Skip to content

CIS Controls v8.1: All 18 Controls, IG1 to IG3, and CIS vs NIST

The CIS Controls v8.1 explained: all 18 Controls and 153 Safeguards, Implementation Groups IG1 to IG3, the IG1 checklist, and how CIS compares with NIST CSF.

Invadel Team13 min read

The CIS Controls, formally the CIS Critical Security Controls, are a prioritized set of 18 security controls published by the Center for Internet Security, broken down into 153 specific actions called Safeguards. They exist to answer one practical question: with limited time and budget, what should an organization do first to stop the attacks that actually happen? Version 8.1, released in June 2024, is the current edition. This guide lists all 18 Controls, explains the three Implementation Groups, turns IG1 into a working checklist, and compares the CIS Controls with the NIST Cybersecurity Framework.

A note on where we fit. Most of the Controls are things your own team implements: inventories, configuration, accounts, backups, training. Two of them test whether those defenses hold, Control 7 (vulnerability scanning) and Control 18 (penetration testing), and Control 18 calls for a qualified party to do the testing. That testing is the part Invadel does. The rest of this guide is useful whether or not you ever hire anyone.

CIS Controls at a glance

Question Answer
Publisher Center for Internet Security (CIS), a nonprofit
Current version v8.1, released June 2024 (CIS announcement)
Structure 18 Controls containing 153 Safeguards
Prioritization Three Implementation Groups: IG1 (56 Safeguards), IG2 (74 more), IG3 (the last 23)
What changed in v8.1 The “Govern” security function from NIST CSF 2.0 added, asset classes revised, some Safeguard descriptions clarified, glossary expanded
Formerly known as The SANS Top 20; v8 in 2021 reorganized 20 Controls into 18
Mandatory? Not by itself; it becomes a benchmark when a law, contract or insurer points to it

The Controls began in 2008 as a consortium effort known as the SANS Top 20, came under CIS ownership with Version 6 in 2015, and gained Implementation Groups in Version 7.1. Version 8, released in May 2021, cut the list from 20 to 18 by grouping Controls around activities rather than around who manages each device (CIS on the evolution of the Controls). Version 8.1 kept the same 18 Controls and 153 Safeguards and aligned the mappings with NIST CSF 2.0.

The 18 CIS Controls

Safeguard counts are from CIS’s own documentation. The IG1 column shows how many of each Control’s Safeguards belong to IG1, the starting set every organization is expected to implement.

# Control What it covers Safeguards In IG1
1 Inventory and Control of Enterprise Assets Knowing every device connected to your infrastructure, and dealing with unknown ones 5 2
2 Inventory and Control of Software Assets Knowing what software runs, keeping it supported, removing what is not authorized 7 3
3 Data Protection Classifying, handling, retaining, encrypting and disposing of data 14 6
4 Secure Configuration of Enterprise Assets and Software Hardened baselines, host firewalls, session locking, default accounts 12 7
5 Account Management Account inventory, unique passwords, dormant accounts, dedicated admin accounts 6 4
6 Access Control Management Granting and revoking access, and MFA for external apps, remote access and admins 8 5
7 Continuous Vulnerability Management Patching, vulnerability scanning and remediation on a defined cadence 7 4
8 Audit Log Management Collecting, storing, reviewing and retaining logs 12 3
9 Email and Web Browser Protections Supported browsers and email clients, DNS filtering, blocking risky file types 7 2
10 Malware Defenses Anti-malware, automatic updates, removable media controls 7 3
11 Data Recovery Automated, protected and isolated backups with a recovery process 5 4
12 Network Infrastructure Management Up-to-date network devices, secure architecture, secure management 8 1
13 Network Monitoring and Defense Centralized alerting, intrusion detection, traffic filtering between segments 11 0
14 Security Awareness and Skills Training A workforce training program, including social engineering 9 8
15 Service Provider Management Inventory and oversight of vendors that handle your data 7 1
16 Application Software Security Secure development, code-level checks and application testing 14 0
17 Incident Response Management Named responders, contacts and a reporting process 9 3
18 Penetration Testing A testing program, external and internal tests, remediation and validation 5 0
Total 153 56

Two things stand out. First, IG1 leans heavily on the basics: inventory, configuration, accounts, backups and training carry most of its 56 Safeguards. Second, three Controls have nothing in IG1 at all (13, 16 and 18). Network monitoring, application security and penetration testing start at IG2, because they assume staff who can act on what they find.

Implementation Groups: IG1, IG2 and IG3

Implementation Groups are how CIS tells you which Safeguards to do first. They are cumulative: IG2 includes everything in IG1, and IG3 includes everything.

