”Without accurate inventories:
Coverage MetricsCannot Be Trusted140. Common Mistake — Treat CIS as a Checklist
Section titled “140. Common Mistake — Treat CIS as a Checklist”Weak:
Safeguard ↓Yes ↓CompleteBetter:
Safeguard ↓Implementation ↓Evidence ↓Effectiveness ↓Risk141. Common Mistake — Start with IG3
Section titled “141. Common Mistake — Start with IG3”Organizations may create unnecessary complexity by trying to implement advanced safeguards before basic hygiene is reliable.
Build the foundation first.
142. Common Mistake — Tool Equals Control
Section titled “142. Common Mistake — Tool Equals Control”Buying:
EDRdoes not automatically mean:
Malware DefenseEffectiveEvaluate:
Coverage
Configuration
Monitoring
Response143. Common Mistake — Ignore Cloud Assets
Section titled “143. Common Mistake — Ignore Cloud Assets”Modern inventories must include:
Cloud VMs
Containers
Serverless
Cloud Databases
SaaS
Cloud Identitieswhere applicable.
144. Common Mistake — Vulnerability Scanning Without Remediation
Section titled “144. Common Mistake — Vulnerability Scanning Without Remediation”Scan ↓Find ↓Reportis incomplete.
Use:
Scan ↓Prioritize ↓Remediate ↓Validate145. Common Mistake — Backup Without Testing
Section titled “145. Common Mistake — Backup Without Testing”A backup that cannot be restored provides little resilience.
146. Common Mistake — Logs Without Monitoring
Section titled “146. Common Mistake — Logs Without Monitoring”Collect Logsis different from:
Detect Threats147. Common Mistake — Training Everyone Identically
Section titled “147. Common Mistake — Training Everyone Identically”Role-based risks require role-based training.
148. Common Mistake — Ignore Service Providers
Section titled “148. Common Mistake — Ignore Service Providers”Outsourcing a service does not automatically remove organizational risk.
149. Common Mistake — Penetration Test as Annual Checkbox
Section titled “149. Common Mistake — Penetration Test as Annual Checkbox”Penetration testing should feed:
Findings ↓Remediation ↓Retesting ↓Security Improvement150. End-to-End Example — Ransomware
Section titled “150. End-to-End Example — Ransomware”Risk:
RansomwareRelevant CIS Controls include:
01 Asset Inventory
02 Software Inventory
04 Secure Configuration
05 Account Management
06 Access Control
07 Vulnerability Management
08 Audit Logging
09 Email Protection
10 Malware Defense
11 Data Recovery
13 Network Defense
14 Awareness
17 Incident Response
18 Penetration Testing151. End-to-End Example — Privileged Account Compromise
Section titled “151. End-to-End Example — Privileged Account Compromise”Risk:
AdministratorAccount CompromiseControls:
05 Account Management
06 Access Control
08 Audit Logging
13 Monitoring
17 Incident ResponseSafeguards may include:
Admin Inventory
MFA
Least Privilege
Central Logging
Monitoring152. End-to-End Example — Unknown Cloud Asset
Section titled “152. End-to-End Example — Unknown Cloud Asset”Developer CreatesCloud VM ↓Not Addedto Inventory ↓Not Scanned ↓Not Patched ↓Internet Exposed ↓CompromiseRelevant Controls:
01 Enterprise Assets
04 Secure Configuration
07 Vulnerability Management
08 Logging
13 Monitoring153. End-to-End Example — Critical Vendor
Section titled “153. End-to-End Example — Critical Vendor”Critical SaaS Provider ↓Customer Data ↓Business DependencyRelevant controls include:
03 Data Protection
15 Service Provider Management
17 Incident Response154. Enterprise CIS Operating Model
Section titled “154. Enterprise CIS Operating Model”Executive Governance ↓Cyber Risk ↓CIS Implementation Group ↓18 CIS Controls ↓Safeguards ↓Enterprise Controls ↓Technical Implementation ↓Evidence ↓Monitoring ↓Risk Reporting155. CIS Controls Assessment Checklist
Section titled “155. CIS Controls Assessment Checklist”Control 1 — Enterprise Assets
Section titled “Control 1 — Enterprise Assets”-
asset inventory maintained.
