The CIS Critical Security Controls (CIS Controls) are a set of cybersecurity best practices published by the Center for Internet Security (CIS). Currently in version 8, the Controls consist of 18 control groups covering the safeguards organizations may implement to reduce their most significant cybersecurity risks. CIS Controls v8 was released in May 2021.
Key takeaways
- CIS Controls v8 consists of 18 control groups and 153 individual safeguards, prioritized to deliver the highest risk reduction per safeguard implemented.
- The implementation group model lets organizations prioritize CIS Controls by maturity and resources—IG1 covers basic cyber hygiene for any organization.
- CIS Controls v8 reorganized around activities rather than technologies, making them better suited for cloud and hybrid environments.
- CIS publishes formal mappings between the Controls and NIST CSF, NIST SP 800-53, ISO 27001, PCI DSS, HIPAA, and CMMC.
- Controls 8 (audit log management), 13 (network monitoring), and 17 (incident response) map directly to continuous monitoring and detection capabilities.
The CIS Critical Security Controls are a curated, evidence-based set of security actions organized by the security outcomes designed to give security teams a defensible starting point when building or improving a security program. For organizations choosing a framework without a regulatory mandate, CIS Controls is one of the most practical options: specific enough to act on, flexible enough to fit organizations of different sizes, and structured to deliver measurable risk reduction. This page covers the 18 Controls, the implementation group model, and how CIS Controls may relate to other frameworks you may already be using.
What are the 18 CIS Controls?
CIS Controls v8 organizes safeguards into 18 control groups, each addressing a specific area of cybersecurity risk. The controls are ordered roughly by implementation priority and impact.
- Controls 1–6 cover foundational hygiene: asset inventory (Controls 1 and 2), data protection (Control 3), secure configuration (Control 4), account management (Control 5), and access control (Control 6).
- Controls 7–12 cover core security operations: vulnerability management (Control 7), audit log management (Control 8), email and web browser protections (Control 9), malware defenses (Control 10), data recovery (Control 11), and network infrastructure management (Control 12).
- Controls 13–18 cover advanced and organizational capabilities: network monitoring and defense (Control 13), security awareness training (Control 14), service provider management (Control 15), application software security (Control 16), incident response management (Control 17), and penetration testing (Control 18).
- Control 8 (audit log management) and Control 17 (incident response management) are the two controls most relevant to a security operations function—and the ones where continuous monitoring and detection capabilities may make the most impact on actual implementation.
CIS Controls implementation groups—what’s the difference?
One of the most useful features of CIS Controls v8 is the implementation group (IG) model. The 18 controls contain 153 individual safeguards in total, and not all of them are equally relevant for every organization. The IG model helps organizations prioritize based on their size, resources, and risk profile.
- IG1 (basic cyber hygiene, 56 safeguards): The basic set of security safeguards recommended by CIS. IG1 addresses the most common attacks and the highest-risk exposures. The CIS benchmark describes IG1 as appropriate for organizations with limited IT/security expertise and budget.
- IG2 (foundational, 130 total safeguards): Adds safeguards for more sophisticated threats and more complex environments. IG2 is appropriate for organizations with dedicated IT and security staff who manage sensitive data and multi-department environments. Most mid-size organizations should target IG2 according to CIS.
- IG3 (organizational, all 153 safeguards): The full set, targeting organizations in regulated environments, facing sophisticated adversaries, or with a mature security program. IG3 includes safeguards for advanced detection, enterprise-level incident response, and red team exercises.
The IG model explicitly acknowledges that not every organization should start with the same baseline. For resource-constrained organizations, IG1 provides a practical, achievable starting point without overwhelming the security team according to CIS.
CIS Controls v7 vs. v8—what changed?
CIS Controls v8, released in May 2021, consolidated 20 controls from v7 into 18 and reorganized the framework around activities rather than technologies—a response to the shift toward cloud-based, mobile, and remote-work environments. Here’s what changed:
- Consolidation from 20 to 18 controls: Several v7 controls were merged (email and web browser protections that were separate are now combined in Control 9), and some were restructured to reflect overlapping safeguards.
- Activity-based organization: v8 moves away from defining controls in terms of specific technologies (like “boundary defense”) toward defining them in terms of activities (like “network monitoring and defense”). This makes the controls more applicable to organizations with cloud-first or hybrid environments.
- Service provider management added: Control 15 is new in v8 and explicitly addresses third-party and supply chain risk, reflecting a growing recognition that vendor risk is a primary attack vector.
- Safeguard-level detail: v8 explicitly lists 153 individual safeguards (previously called “sub-controls”), making it easier to track and measure implementation at a granular level.
Organizations that implemented v7 don’t need to start over. The mapping between v7 and v8 is well-documented by CIS, and most v7 implementations translate cleanly with some reorganization.
