by SigmaSRC Team
The CIS Critical Security Controls provide a prioritized set of actions to protect organizations from cyber attacks. This guide explains how to implement CIS Controls v8 effectively.
The CIS Critical Security Controls (formerly SANS Top 20) are a prioritized set of cybersecurity best practices developed by the Center for Internet Security. Version 8, released in 2021, organizes 18 controls into three Implementation Groups based on organizational resources.
CIS Controls are organized into three Implementation Groups:
| Group | Description | Organizations |
|---|---|---|
| IG1 | Essential cyber hygiene | Small businesses, limited IT staff |
| IG2 | Expanded controls | Enterprise IT, sensitive data |
| IG3 | Comprehensive security | Sophisticated adversaries, regulatory requirements |
IG1 is the starting point—organizations should implement all IG1 safeguards before moving to IG2 and IG3.
| Implementation Group | Safeguards | Cumulative |
|---|---|---|
| IG1 | 56 | 56 |
| IG2 | 74 | 130 |
| IG3 | 23 | 153 |
Purpose: Know what's on your network
Key Safeguards:
Implementation Tips:
Purpose: Know what software is running
Key Safeguards:
Implementation Tips:
Purpose: Protect sensitive data
Key Safeguards:
Implementation Tips:
Purpose: Establish secure baselines
Key Safeguards:
Implementation Tips:
Purpose: Manage the lifecycle of accounts
Key Safeguards:
Implementation Tips:
Purpose: Control access to systems and data
Key Safeguards:
Implementation Tips:
Purpose: Find and fix vulnerabilities
Key Safeguards:
Implementation Tips:
Purpose: Collect and review security logs
Key Safeguards:
Implementation Tips:
Purpose: Protect against web and email threats
Key Safeguards:
Implementation Tips:
Purpose: Prevent and detect malware
Key Safeguards:
Implementation Tips:
Purpose: Ensure ability to recover from incidents
Key Safeguards:
Implementation Tips:
Purpose: Secure network devices
Key Safeguards:
Implementation Tips:
Purpose: Detect and respond to network threats
Key Safeguards:
Implementation Tips:
Purpose: Build security culture
Key Safeguards:
Implementation Tips:
Purpose: Manage third-party security
Key Safeguards:
Implementation Tips:
Purpose: Secure application development
Key Safeguards:
Implementation Tips:
Purpose: Prepare for and respond to incidents
Key Safeguards:
Implementation Tips:
Purpose: Test defenses through simulated attacks
Key Safeguards:
Implementation Tips:
Focus on essential cyber hygiene:
Add enterprise-grade controls:
Implement sophisticated defenses:
SigmaSRC automates CIS Controls implementation with: