CIS Critical Security Controls
The CIS Critical Security Controls are a set of 18 prioritized, community-developed cybersecurity best practices that organizations can adopt to strengthen their defenses against common cyber attacks. They are voluntary recommendations rather than a law, focusing on specific security activities rather than on particular roles or types of devices. Organizations use them to help focus their security efforts on measures that offer the most value.
The CIS Critical Security Controls (formerly the Critical Security Controls, abbreviated CSC) are a framework of 18 prioritized safeguards developed and maintained by the Center for Internet Security (CIS) with input from a community of cybersecurity practitioners. They constitute a voluntary set of cyber defense best practices—not a binding regulation—and are not a certification scheme in themselves, though they may be referenced contractually or mapped to other frameworks. The Controls prioritize defensive activities over roles and device ownership, and are periodically revised (the current major revision is CIS Controls v8); practitioners should verify the specific control content and version against the current authoritative source at cisecurity.org. Application to a given organization's risk profile requires professional judgment and, where the Controls are invoked by law or agreement, review against those specific obligations.
Why it matters
Organizations face a broad and shifting landscape of cyber threats, and security teams often struggle to decide where to focus limited resources. The CIS Critical Security Controls address this by offering a prioritized set of 18 community-developed safeguards, drawing on the knowledge of cybersecurity practitioners to help organizations concentrate their efforts on the measures that offer the most value. Rather than presenting an undifferentiated checklist, the Controls emphasize prioritization, which can be particularly useful for organizations building or maturing a security program.
Because the CIS Controls are a voluntary best-practice framework rather than a binding regulation, adopting them does not by itself satisfy any legal obligation. Their value lies in improving an organization's overall security posture and in providing a structured, recognized reference point that can be mapped to other frameworks or invoked contractually. Where the Controls are referenced in an agreement or incorporated by another obligation, they may take on practical force through that instrument rather than as law in their own right.
The Controls are periodically revised—the current major revision is CIS Controls v8—so their specific content changes over time. Practitioners relying on them should confirm which version applies to their circumstances and verify the specific safeguards against the current authoritative source, since application to a given organization's risk profile requires professional judgment.
Who it's relevant to
Inside CIS Controls
Common questions
Answers to the questions practitioners most commonly ask about CIS Controls.