How CIS Controls relate to other frameworks
CIS Controls are designed to be complementary to other frameworks, not competitive. The Center for Internet Security publishes mappings between CIS Controls and NIST CSF, NIST SP 800-53, ISO 27001, and other major frameworks.
- CIS Controls and NIST CSF: NIST CSF is a high-level outcome framework; CIS Controls are a specific implementation set. Organizations often use NIST CSF to describe their security program structure and CIS Controls to define what they actually implement.
- CIS Controls and NIST SP 800-53: NIST 800-53 has over 1,000 control requirements across more than 20 control families. CIS Controls IG3 maps well to NIST 800-53 but is much more concise. For example, non-federal organizations may want a practical baseline without implementing the full NIST 800-53 catalog, and CIS Controls can offer a more manageable starting point.
- CIS Controls and ISO 27001: ISO 27001 contemplates building an information security management system (ISMS) and selecting controls from a catalog. CIS Controls can serve as the control selection that supports an ISO 27001 implementation.
Using CIS Controls as a security baseline
Organizations adopting CIS Controls typically follow a three-step process: assess, prioritize, and implement.
- Assess current state: The CIS Controls Assessment Specification (CCAS) provides a methodology for evaluating how well an organization implements each safeguard. The output is a score against the full 153-safeguard list, with gaps identified at the IG level.
- Prioritize by implementation group: Most organizations start with IG1 as the target baseline, then plan toward IG2. The prioritization built into the framework means early investment delivers the highest risk reduction per safeguard implemented.
- Implement iteratively: CIS Controls don’t require a one-time deployment. Organizations typically implement one or two control areas at a time, validate implementation, and move forward. The CIS website publishes companion guides (CIS Benchmarks) for hardening specific technologies—operating systems, cloud platforms, mobile devices—that map to the Controls.
For organizations using CIS Controls to help satisfy regulatory requirements, the CIS Controls Navigator (a free tool) supports cross-referencing safeguards against specific regulatory frameworks to identify which controls may satisfy which requirements.
How does Expel help with CIS Controls?
Several of the highest-priority CIS Controls map to continuous monitoring, detection, and response capabilities—the functions that Expel’s MDR service provides.
For example, Expel’s 24×7 monitoring ingests and analyzes log data from across the environment, providing the active log review that CIS auditors and assessors may look for as evidence that Control 8 is operationally implemented—not just documented.
Control 13 (network monitoring and defense) requires organizations to detect adversarial activity. Expel’s network-level detection capabilities may support this control.
Expel also holds SOC 2 Type 2 and ISO 27001 certifications, which supports Control 15 (service provider management) by giving organizations direct access to Expel’s security posture documentation. You can read all about our Compliance program here: https://expel.com/security-compliance/ and find all our compliance documentation within our Trust Center here: https://security.expel.com
Frequently asked questions
What are the CIS Critical Security Controls?
The CIS Critical Security Controls (CIS Controls) are a prioritized set of 18 cybersecurity best practices published by the Center for Internet Security. Currently in version 8, they consist of 153 individual safeguards organized into 18 control groups that address the most common and highest-impact security risks according to CIS. CIS Controls are widely used as a practical security baseline by organizations that want actionable guidance regarding control implementation.
How many CIS Controls are there?
CIS Controls v8 has 18 control groups containing 153 individual safeguards. The 18 controls span activities from asset inventory and vulnerability management to incident response and penetration testing. Not all 153 safeguards apply equally to every organization—the implementation group model helps organizations prioritize by maturity and resource level.
What are CIS implementation groups?
CIS Controls implementation groups (IGs) are three tiers that help organizations prioritize safeguard implementation based on their size, resources, and risk profile. IG1 (56 safeguards) covers basic cyber hygiene for any organization. IG2 (130 total safeguards) adds requirements for organizations with dedicated security staff and more complex environments. IG3 (all 153 safeguards) covers the full set for organizations with mature security programs facing sophisticated threats.
What is the difference between CIS Controls v7 and v8?
CIS Controls v8 (released May 2021) consolidated the 20 controls from v7 into 18, reorganized them around activities rather than specific technologies, added a new control for service provider management (Control 15), and explicitly enumerated 153 individual safeguards. The restructuring makes v8 better suited for cloud and hybrid environments compared to v7’s more on-premises-oriented framing.
How do CIS Controls relate to NIST and other frameworks?
CIS Controls are designed to complement other frameworks. NIST CSF provides high-level outcome categories that CIS Controls help operationalize with specific safeguards. CIS Controls IG2 and IG3 also may satisfy significant portions of NIST SP 800-53, ISO 27001, and other requirements. CIS publishes formal mapping documents between the Controls and each major framework.