-
cloud assets included.
-
ownership defined.
-
unauthorized assets detected.
-
asset criticality maintained.
Control 2 — Software Assets
Section titled “Control 2 — Software Assets”-
software inventory maintained.
-
authorized software defined.
-
unsupported software identified.
-
unauthorized software addressed.
Control 3 — Data Protection
Section titled “Control 3 — Data Protection”-
sensitive data identified.
-
data classified.
-
access restricted.
-
encryption implemented where required.
-
retention established.
-
secure disposal established.
Control 4 — Secure Configuration
Section titled “Control 4 — Secure Configuration”-
secure baselines defined.
-
endpoints covered.
-
servers covered.
-
cloud configurations covered.
-
configuration drift monitored.
Control 5 — Account Management
Section titled “Control 5 — Account Management”-
account inventory maintained.
-
dormant accounts managed.
-
administrator accounts controlled.
-
service accounts governed.
-
account lifecycle established.
Control 6 — Access Control
Section titled “Control 6 — Access Control”-
least privilege implemented.
-
MFA implemented based on risk.
-
privileged access controlled.
-
access reviews performed.
-
access removed when no longer required.
Control 7 — Vulnerability Management
Section titled “Control 7 — Vulnerability Management”-
vulnerability scanning established.
-
scope complete.
-
vulnerabilities prioritized.
-
remediation SLAs defined.
-
remediation validated.
Control 8 — Audit Logs
Section titled “Control 8 — Audit Logs”-
logging requirements defined.
-
critical logs collected.
-
centralized logging established.
-
retention defined.
-
time synchronization maintained.
Control 9 — Email & Web
Section titled “Control 9 — Email & Web”-
email filtering implemented.
-
malicious URLs controlled.
-
browser configurations managed.
-
unsupported browsers restricted.
Control 10 — Malware Defenses
Section titled “Control 10 — Malware Defenses”-
endpoint protection deployed.
-
coverage monitored.
-
agents healthy.
-
detections monitored.
-
malware incidents investigated.
Control 11 — Data Recovery
Section titled “Control 11 — Data Recovery”-
backups configured.
-
backups protected.
-
restoration tested.
-
RTO/RPO considered.
-
recovery failures remediated.
Control 12 — Network Infrastructure
Section titled “Control 12 — Network Infrastructure”-
network inventory maintained.
-
configurations secured.
-
administrative access protected.
-
network devices patched.
-
network logs collected.
Control 13 — Network Monitoring
Section titled “Control 13 — Network Monitoring”-
network monitoring established.
-
suspicious traffic detected.
-
critical networks covered.
-
segmentation implemented based on risk.
Control 14 — Security Awareness
Section titled “Control 14 — Security Awareness”-
baseline training established.
-
role-based training implemented.
-
phishing awareness included.
-
completion monitored.
-
effectiveness measured.
Control 15 — Service Providers
Section titled “Control 15 — Service Providers”-
provider inventory maintained.
-
criticality assigned.
-
assessments performed.
-
contractual requirements established.
-
providers monitored.
-
offboarding defined.
Control 16 — Application Security
Section titled “Control 16 — Application Security”-
secure development process defined.
-
code reviewed.
-
security testing performed.
-
dependencies monitored.
-
secrets protected.
Control 17 — Incident Response
Section titled “Control 17 — Incident Response”-
IR plan maintained.
-
roles assigned.
-
escalation defined.
-
exercises conducted.
-
lessons learned tracked.
Control 18 — Penetration Testing
Section titled “Control 18 — Penetration Testing”-
testing scope defined.
-
authorization documented.
-
testing performed.
-
findings risk-rated.
-
remediation tracked.
