Skip to content
Oluma Cyber Security Awareness
Standard · Defensive Controls

The CIS Critical Security Controls

A prioritized, plain-language to-do list for defending any organization — built from how real attacks actually happen.

v8.1 · June 2024 18 Controls 153 Safeguards 3 Implementation Groups
01 The Problem

Too much security advice, no map

Two decades ago, organizations weren’t short on cybersecurity advice — they were drowning in it. Every vendor, auditor, and magazine had a list of “things you absolutely must do.” A hospital, a school district, and a corner-shop business all received the same impossible homework: do everything, all at once, with whatever budget and people you happened to have.

Meanwhile, attackers kept winning with the same small handful of tricks. The real problem was never a shortage of good ideas. It was the absence of priority — no one was saying clearly, “If you can only do five things this year, do these five.”

03 The Story Behind It

From “offense informs defense” to a global standard

The Controls began with a simple, powerful principle: let the people who break into systems tell the people who defend them what actually works.

2008
Born inside U.S. defense circles
A community effort — the “Consensus Audit Guidelines” — gathered defenders and offensive experts to agree on the controls that mattered most. It became known as the SANS Top 20, hosted by the SANS Institute.
2015
Handed to a nonprofit steward
Stewardship passed to the Center for Internet Security (CIS), a community-driven nonprofit founded in 2000. The list became the “CIS Controls.”
2021 · v8
Reorganized for the cloud era
Version 8 regrouped the list around activities rather than who owns the device — reflecting cloud, remote work, and mobile. The count was trimmed from 20 controls to 18.
2024 · v8.1
Governance joins the picture
The current release added a “Govern” function to line up with NIST’s updated Cybersecurity Framework (CSF 2.0), plus a new Documentation asset class for plans and policies.
04 How It Works

18 controls, 153 safeguards, 3 starting points

Each of the 18 controls breaks down into specific, measurable safeguards — 153 in total. The genius of the system is that you don’t tackle them all at once. They’re sorted into three Implementation Groups so you know exactly where to begin.

IG1 · 56 safeguards
Essential cyber hygiene
The minimum standard every organization should meet — the basics that stop the most common attacks. If you do nothing else, do this.
IG2 · builds on IG1
Growing organizations
For teams with more resources and more at stake — handling sensitive data across multiple departments and systems.
IG3 · all safeguards
Mature, high-risk environments
For organizations facing sophisticated, targeted attacks — critical infrastructure, large enterprises, and anyone defending highly sensitive data.

Every safeguard is tagged with a security function and tied to real attacker behavior (mapped to MITRE ATT&CK). Version 8.1 added the sixth function, Govern:

IdentifyProtectDetectRespondRecoverGovern ★ new
CIS Controls vs. CIS Benchmarks

People often mix these up. The Controls tell you what to do across the whole organization. The Benchmarks are step-by-step settings for specific technology — how to securely configure Windows, Linux, AWS, and more. They work hand in hand.

The full set of 18, in priority order:

01 Inventory & control of enterprise assets
02 Inventory & control of software assets
03 Data protection
04 Secure configuration
05 Account management
06 Access control management
07 Continuous vulnerability management
08 Audit log management
09 Email & web browser protections
10 Malware defenses
11 Data recovery
12 Network infrastructure management
13 Network monitoring & defense
14 Security awareness & skills training
15 Service provider management
16 Application software security
17 Incident response management
18 Penetration testing
06 Who Uses It

From town halls to global enterprises

🏛️
Government & public sector
U.S. state, local, tribal & territorial bodies — supported through CIS’s MS-ISAC community.
🏪
Small & mid-sized business
Teams with limited resources who need a clear, affordable place to begin.
🏢
Large enterprises
Used as a measurable baseline beneath broader governance programs.

A big reason for its reach: the Controls map to other major frameworks. One set of actions can produce evidence for many compliance demands at once.

maps to NIST CSF ISO 27001 HIPAA PCI DSS SOC 2 CMMC
07 Career Relevance

The friendliest on-ramp into cyber & GRC

If you’re entering security — especially Governance, Risk & Compliance — CIS is the gentlest place to start. It’s concrete: you can point at a safeguard and know exactly what “done” looks like, which is rarely true of bigger, more abstract frameworks.

GRC analyst
Gap & risk work
Use the Controls to run gap assessments, build risk registers, and show leadership a clear path to “better.”
Sysadmin / engineer
Hardening systems
Apply the companion CIS Benchmarks to lock down real machines and cloud accounts.
Auditor / consultant
A shared yardstick
Measure an organization against a recognized baseline, then translate findings into action everyone understands.

“Familiar with CIS Controls” on a résumé signals something employers value: that you can turn security theory into security action.

09 Final Takeaway
If frameworks feel overwhelming, CIS is where you start.

It turns the impossible task of “secure everything” into “do these things, in this order.” For a small team, a nonprofit, or a community just beginning their journey, that first ordered list is the difference between paralysis and progress. Master IG1, and you’ve already moved further than most.