Resources

CIS Critical Security Controls Guide for Businesses

Understand CIS Controls v8.1, Implementation Groups IG1, IG2 and IG3, and how businesses can use the framework to prioritize cybersecurity improvements.

We like the CIS Controls because they give management a practical order of operations. Instead of buying whatever security product is being promoted this month, a business can work through a defined set of safeguards and see where the real gaps are.

What we look for

We do not assign a CIS Implementation Group by employee count alone. A smaller company with regulated data, critical production systems or a low tolerance for downtime may need stronger safeguards than a larger company with a simpler environment.

The CIS Critical Security Controls are a prioritized set of cybersecurity best practices designed to help organizations defend against common attacks.

CIS Controls version 8.1 organizes safeguards into 18 Controls and three Implementation Groups.

Why Use CIS Controls?

Many organizations struggle with cybersecurity because there are hundreds of products and recommendations competing for attention.

CIS provides a structured way to prioritize actions.

The framework covers the entire environment: devices, software, data, users, networks, monitoring, backups, vendors, applications and incident response.

The 18 CIS Controls

  1. Inventory and Control of Enterprise Assets
  2. Inventory and Control of Software Assets
  3. Data Protection
  4. Secure Configuration of Enterprise Assets and Software
  5. Account Management
  6. Access Control Management
  7. Continuous Vulnerability Management
  8. Audit Log Management
  9. Email and Web Browser Protections
  10. Malware Defenses
  11. Data Recovery
  12. Network Infrastructure Management
  13. Network Monitoring and Defense
  14. Security Awareness and Skills Training
  15. Service Provider Management
  16. Application Software Security
  17. Incident Response Management
  18. Penetration Testing

Implementation Group 1

CIS describes IG1 as essential cyber hygiene and the starting point for organizations.

CIS Controls v8 and v8.1 identify 56 safeguards in IG1.

IG1 focuses on foundational protections against common attacks.

Implementation Group 2

IG2 builds on IG1 and adds safeguards for organizations with more complexity and risk.

CIS states that IG2 includes 74 additional safeguards beyond the 56 in IG1.

An IG2 organization may have multiple departments, more complicated infrastructure, sensitive information or operational requirements that justify additional controls.

Implementation Group 3

IG3 builds on IG1 and IG2.

CIS states that the complete set totals 153 safeguards in Controls v8 and v8.1.

IG3 is intended for organizations with higher risk and the resources required for more advanced security capabilities.

Implementation Groups Are Risk-Based

Employee count alone should not determine an Implementation Group.

Organizations should consider:

  • Data sensitivity
  • Regulatory requirements
  • Operational complexity
  • Business impact of downtime
  • Threat profile
  • Available security resources
  • Customer requirements
  • Internet-facing systems
  • Third-party dependencies

Practical Implementation Approach

Phase 1: Inventory

Identify assets, software, cloud services, accounts and critical data.

A business cannot secure systems it does not know exist.

Phase 2: Secure Identities and Systems

Standardize configurations, patch systems, remove unnecessary administrative rights and establish strong authentication.

Phase 3: Protect Data

Understand where sensitive data exists and control access, retention and backups.

Phase 4: Improve Detection

Centralize security logs and deploy monitoring appropriate to the organization's risk.

Phase 5: Prepare for Recovery

Test backup restoration and create an incident response plan.

Phase 6: Measure and Improve

Cybersecurity should be reassessed periodically as the business, threats and technology change.

Common questions

Is CIS Controls only for large businesses?

No. The Implementation Group model specifically provides a prioritized entry point for organizations with different levels of resources and risk.

Is CIS certification required?

The CIS Controls are a framework. Whether a particular certification, attestation or contractual requirement applies depends on the organization and the program it participates in.

Can CIS Controls support compliance?

CIS publishes mappings to multiple cybersecurity and regulatory frameworks. Using CIS can help organize security work, but organizations must evaluate each applicable requirement separately.

CIS Controls Support From Huff Data Systems

Huff Data Systems can help businesses assess existing controls, identify gaps and create a technical roadmap using the CIS Controls as a reference framework.

Sources and further reading

This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.

Ready to move forward?

Want help applying this to your business?

We can look at your current environment and tell you which parts of this guide matter most for you.

Talk With Huff Data