Group Safeguards Who it is written for (CIS’s descriptions)
IG1 56 “Essential cyber hygiene.” Typically small to medium-sized organizations with limited IT and security expertise (CIS on IG1)
IG2 56 + 74 = 130 Organizations with staff responsible for managing and protecting IT infrastructure, supporting several departments with different risk profiles
IG3 All 153 Organizations with security specialists and sensitive data or functions under regulatory and compliance oversight

CIS presents IG1 as the minimum standard for every enterprise, so everyone starts there, whatever its size. An organization that meets IG2 but skipped part of IG1 has a gap in exactly the controls attackers probe first.

The IG1 checklist: all 56 Safeguards by Control

This is IG1 as a working checklist, with Safeguard numbers so you can match it to the CIS documents. Mark each one done, partial or not started, and name an owner for each gap.

  • Control 1, assets (1.1, 1.2): a detailed inventory of every enterprise asset; a process to remove, block or quarantine unauthorized assets weekly.
  • Control 2, software (2.1 to 2.3): a licensed-software inventory; only supported software authorized; unauthorized software removed or given a documented exception.
  • Control 3, data (3.1 to 3.6): a data management process; a data inventory; access control lists based on need to know; retention limits; secure disposal; encryption on end-user devices.
  • Control 4, configuration (4.1 to 4.7): a secure configuration process for devices and for network infrastructure; automatic session locking; firewalls on servers and on end-user devices; secure management of assets; default accounts managed or disabled.
  • Control 5, accounts (5.1 to 5.4): an account inventory; unique passwords; dormant accounts disabled after 45 days; admin rights limited to dedicated admin accounts.
  • Control 6, access (6.1 to 6.5): a process to grant access and one to revoke it; MFA on externally exposed applications, on remote network access and on administrative access.
  • Control 7, vulnerabilities (7.1 to 7.4): a documented vulnerability management process; a risk-based remediation process reviewed monthly; automated operating system and application patching at least monthly.
  • Control 8, logging (8.1 to 8.3): an audit log management process; logs collected; enough log storage.
  • Control 9, email and web (9.1, 9.2): only supported browsers and email clients; DNS filtering on all assets.
  • Control 10, malware (10.1 to 10.3): anti-malware on all assets; automatic signature updates; autorun and autoplay disabled for removable media.
  • Control 11, recovery (11.1 to 11.4): a data recovery process; automated backups; backups protected like the original data; an isolated copy of recovery data.
  • Control 12, network (12.1): network infrastructure kept up to date, with versions reviewed at least monthly.
  • Control 14, training (14.1 to 14.8): an awareness program covering social engineering, authentication, data handling, accidental exposure, incident reporting, missing updates and insecure networks.
  • Control 15, providers (15.1): an inventory of service providers.
  • Control 17, incidents (17.1 to 17.3): a named incident handler and backup; contact details for reporting; a process for the workforce to report incidents.

Four IG1 Safeguards do much of the work against ransomware: an isolated copy of recovery data (11.4), MFA on remote network access (6.4) and on administrative access (6.5), and dedicated admin accounts (5.4). If you only have time to verify a few items this quarter, start there.

The Controls that need testing: 7 and 18

Most Safeguards are verified by looking at a setting or a record. Two Controls are verified by probing your own environment the way an attacker would, and they are the ones where outside testers usually come in.

Control 7, Continuous Vulnerability Management. IG1 covers the process and the patching. IG2 adds the scanning:

Safeguard Requirement Group
7.5 Automated vulnerability scans of internal assets at least quarterly, both authenticated and unauthenticated IG2
7.6 Automated vulnerability scans of externally exposed assets at least monthly IG2
7.7 Remediate detected vulnerabilities at least monthly, following the remediation process IG2

Control 18, Penetration Testing. Nothing here is in IG1, which is deliberate: a test only pays off once the basics exist to fix what it finds.

Safeguard Requirement Group
18.1 A penetration testing program covering scope, frequency, limitations, contacts and how findings are remediated IG2
18.2 External penetration tests at least annually, including reconnaissance, by a qualified party IG2
18.3 Remediate findings according to your remediation policy IG2
18.4 Validate security measures after each test, and tune detection to the techniques used IG3
18.5 Internal penetration tests at least annually IG3

How this maps to our services: an external network penetration test from $4,200 answers 18.2, an internal network penetration test from $6,000 answers 18.5, the free retest included with both evidences 18.3, and the report’s attack narrative shows which techniques to tune detection for under 18.4. For Control 7, validated vulnerability scanning from $1,500 per scan covers the scans in 7.5 and 7.6, and a vulnerability management program runs them on the monthly and quarterly cadence the Safeguards set. For the monthly risk-based fixing that 7.2 asks for, see our guide to vulnerability remediation.

CIS Controls vs NIST CSF

“CIS vs NIST” is usually a comparison between the CIS Controls and the NIST Cybersecurity Framework (CSF). They are not competitors; they work at different altitudes.

