Compliance · Global
CIS Controls v8Implementation Groups 1-3

CIS Controls

Plain-English definition

The CIS Controls are a prioritized set of 18 safeguards from the Center for Internet Security, organized to be more prescriptive and immediately actionable than broader frameworks like ISO 27001 or NIST CSF. They scale by Implementation Group (IG1 for basic cyber hygiene, up to IG3 for organizations facing sophisticated threats), so the expected control set matches your actual size and risk profile.

Often used as a practical starting baseline before pursuing a certifiable framework like ISO 27001.

Who needs it

Organizations that want concrete, prioritized security actions rather than a broad risk-management framework to interpret, and companies building a security program from a low baseline who need to know what to do first.

Key requirements

Implementation of safeguards appropriate to your assigned Implementation Group, starting with foundational controls (asset inventory, access control, vulnerability management) before advancing to more sophisticated safeguards.

Cyber/privacy implications

Because the Controls are ranked by priority, gaps in the earliest controls (asset and software inventory, access control) undermine the effectiveness of every control built on top of them.

Assessment methodology

Implementation Group determination based on organization size and risk profile, safeguard-by-safeguard gap assessment, and a prioritized implementation roadmap starting from IG1.

Implementation phases

01
Scope

Determine your Implementation Group and assess current safeguard coverage.

02
Implement

Prioritized rollout starting from foundational IG1 safeguards.

03
Mature

Advance toward IG2/IG3 safeguards as your risk profile requires.

Evidence & documentation requirements

Asset and software inventories, access control records, vulnerability management logs, and a documented safeguard implementation status mapped to your Implementation Group.

Common mistakes

Jumping to advanced IG3 safeguards while foundational IG1 controls like asset inventory remain incomplete; treating the Controls as a static checklist instead of a prioritized, continuously maintained baseline.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

How do I know which Implementation Group applies to us?
It's based on your organization's size, IT resources, and risk profile; we determine this as the first step of the assessment.
Is this a certifiable standard?
No, there's no formal certification for CIS Controls, but implementation status is often referenced as evidence of security maturity by customers and insurers.
How does this relate to CIS Benchmarks?
CIS Controls are the prioritized safeguard list; CIS Benchmarks are detailed configuration standards for specific platforms (AWS, Azure, operating systems). We reference Benchmarks during our Cloud Security engagements.

Request a Gap Assessment

Find out your Implementation Group and where your current safeguards stand.

Request a Gap Assessment →