CIS Controls

The CIS Controls are a prioritized set of cybersecurity actions maintained by the Center for Internet Security, designed as an implementation-focused baseline for organizations building or benchmarking a cyber program.

What the CIS Controls Cover

The current version organizes the controls into 18 top-level categories, from inventory and control of enterprise assets through application software security and incident response management. Each top-level control contains specific safeguards, mapped to implementation groups based on organizational size and risk profile.

The implementation groups matter. IG1 covers essential cyber hygiene for smaller organizations. IG2 and IG3 add depth for larger or higher-risk environments. Organizations use the groups to right-size adoption rather than trying to implement every safeguard at once.

CIS Controls vs. NIST CSF

The CIS Controls are more prescriptive than NIST CSF 2.0. Where CSF describes outcomes (identify, protect, detect, respond, recover, govern), CIS specifies concrete actions to achieve those outcomes. Many organizations use CSF as the outcome-level framework and CIS as the implementation-level guide.

CIS in Quantified Programs

CIS-aligned control posture feeds directly into cyber risk quantification. Modeled scenarios respond to the specific safeguards an organization has implemented, so CIS control coverage shows up in the loss distribution and in the response to hypothetical control investments.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.