CIS Controls v8.1 NIST CSF 2.0
What it is A prioritized list of specific actions A framework of outcomes, organized by function
Structure 18 Controls, 153 Safeguards, three Implementation Groups Six functions: Govern, Identify, Protect, Detect, Respond, Recover
How prescriptive Specific: “scan external assets at least monthly” Outcome-based: what should be achieved, not how
Where to start IG1 Profiles and tiers you define yourself
Penetration testing Named, with annual external and internal tests (Control 18) Not required by name; a test evidences outcomes such as identifying and validating vulnerabilities
Best for Deciding what to do next, and proving it was done Governing a program, reporting to leadership, mapping across frameworks

In practice many organizations use both: the CSF to structure and report the program, the CIS Controls to decide the concrete work underneath it. CIS publishes mappings from each Safeguard to CSF functions, and v8.1 realigned those mappings to CSF 2.0 (CIS Controls v8.1). For how NIST SP 800-53, CSF and SP 800-171 treat penetration testing next to Control 18, see our guide to NIST penetration testing requirements.

CIS Controls vs CIS Benchmarks

The names cause confusion. The CIS Controls say what to do: for example, Safeguard 4.1 asks for a secure configuration process. The CIS Benchmarks are separate, product-by-product configuration guides (for a Windows server, a firewall or a cloud account) that tell you how. Many teams use the Benchmarks as the baseline that satisfies Control 4.

Why the CIS Controls show up in laws and contracts

The CIS Controls are voluntary, but several authorities treat them as a measure of reasonable security:

  • California. The Attorney General’s 2016 Data Breach Report said the then-20 Controls “identify a minimum level of information security” for organizations holding personal information, and that failing to implement the applicable ones “constitutes a lack of reasonable security” (California Data Breach Report, February 2016).
  • Ohio. The state’s data protection law gives businesses an affirmative defense against certain breach claims when their written security program reasonably conforms to a recognized framework, and the CIS Controls are on the list alongside NIST and ISO 27000 (Ohio Revised Code 1354.03).
  • Cyber insurance and customers. Insurance applications and customer security questionnaires ask about the same Safeguards the Controls prioritize: MFA, backups, patching, endpoint protection and testing. Our guide to cyber insurance and penetration testing covers the testing questions.

If you are adopting the Controls because one of these points to them, keep evidence as you go: dated inventories, configuration exports, scan reports and test reports. Evidence is what turns “we follow CIS” into something a lawyer, auditor or underwriter can rely on.

How to implement the CIS Controls

  1. Pick your Implementation Group. Start with IG1 unless you already meet it. Decide honestly; IG2 on paper with IG1 gaps is worse than IG1 done well.
  2. Do Controls 1 and 2 first. Every other Control depends on knowing what assets and software you have.
  3. Measure each Safeguard. Done, partial or not started, with an owner, a date and the evidence that shows it.
  4. Close the IG1 gaps in risk order. Backups, MFA and admin separation before training refreshes.
  5. Add scanning and testing at IG2. Monthly external and quarterly internal scans (7.5, 7.6), then an annual external penetration test (18.2) to check whether the Safeguards hold under attack. Our guide to a network security assessment explains which kind of test answers which question.
  6. Re-measure every year and after major changes. New offices, acquisitions and cloud migrations reset parts of Controls 1, 4 and 12.

Frequently asked questions

What are the CIS top 20 controls? It is the old name. The Controls were known as the SANS Top 20 and then as the CIS Top 20 until Version 8 consolidated them into 18 in 2021. If a questionnaire asks about the “top 20”, answer against the current 18.

What are the IG1, IG2 and IG3 CIS Controls? They are the three Implementation Groups. IG1 is 56 Safeguards of essential cyber hygiene for every organization; IG2 adds 74 for organizations with dedicated IT staff and more sensitive data; IG3 adds the final 23 for organizations with security specialists and regulatory oversight.

Are the CIS Controls mandatory? Not on their own. They become a benchmark when a law, contract, insurer or regulator points to them, as Ohio’s safe-harbor statute and California’s 2016 breach report do.

Do the CIS Controls require penetration testing? Yes, from IG2. Control 18 calls for a penetration testing program, external tests at least annually and remediation of findings at IG2, plus internal tests at least annually and post-test validation at IG3.

What are the key differences between NIST and CIS Controls? NIST CSF describes outcomes and leaves the method to you; the CIS Controls prescribe specific actions in priority order. Many organizations use the CSF to structure the program and the CIS Controls to decide the work.

Which CIS Controls does a penetration test help with? Control 18 directly, since the test is the Safeguard. A good test also checks many others in passing, because it tries to defeat them: configuration (4), accounts and MFA (5 and 6), network architecture and segmentation (12 and 13), and whether your logging would have noticed (8).

Working toward IG2 and need the external and internal tests Control 18 asks for? Scope a test and we will match it to the Safeguards you are evidencing, at a fixed price with a free retest.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation