Test Your Knowledge
Latest from the Blog
CIS Controls v8
The 18 CIS Critical Security Controls (formerly SANS Top 20) provide prioritized, actionable security guidance. Controls are organized into Implementation Groups (IG) based on organizational resources and risk profile.
Inventory and Control of Enterprise Assets IG1
Actively manage all enterprise assets connected to the network so only authorized devices are given access.
Inventory and Control of Software Assets IG1
Actively manage all software on the network so only authorized software is installed and executed.
Data Protection IG1
Develop processes to identify, classify, securely handle, retain, and dispose of data.
Secure Configuration of Enterprise Assets and Software IG1
Establish and maintain secure configurations for hardware and software on enterprise assets.
Account Management IG1
Use processes and tools to assign and manage authorization of user accounts.
Access Control Management IG1
Use processes and tools to create, assign, manage, and revoke access credentials and privileges.
Continuous Vulnerability Management IG1
Continuously acquire, assess, and remediate vulnerabilities to minimize the window of exploitation.
Audit Log Management IG2
Collect, alert, review, and retain audit logs to help detect, understand, and recover from attacks.
Email and Web Browser Protections IG1
Improve protections and detections of threats from email and web vectors.
Malware Defenses IG1
Prevent or control installation, spread, and execution of malicious applications and code.
Data Recovery IG1
Establish and maintain data recovery practices to restore in-scope enterprise assets.
Network Infrastructure Management IG2
Establish and maintain secure network device configurations to prevent attacks.
Network Monitoring and Defense IG2
Operate processes and tools to establish and maintain comprehensive network monitoring and defense.
Security Awareness and Skills Training IG1
Establish and maintain a security awareness program to influence behavior toward being security conscious.
Service Provider Management IG2
Develop processes to evaluate service providers who hold sensitive data or critical processes.
Application Software Security IG2
Manage the security lifecycle of in-house developed, hosted, or acquired software.
Incident Response Management IG1
Establish a program to prepare for, detect, and respond to incidents.
Penetration Testing IG3
Test the effectiveness of defenses through regular penetration testing.
IG1 Quick Start (Essential Cyber Hygiene)
Start here if you have limited resources. These 56 safeguards provide essential protection.
Priority Actions
- Create hardware and software inventories
- Establish secure configurations
- Maintain unique accounts for each user
- Implement MFA for remote access
- Regularly patch operating systems and applications
- Deploy anti-malware on all assets
- Establish weekly automated backups
- Conduct security awareness training annually
- Develop incident response procedures
Implementation Priority
| Priority | Controls | Focus Area |
|---|---|---|
| 1st | 1, 2, 4 | Know what you have and configure it securely |
| 2nd | 5, 6 | Control who has access |
| 3rd | 3, 7 | Protect data and fix vulnerabilities |
| 4th | 9, 10, 11 | Protect endpoints and ensure recovery |
| 5th | 14, 17 | Train users and prepare for incidents |
| 6th | 8, 12, 13 | Logging and network security |
| 7th | 15, 16, 18 | Third parties, app security, testing |
Need Detailed CIS Implementation Guides?
For comprehensive tutorials and control implementation guides:
Visit FixTheVuln.com →FixTheVuln Store
Studying for Security+ or GSEC?
Structured study planners covering security controls, hardening, and defense.
Related Resources
FixTheVuln Store
Studying for CompTIA CySA+? Get the Study Planner
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
CompTIA CySA+ Planner60+ certifications available — from $5.99