-
retesting performed.
CIS Controls Deliverables
Section titled “CIS Controls Deliverables”After completing this lesson, you should be able to create:
01 CIS Controls Scope
02 Implementation Group Assessment
03 CIS Safeguard Register
04 Enterprise Asset Inventory
05 Software Asset Inventory
06 Data Inventory
07 Secure Configuration Register
08 Account Inventory
09 Access Control Matrix
10 Vulnerability Register
11 Logging Coverage Matrix
12 Malware Defense Coverage
13 Recovery Readiness Assessment
14 Network Security Assessment
15 Security Awareness Matrix
16 Service Provider Register
17 Application Security Assessment
18 Incident Response Readiness Assessment
19 Penetration Testing Register
20 CIS Gap Assessment
21 CIS Remediation Register
22 CIS Control-to-Risk Mapping
23 CIS-to-Framework Mapping
24 CIS Executive Dashboard
25 CIS Implementation RoadmapPractical Activity — Determine the Implementation Group
Section titled “Practical Activity — Determine the Implementation Group”Scenario:
Organization:Online Financial Services Company
Employees:2,000
Environment:AWSMicrosoft 365SaaSRemote Workforce
Data:Customer PIIFinancial Information
Security Team:Dedicated SOCSecurity EngineeringGRCDetermine whether the organization should primarily operate toward:
IG1
IG2
IG3Document your reasoning based on:
Threat
Data
Complexity
Business Impact
ResourcesPractical Activity — Perform CIS Gap Assessment
Section titled “Practical Activity — Perform CIS Gap Assessment”Assess:
Control 1Asset Inventory
Control 5Account Management
Control 6Access Control
Control 7Vulnerability Management
Control 8Logging
Control 11RecoveryFor each record:
Current State
Evidence
Gap
Risk
Owner
Recommended ActionPractical Activity — Build a Remediation Roadmap
Section titled “Practical Activity — Build a Remediation Roadmap”Findings:
12 Unknown Cloud Assets
4 Admin Accounts Without MFA
8 Critical Vulnerabilities Past SLA
20 Endpoints Without EDR
2 Failed Recovery TestsPrioritize the findings based on:
Threat Exposure
Asset Criticality
Business Impact
Likelihood
DependenciesDo not prioritize based simply on the number of findings.
Practical Activity — Map CIS to Enterprise Risks
Section titled “Practical Activity — Map CIS to Enterprise Risks”Map appropriate CIS Controls to:
Ransomware
Credential Theft
Cloud Misconfiguration
Data Breach
Third-Party Compromise
Service DisruptionThen identify:
Preventive Controls
Detective Controls
Responsive Controls
Recovery ControlsCIS Controls GRC Mindset
Section titled “CIS Controls GRC Mindset”When using CIS Controls, ask:
Do We KnowEvery Important Asset?
Do We KnowWhat SoftwareIs Running?
Do We KnowWhere SensitiveData Exists?
Are SystemsSecurely Configured?
Do We KnowEvery Account?
Is AccessLeast Privilege?
Is MFAImplemented?
Are VulnerabilitiesContinuously Identified?
Are CriticalVulnerabilitiesRemediated Quickly?
Are ImportantEvents Logged?
Can WeDetect Attacks?
Are EndpointsProtected?
Can WeRecover Data?
Have WeTested Recovery?
Are NetworksSecurely Managed?
Can WeMonitor NetworkThreats?
Are EmployeesSecurity Aware?
Are CriticalVendors Governed?
Are ApplicationsDeveloped Securely?
Can WeRespond to Incidents?
Do WeTest Our Defenses?
Which ImplementationGroup Is Appropriate?
Which SafeguardsMatter Most?
What EvidenceShows They Work?
Which ControlsAre Failing?
What RiskDoes That Create?
Who Ownsthe Remediation?
Are WeMeasuring Activity?
Or Are WeReducing Risk?That is the mindset of a GRC professional using CIS Controls v8.
