FixTheVuln

CIS Critical Security Controls

By FixTheVuln Team Peer-reviewed security content Sources: CISA, NVD, OWASP

Test Your Knowledge

CISSP Practice Quiz Security+ Practice Quiz

Latest from the Blog

Cisco CCNA Study Guide: Everything You Need to Pass the 200-301 Exam Cisco CCNP ENCOR Study Guide: How to Pass the 350-401 Exam Cisco CCNP Security SCOR Study Guide: Everything You Need to Pass t...
← Back to Home

CIS Controls v8

The 18 CIS Critical Security Controls (formerly SANS Top 20) provide prioritized, actionable security guidance. Controls are organized into Implementation Groups (IG) based on organizational resources and risk profile.

IG1 (Essential) - Basic cyber hygiene for all organizations
IG2 (Foundational) - More resources, greater risk exposure
IG3 (Organizational) - Sophisticated attacks, significant resources
1

Inventory and Control of Enterprise Assets IG1

Actively manage all enterprise assets connected to the network so only authorized devices are given access.

2

Inventory and Control of Software Assets IG1

Actively manage all software on the network so only authorized software is installed and executed.

3

Data Protection IG1

Develop processes to identify, classify, securely handle, retain, and dispose of data.

4

Secure Configuration of Enterprise Assets and Software IG1

Establish and maintain secure configurations for hardware and software on enterprise assets.

5

Account Management IG1

Use processes and tools to assign and manage authorization of user accounts.

6

Access Control Management IG1

Use processes and tools to create, assign, manage, and revoke access credentials and privileges.

7

Continuous Vulnerability Management IG1

Continuously acquire, assess, and remediate vulnerabilities to minimize the window of exploitation.

8

Audit Log Management IG2

Collect, alert, review, and retain audit logs to help detect, understand, and recover from attacks.

9

Email and Web Browser Protections IG1

Improve protections and detections of threats from email and web vectors.

10

Malware Defenses IG1

Prevent or control installation, spread, and execution of malicious applications and code.

11

Data Recovery IG1

Establish and maintain data recovery practices to restore in-scope enterprise assets.

12

Network Infrastructure Management IG2

Establish and maintain secure network device configurations to prevent attacks.

13

Network Monitoring and Defense IG2

Operate processes and tools to establish and maintain comprehensive network monitoring and defense.

14

Security Awareness and Skills Training IG1

Establish and maintain a security awareness program to influence behavior toward being security conscious.

15

Service Provider Management IG2

Develop processes to evaluate service providers who hold sensitive data or critical processes.

16

Application Software Security IG2

Manage the security lifecycle of in-house developed, hosted, or acquired software.

17

Incident Response Management IG1

Establish a program to prepare for, detect, and respond to incidents.

18

Penetration Testing IG3

Test the effectiveness of defenses through regular penetration testing.

IG1 Quick Start (Essential Cyber Hygiene)

Start here if you have limited resources. These 56 safeguards provide essential protection.

Priority Actions

  • Create hardware and software inventories
  • Establish secure configurations
  • Maintain unique accounts for each user
  • Implement MFA for remote access
  • Regularly patch operating systems and applications
  • Deploy anti-malware on all assets
  • Establish weekly automated backups
  • Conduct security awareness training annually
  • Develop incident response procedures

Implementation Priority

Priority Controls Focus Area
1st 1, 2, 4 Know what you have and configure it securely
2nd 5, 6 Control who has access
3rd 3, 7 Protect data and fix vulnerabilities
4th 9, 10, 11 Protect endpoints and ensure recovery
5th 14, 17 Train users and prepare for incidents
6th 8, 12, 13 Logging and network security
7th 15, 16, 18 Third parties, app security, testing

Need Detailed CIS Implementation Guides?

For comprehensive tutorials and control implementation guides:

Visit FixTheVuln.com →

FixTheVuln Store

Studying for Security+ or GSEC?

Structured study planners covering security controls, hardening, and defense.

Security+ (701) GSEC CISSP 2026
CompTIA (ISC)2 AWS Cisco All โ†’

Related Resources

๐Ÿ›๏ธ NIST Framework Cybersecurity risk management ๐Ÿง Linux Hardening Secure your Linux systems โ˜๏ธ Cloud Security AWS, Azure & GCP security

FixTheVuln Store

Studying for CompTIA CySA+? Get the Study Planner

Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

CompTIA CySA+ Planner

60+ certifications available — from $5.99