GRC Careers

HomeResourcesCIS Controls

CS-105 · Compliance & Frameworks

CIS Controls

A prioritized set of practical safeguards for building a defensible security baseline.

Executive Summary

The CIS Controls are a prioritized set of practical safeguards published by the Center for Internet Security to help organizations defend against the most common and damaging attacks. They are organized so that a team with limited resources can start with the highest-value basics and grow from there. Implementation groups let organizations pick a scope that matches their size, risk, and capability.

What It Is

The CIS Controls are a community-developed, prioritized list of defensive actions, called safeguards, grouped into a manageable number of top-level controls. Rather than describing broad outcomes, they focus on concrete, testable measures such as maintaining an inventory of hardware and software, controlling administrative privileges, and managing configurations. The set is intentionally ordered so the earliest controls deliver the most protection per unit of effort. To make adoption realistic, the safeguards are sorted into implementation groups (commonly referred to as IG1, IG2, and IG3), where the first group represents essential cyber hygiene for smaller organizations and each higher group adds safeguards for organizations with greater risk and resources.

Why It Matters

Many organizations know they should improve security but do not know where to begin. The CIS Controls answer that question by giving a defensible starting order grounded in how real attacks actually unfold. Because the safeguards are specific and measurable, they are easy to audit and to translate into projects, budgets, and metrics. They also map to broader frameworks, so effort spent implementing CIS Controls supports compliance with other requirements at the same time. For professionals, the controls provide a practical bridge between high-level frameworks and the day-to-day technical work of reducing risk.

How It Works

An organization first selects the implementation group that fits its size, risk profile, and resources. It then assesses which safeguards in that group are already in place, treats the gaps as a prioritized backlog, and works down the list. Because the controls are ordered by impact, early wins such as building an accurate asset inventory and enforcing multi-factor authentication tend to reduce risk quickly. Each safeguard is written to be measurable, which lets teams track coverage over time and demonstrate progress. Many organizations map the CIS Controls to a broader framework like the NIST CSF so that improving the controls also advances their overall program.

Architecture Diagram

Know your assets: hardware and software inventory
Control access and configurations
Protect data, email, and browsers
Detect with logging and continuous monitoring
Respond with incident handling and recovery
Safeguards build upward: essential hygiene first, then broader coverage, then advanced defenses as risk and resources grow.

Visual Workflow

Choose the implementation group that matches your organization's size, risk, and resources.Inventory hardware, software, and data so you know what must be protected.Assess which safeguards in your group are already implemented.Treat the gaps as a prioritized backlog and address the highest-impact safeguards first.Measure coverage of each safeguard and track progress over time.Reassess as the organization grows or its risk profile changes.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Asset inventory tool
Discovers and tracks hardware and software so nothing is unmanaged
Configuration management tool
Applies secure baselines and detects drift
Vulnerability scanner
Finds weaknesses to prioritize against the safeguards
GRC platform
Tracks safeguard coverage, evidence, and framework mappings

Industry Standards

CIS Critical Security Controls
The prioritized safeguards themselves, grouped into implementation groups
CIS Benchmarks
Secure configuration baselines that support several safeguards
NIST Cybersecurity Framework (CSF) 2.0
Broader framework the CIS Controls commonly map to

Career Relevance

The CIS Controls are widely used by GRC analysts, compliance analysts, security auditors, and CISOs to set a defensible baseline and to translate frameworks into concrete work. Security engineers and IT staff often implement the safeguards directly, while auditors and risk professionals use their measurable nature as evidence. For the privacy and AI governance professionals AI-Governance-Jobs.com serves, the controls offer a practical way to show that governance decisions are backed by real safeguards.

Interview Questions

Related Certifications

CompTIA Security+ ISC2 CISSP ISACA CISM

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

How are the CIS Controls different from the NIST CSF?

The NIST CSF describes high-level outcomes and functions, while the CIS Controls give specific, prioritized safeguards to implement. Many teams use the CSF to structure their program and the CIS Controls to carry out the technical work, mapping one to the other.

What are implementation groups?

Implementation groups sort the safeguards by the level of risk and resources an organization has. The first group represents essential cyber hygiene suitable for smaller organizations, and each higher group adds safeguards for those with greater risk and capability.

Are the CIS Controls free to use?

The controls are published by the Center for Internet Security and are broadly available for organizations to adopt. Some supporting resources and tools may have their own terms, so confirm details on the official CIS site.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+ISC2 CISSPISACA CISM

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: CIS Controls
  3. Go deeper: NIST Cybersecurity Framework (CSF)
  4. Go deeper: ISO/IEC 27001
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Compliance & Frameworks

Share this LinkedIn Facebook X Email