O Oluma Cyber Security Framework Files · No. 01 Standard · Defensive Controls The CIS Critical Security Controls A prioritized, plain-language to-do list for defending any organization — built from how real attacks actually happen. v8.1 · June 2024 18 Controls 153 Safeguards 3 Implementation Groups CIS IG1IG2IG3 How we’ll read this 01 The Problem 02 Why It Exists 03 The Story 04 How It Works 05 Example 06 Who Uses It 07 Career 08 Strengths & Challenges 09 Takeaway 01 The Problem Too much security advice, no map Two decades ago, organizations weren’t short on cybersecurity advice — they were drowning in it. Every vendor, auditor, and magazine had a list of “things you absolutely must do.” A hospital, a school district, and a corner-shop business all received the same impossible homework: do everything, all at once, with whatever budget and people you happened to have. Meanwhile, attackers kept winning with the same small handful of tricks. The real problem was never a shortage of good ideas. It was the absence of priority — no one was saying clearly, “If you can only do five things this year, do these five.” 02 Why It Was Created To answer one honest question The CIS Controls exist to answer the question every overwhelmed team is really asking: “What should I do first?” Instead of an endless wish-list, they offer an ordered to-do list — arranged so the very first items block the most common and most damaging attacks. The core idea Don’t try to solve every security problem. Stop the attacks that are actually happening, in the order that gives you the most protection for the least effort. Crucially, the list is built from real attack data — not opinion. The order reflects what defenders have observed working in the field, which is why a three-person team and a three-hundred-person team can both use it to find their starting line. 03 The Story Behind It From “offense informs defense” to a global standard The Controls began with a simple, powerful principle: let the people who break into systems tell the people who defend them what actually works. 2008 Born inside U.S. defense circles A community effort — the “Consensus Audit Guidelines” — gathered defenders and offensive experts to agree on the controls that mattered most. It became known as the SANS Top 20, hosted by the SANS Institute. 2015 Handed to a nonprofit steward Stewardship passed to the Center for Internet Security (CIS), a community-driven nonprofit founded in 2000. The list became the “CIS Controls.” 2021 · v8 Reorganized for the cloud era Version 8 regrouped the list around activities rather than who owns the device — reflecting cloud, remote work, and mobile. The count was trimmed from 20 controls to 18. 2024 · v8.1 Governance joins the picture The current release added a “Govern” function to line up with NIST’s updated Cybersecurity Framework (CSF 2.0), plus a new Documentation asset class for plans and policies. 04 How It Works 18 controls, 153 safeguards, 3 starting points Each of the 18 controls breaks down into specific, measurable safeguards — 153 in total. The genius of the system is that you don’t tackle them all at once. They’re sorted into three Implementation Groups so you know exactly where to begin. IG1 · 56 safeguards Essential cyber hygiene The minimum standard every organization should meet — the basics that stop the most common attacks. If you do nothing else, do this. IG2 · builds on IG1 Growing organizations For teams with more resources and more at stake — handling sensitive data across multiple departments and systems. IG3 · all safeguards Mature, high-risk environments For organizations facing sophisticated, targeted attacks — critical infrastructure, large enterprises, and anyone defending highly sensitive data. Every safeguard is tagged with a security function and tied to real attacker behavior (mapped to MITRE ATT&CK). Version 8.1 added the sixth function, Govern: IdentifyProtectDetectRespondRecoverGovern ★ new CIS Controls vs. CIS Benchmarks People often mix these up. The Controls tell you what to do across the whole organization. The Benchmarks are step-by-step settings for specific technology — how to securely configure Windows, Linux, AWS, and more. They work hand in hand. The full set of 18, in priority order: 01 Inventory & control of enterprise assets 02 Inventory & control of software assets 03 Data protection 04 Secure configuration 05 Account management 06 Access control management 07 Continuous vulnerability management 08 Audit log management 09 Email & web browser protections 10 Malware defenses 11 Data recovery 12 Network infrastructure management 13 Network monitoring & defense 14 Security awareness & skills training 15 Service provider management 16 Application software security 17 Incident response management 18 Penetration testing 05 Real-World Example A small county with a three-person IT team Picture a local county government. Three people run all the technology, and there’s no budget for a 500-page security program. A massive framework would sit on a shelf, untouched. So they start with IG1 — and only IG1. Their IG1 starting list Five moves that shut most doors List every device and app the county actually owns Turn on multi-factor authentication everywhere it counts Patch and update on a regular schedule Train staff to recognize phishing emails Back up data so ransomware can’t end the story None of this is exotic. But together, these basics close the door on the majority of attacks they’ll realistically face. In fact, CIS Controls are written into “safe harbor” laws in states like Ohio, Utah, Connecticut, and Iowa — adopt them, and you gain legal protection if a breach still occurs. 06 Who Uses It From town halls to global enterprises 🏛️ Government & public sector U.S. state, local, tribal & territorial bodies — supported through CIS’s MS-ISAC community. 🏪 Small & mid-sized business Teams with limited resources who need a clear, affordable place to begin. 🏢 Large enterprises Used as a measurable baseline beneath broader governance programs. A big reason for its reach: the Controls map to other major frameworks. One set of actions can produce evidence for many compliance demands at once. maps to NIST CSF ISO 27001 HIPAA PCI DSS SOC 2 CMMC 07 Career Relevance The friendliest on-ramp into cyber & GRC If you’re entering security — especially Governance, Risk & Compliance — CIS is the gentlest place to start. It’s concrete: you can point at a safeguard and know exactly what “done” looks like, which is rarely true of bigger, more abstract frameworks. GRC analyst Gap & risk work Use the Controls to run gap assessments, build risk registers, and show leadership a clear path to “better.” Sysadmin / engineer Hardening systems Apply the companion CIS Benchmarks to lock down real machines and cloud accounts. Auditor / consultant A shared yardstick Measure an organization against a recognized baseline, then translate findings into action everyone understands. “Familiar with CIS Controls” on a résumé signals something employers value: that you can turn security theory into security action. 08 Strengths & Challenges Honest trade-offs ✦ Strengths Prioritized — tells you what to do first Free to download and use Practical and measurable, not abstract Grounded in real attack data Maps cleanly to nearly every other framework ⚠ Challenges Strong on tactics, lighter on the full risk & governance story Not a complete management system like ISO 27001 Even IG1 takes real effort and ongoing upkeep Best paired with a broader framework, not used alone 09 Final Takeaway If frameworks feel overwhelming, CIS is where you start. It turns the impossible task of “secure everything” into “do these things, in this order.” For a small team, a nonprofit, or a community just beginning their journey, that first ordered list is the difference between paralysis and progress. Master IG1, and you’ve already moved further than most.