Key Takeaways
Section titled “Key Takeaways”-
CIS Controls v8 provides 18 prioritized cybersecurity Controls.
-
Each Control contains practical Safeguards.
-
Implementation Groups help organizations prioritize safeguards.
-
IG1 establishes essential cyber hygiene.
-
IG2 builds stronger security capabilities for more complex organizations.
-
IG3 addresses organizations facing more sophisticated or significant risks.
-
Organizations should select implementation priorities based on risk.
-
Asset and software inventories form the foundation for many other controls.
-
Data must be identified and protected throughout its lifecycle.
-
Secure configuration baselines reduce unnecessary exposure.
-
Account and access-control management are related but distinct disciplines.
-
Vulnerability management requires discovery, prioritization, remediation, and validation.
-
Logging must support security monitoring and investigation.
-
Email and browser protections reduce common attack paths.
-
Malware defense requires coverage, monitoring, and response.
-
Backup alone does not prove recoverability.
-
Network infrastructure requires secure configuration and administration.
-
Network monitoring provides visibility into malicious activity.
-
Security awareness should include role-based training.
-
Service-provider security must be managed throughout the vendor lifecycle.
-
Application security should be integrated into the software-development lifecycle.
-
Incident-response capability must be planned and exercised.
-
Penetration testing validates exploitable attack paths.
-
CIS Controls can be mapped to NIST CSF, NIST RMF, ISO 27001, PCI DSS, and enterprise common controls.
-
Control implementation should be supported by evidence.
-
Automation can improve continuous control monitoring.
-
Control gaps should be evaluated according to risk rather than simple percentages.
-
CIS Controls should be used as an operational risk-reduction framework rather than a checklist.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What are the CIS Controls?
-
How many CIS Controls exist in v8?
-
What is a CIS Safeguard?
-
What are Implementation Groups?
-
What is IG1?
-
What is IG2?
-
What is IG3?
-
How should an organization select its Implementation Group?
-
Why is enterprise asset inventory foundational?
-
Why is software inventory important?
-
What is data classification?
-
What is configuration drift?
-
What is account lifecycle management?
-
How does account management differ from access control?
-
What is least privilege?
-
Why is MFA important?
-
What is continuous vulnerability management?
-
Why should vulnerability priority consider more than CVSS?
-
Why is centralized logging useful?
-
Why is time synchronization important?
-
What risks do email and browsers introduce?
-
What is malware defense?
-
Why must backups be tested?
-
What is network infrastructure management?
-
What is network monitoring and defense?
-
Why is network segmentation useful?
-
Why should security training be role-based?
-
What is service-provider management?
-
Why should vendor criticality be defined?
-
What is application software security?
-
What is an SBOM?
-
What is incident-response management?
-
Why should incident-response exercises be performed?
-
How does penetration testing differ from vulnerability scanning?
-
What are rules of engagement?
-
Why should penetration-test findings be retested?
-
How can CIS Controls support NIST CSF?
-
How can CIS Controls support enterprise common controls?
-
Why can overall implementation percentages be misleading?
-
Why should CIS Controls be treated as a risk-reduction program rather than a checklist?
What’s Next?
Section titled “What’s Next?”➡️ Next: 04 — COBIT 2019
In the next lesson, you will move from operational cybersecurity safeguards into enterprise governance of information and technology.
You will learn how COBIT 2019 helps organizations connect:
Enterprise Objectives ↓Stakeholder Needs ↓Governance ↓Information & Technology ↓Management Objectives ↓Controls & Processes ↓Performance ↓Business ValueYou will explore the COBIT governance and management domains:
EDMEvaluate, Direct and Monitor
APOAlign, Plan and Organize
BAIBuild, Acquire and Implement
DSSDeliver, Service and Support
MEAMonitor, Evaluate and Assessand understand how GRC professionals use COBIT to connect technology governance, enterprise risk, compliance, controls, assurance, performance, and executive oversight.
➡️ Next: 04 — COBIT 2019