CIS Critical Security Controls (CIS Controls) are a globally recognized set of best practices that help organizations improve their cybersecurity posture, often with the assistance of their Managed Service Provider.
CIS (Center for Internet Security) was founded in 2000. Its mission is “to make the connected world a safer place by developing, validating, and promoting timely best practice solutions that help people, businesses, and governments protect themselves against pervasive cyber threats.”
CIS Controls Structure and Examples
The CIS Controls are grouped into eighteen categories, shown in this table
| No. | Control Title | No. | Control Title |
|---|---|---|---|
| 01 | Inventory and Control of Enterprise Assets | 10 | Malware Defenses |
| 02 | Inventory and Control of Software Assets | 11 | Data Recovery |
| 03 | Data Protection | 12 | Network Infrastructure Management |
| 04 | Secure Configuration of Enterprise Assets and Software | 13 | Network Monitoring and Defense |
| 05 | Account Management | 14 | Security Awareness and Skills Training |
| 06 | Access Control Management | 15 | Service Provider Management |
| 07 | Continuous Vulnerability Management | 16 | Applications Software Security |
| 08 | Audit Log Management | 17 | Incident Response Management |
| 09 | Email and Web Browser Protections | 18 | Penetration Testing |
Each control has a set of measurable ‘Safeguards’ that clearly articulate one action. Here are three examples:
Safeguard 2.1 of Control 2 (Inventory and Control of Software Assets) begins with, “Establish and maintain a detailed inventory of all licensed software installed on enterprise assets.”
Safeguard 3.6 of Control 3 (Data Protection) states, “Encrypt data on end-user devices containing sensitive data.” It also lists several example technologies.
Safeguard 14.4 of Control 14 (Security Awareness and Skills Training) begins with the following: “Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data.”
Safeguards are also assigned one of three Implementation Groups (IGs), which guide organizations and their MSPs in prioritizing controls based on available resources and risk profiles.
- IG1: Basic cybersecurity hygiene, particularly for smaller businesses that may be lacking in many fundamental areas
- IG2: A more comprehensive set of controls suited for businesses with more resources and that house a moderate level of sensitive data
- IG3: For larger enterprises, those operating in regulated industries or housing a high level of sensitive data
You can download a complete list of Controls and Safeguards from the CIS website.
MSP Community Feedback
Managed Service Providers that have studied and applied the eighteen Controls and their respective Safeguards are increasingly introducing CIS Controls to their customers.
Here is what a couple of MSPs shared on a subreddit.
One MSP said that the CIS framework’s prescriptive approach is particularly beneficial for organizations ‘just getting started.’
They emphasized that CIS stands out by offering the ability to tailor control sets through Implementation Groups and assess an organization’s security posture against its industry peers.
Another MSP pointed out that CIS v8.1 is an excellent framework for most ‘standard’ customers because it offers a high-level process to guide them through essential best practices and helps them better understand their current state and future needs.
However, some end customers may still find the complete list of CIS controls overwhelming, so it’s critical to translate them into operational benefits.
This MSP concluded by stating that clients often grasp the critical takeaway that fundamental practices help them avoid downtime.
However, MSPs can go much deeper with the Controls for customers in specific industries.
Critical Security Controls and Compliances
CIS refers to the Controls as an on-ramp to compliance.
How do CIS Critical Security Controls relate to regulatory and industry compliances?
Standard regulatory compliances explain what organizations need to do to become compliant.
The organizational policies and workflows of CIS Controls, plus the configuration checks of CIS Benchmarks, show organizations how to achieve compliance.
Mapping Safeguards to Compliances
Certain Safeguards can be mapped to specific compliances, such as PCI DSS, NIST & FISMA, HIPAA, GDPR, and ISO/IEC 27001.
For example, four Control 8 (Audit Log Management) Safeguards map to ISO 27001 Objective Number A.12.2.1 (Controls against malware).
This is just one example of over 100 relationship mappings between CIS Controls and ISO 27001 Objectives. Most relationships are not one-to-one equals and are labeled ‘small subsets.’ Hence, CIS’s ‘on-ramp’ characterization.
CIS provides downloadable mappings for various compliances.
Mapping to Technology Solutions
Safeguards can also be mapped to assistive technology platforms.
For example, Actifile’s discovery, classification, and encryption capabilities address various Safeguards, including two-thirds of Data Protection Controls.
As an illustration, for Safeguard 3.6, mentioned above, Actifile encrypts data on endpoint devices using file-level encryption. This makes the files even more resilient to attacks from malware and ransomware (more than disk-level encryption, which is turned off when the machine is powered on).
CIS Critical Security Controls are carefully designed to address the most common and dangerous cyber threats, allowing businesses of all sizes to protect their systems, data, and users more effectively.
MSPs that know the Controls well can provide customers with a gap analysis between their current security state and Controls and Safeguards specifications.
Service Providers can help their SMB customers prioritize the Controls to focus on, often starting with those in IG1 that need essential security practices for the minimum standard of cyber hygiene.
IG3 Safeguards, particularly those in the Data Protection Control, may be given greater emphasis for customers with regulatory compliance needs and those who house sensitive data.


