Skip to main content

CIS Controls.

The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyCybersecurity operationsAll entries

The Cyber Academy take

The CIS Critical Security Controls are a prioritised set of 18 control categories published by the Center for Internet Security. Implementation groups (IG1, IG2, IG3) match organisation maturity. The fastest way to take a small or mid-sized organisation from zero to defensible. Maps neatly onto ISO 27001 Annex A.

What the CIS Controls actually are

The CIS Critical Security Controls are an ordered, opinionated answer to a question every defender faces: of all the things you could do, what should you do first? Published and maintained by the Center for Internet Security, they distil real-world attack data into a prioritised set of safeguards grouped into 18 control categories, from inventory of enterprise assets and software through data protection, access control, continuous vulnerability management, audit log management, and incident response. Unlike a framework that tells you to establish a process, the Controls tell you concretely what to implement and roughly in what order, which is why they are often the fastest route from no security programme to a defensible one.

The defining feature is prioritisation. The list is not alphabetical or theoretical; the earlier controls are the ones that block the most common attacks. Knowing what hardware and software you have, configuring it securely, controlling administrative privileges, and patching known vulnerabilities prevent a large share of real incidents before you spend a euro on advanced tooling. That ordering is the value: a small team with limited time can start at the top and work down, confident it is closing the gaps attackers actually exploit.

Implementation Groups: IG1, IG2, IG3

The Controls scale through three Implementation Groups so the same catalogue serves a two-person business and a multinational. IG1 is defined as basic cyber hygiene, the minimum set every organisation should have in place, designed for enterprises with limited expertise and resources protecting against unsophisticated, opportunistic attacks. IG2 adds safeguards for organisations managing more sensitive data and facing more capable adversaries. IG3 is the full set, intended for mature organisations that hold critical assets and must defend against targeted, sophisticated attacks. Each group is cumulative: IG2 includes everything in IG1, and IG3 includes everything in IG1 and IG2.

CIS Implementation Groups
GroupWho it fitsPosture
IG1Small to mid-sized organisations, limited IT and security resourcesEssential cyber hygiene, baseline defence
IG2Organisations holding more sensitive data, dedicated security staffHardened against more capable attackers
IG3Mature organisations with critical assets and high exposureFull safeguard set against targeted attacks

In practice you self-assess to an Implementation Group, then treat the safeguards in that group as your work plan. Most small and mid-sized organisations should aim squarely at IG1 first and only move to IG2 once it holds. This is what makes the Controls approachable where a full management system can feel out of reach: you are handed a finite, testable checklist sized to your reality.

Where they sit next to ISO 27001 and other frameworks

The CIS Controls are a controls catalogue, not a certifiable management system, and that distinction matters. ISO 27001 certifies that you operate an information security management system with risk assessment, a Statement of Applicability, and continual improvement; CIS gives you a concrete, prioritised set of technical and operational safeguards to implement underneath it. They are complementary rather than competing. CIS publishes mappings from its safeguards to ISO 27001 Annex A and to other references such as NIST frameworks, so the implementation work you do for CIS becomes evidence you can present against an ISO control set. Teams frequently use CIS to drive the hands-on hardening and then map that effort up to whatever framework their auditors or customers require.

Frequently asked questions

01How many CIS Controls are there?

There are 18 control categories in the current version, each containing a set of specific safeguards. The number of safeguards you implement depends on which Implementation Group you target.

02Which Implementation Group should a small organisation start with?

IG1, defined as essential cyber hygiene. It is the minimum baseline designed for organisations with limited security resources, and it should be fully in place before moving to IG2.

03Are the CIS Controls a certification?

No. They are a prioritised catalogue of safeguards, not a certifiable management system. There is no CIS certificate to display, though you can self-assess and use the Controls to drive a programme that supports certifications like ISO 27001.

04How do the CIS Controls relate to ISO 27001?

They complement it. CIS gives you concrete, prioritised technical safeguards to implement, while ISO 27001 certifies the management system around them. CIS publishes mappings to ISO 27001 Annex A so the same work supports both.

05Are the CIS Controls free to use?

Yes. The Controls and their supporting mappings and tools are published by the Center for Internet Security and are freely available, which is part of why they are a popular starting point for resource-constrained teams.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.