Back to Frameworks
Security

CIS Controls

The CIS Controls (version 8) are a prioritized set of 18 safeguards designed to be one of the most practical starting points for an organization with limited security resources.

Controls are grouped into three Implementation Groups (IG1, IG2, IG3), scaled to organization size and risk — IG1 covers essential cyber hygiene that almost any organization should have, while IG3 adds the depth larger or higher-risk organizations need. The list is deliberately concrete (e.g., "Inventory and Control of Enterprise Assets") rather than abstract, which makes it a popular baseline before tackling a heavier framework like ISO 27001.

See how LumiGRC handles CIS Controls

Get a Demo
18

Prioritized controls

0%
Typical certification profile
Audit Rigor61%
Time to Certify64%
Surveillance Burden57%
Issued & Enforced By

Center for Internet Security

CIS Controls v8

Key Points

  • 18 prioritized controls, version 8
  • Three Implementation Groups scaled to organization size
  • Concrete and action-oriented rather than abstract
  • A common starting baseline before a full certification effort