What are CIS Controls
Organizations throughout the globe are looking for ways to secure their networks from cyber-attacks. One of the ways that organizations accomplish this objective is by leveraging security controls. While many regulatory frameworks such as NIST, ISO 2700x, and HIPAA provide control objectives, they frequently need more details to implement those controls effectively. This is where the CIS Controls come into play. This article will give you an understanding of CIS Controls, their sub-components, how they are used, how they compare to other common frameworks such as NIST or HIPAA, and how they have evolved over time.
What are the CIS Security Controls?
The CIS Controls have a history of change. SANS cybersecurity training organization originally created what was known as the SANS Top 20 Critical Security Controls. Each year, they would update these controls and create posters to promote the controls; one of the Critical Security Controls Posters can still be found on the sans.org website. "Ownership of the controls was transferred to the Council on Cyber Security (CCS) in 2013, and then transferred to the Center for Internet Security (CIS) in 2015", according to a sparsely populated article on Wikipedia.
After SANS transferred ownership of the controls to the Center for Internet Security, they were named the CIS Critical Security Controls. When the CIS Controls v8 update was released in May of 2021, the controls were renamed again to the CIS Controls, shortening the name.
Per the Center for Internet Security:
"The CIS Controls (formerly known as Critical Security Controls) is a recommended set of prioritized cyber defense best practices. They provide specific and actionable ways to protect against today's most pervasive and dangerous attacks."
These "prioritized cyber defense best practices" that the CIS Controls cover is also aligned with the NIST-CSF. If you've worked in cybersecurity for some time, you may be familiar with the NIST Cybersecurity Framework (CSF). If you need to become more familiar with the NIST-CSF, version 2 was recently released and provides guidance from the National Institute of Standards and Technology (NIST) on implementing cybersecurity best practices. A deeper dive into NIST is beyond the scope of this article. Still, many organizations that do business in the United States leverage the NIST-CSF in some fashion for cybersecurity guidance.
What Problems do the CIS Controls Solve?
CIS Control intend to make the steps needed to help secure an organization accessible to understand and with clear implementation steps. If you're an existing security practitioner or what you will discover if you're new to the industry, most cybersecurity frameworks need to be more explicit in their implementation requirements. This clarity is one of the CIS Controls' greatest strengths. Lack of control clarity can lead to significant inefficiencies during regulatory audits or cybersecurity assessments.
ISO 27001:2022 Control A5.9, Inventory of information and other associated assets definition is:
"An inventory of information and other associated assets, including owners, should be developed and maintained."
You must pay for the ISO 27001 standard per the ANSI organization; if you want to acquire the document (though we do not recommend it), you can find the 27001 source material on the ANSI website. The control definition provided by the ANSI organization is vague and lacks clear implementation guidance. Let's compare this with the language used by the CIS Controls for a similar objective.
"Actively manage (inventory, track, and correct) all enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/Internet of Things (IoT) devices; and servers) connected to the infrastructure physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise. This will also support identifying unauthorized and unmanaged assets to remove or remediate."
The CIS Controls provide a more precise definition of the objective, how that objective can be achieved, and examples of where that control should be applied within an organization. This is helpful for organizations because while no business is forced to comply with the CIS Controls, some businesses must comply with other frameworks. For example, companies that process and manage healthcare data must comply with the U.S. Department of Health and Human Services HIPAA Security Rule. HIPAA stands for Health Insurance Portability and Accountability Act, and one of the primary components is Part 164 – Security and Privacy. If you were to read the law, the guidance for implementation is not clear, and organizations can struggle to understand what they are supposed to do to comply with the law. CIS Provides organizations with CIS Controls HIPAA mapping to help make implementing those requirements more straightforward. Suppose you're responsible for control objectives in your organization and are struggling to implement them. In that case, the CIS Controls may have a mapping to your framework.
Where can the CIS Controls be Downloaded?
If you're looking for CIS Controls v8, it can be downloaded from the Center for Internet Security website. You must submit your information to the organization, and they will email you a download link. When you receive your download link, you will see two documents presented if your native language is English: a PDF and an Excel document. We would recommend that you read the PDF document first; included in the PDF for each control is:
- An overview of the control
- The rationale on why the control is critical
- Procedures and tools related to the control
- Links to additional references, if available
- and safeguard details
This additional context not found in the Excel document will be helpful if you're new to the CIS Control framework.
How the CIS Controls are Structured
Controls and Safeguards
As you may imagine, the primary grouping of security controls is named… "Controls", shocker, we know. In CIS Controls v8, there are 18 controls; this is a change from all previous versions of the controls. In previous versions, there were 20 controls, thus why they were named the "SANS Top 20" or "CIS Top 20". For individuals who have been in the security industry for quite some time, you may hear them referring to the CIS Controls by those legacy names. The current list of CIS Controls is as follows:
- Inventory and Control of Enterprise Assets
- Inventory and Control of Software Assets
- Data Protection
- Secure Configuration of Enterprise Assets and Software
- Account Management
- Access Control Management
- Continuous Vulnerability Management
- Audit Log Management
- Email and Web Browser Protections
- Malware Defenses
- Data Recovery
- Network Infrastructure Management
- Network Monitoring and Defense
- Security Awareness and Skills Training
- Service Provider Management
- Application Software Security
- Incident Response Management
- Penetration Testing
These controls are broad topics that organizations can focus on to improve their security posture over time. However, there are sub-elements of these controls that provide additional detail. Each CIS Control has subsections named Safeguards. Each Control has five to fourteen "Safeguards" that add further detail and control objectives as organizations mature their security posture. As an organization grows and the data it manages becomes more sensitive, it should implement more controls to protect that data. This maturity is executed via Implementation Groups, which we will cover shortly.
The following is an example of how the Controls and Safeguards are matched. CIS Control number one is:
- Inventory and Control of Enterprise Assets
The "Safeguards" for CIS Control are as follows:
- Establish and Maintain Detailed Enterprise Asset Inventory
- Address Unauthorized Assets
- Utilize an Active Discovery Tool
- Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
- Use a Passive Asset Discovery Tool
As you can see, all the CIS Safeguards share the same theme of the primary control objective. This structure and detail provide rich guidance for organizations seeking to implement environmental controls and safeguards.
Implementation Groups
As you read through the included PDF, you will notice a concept termed "Implementation Groups." there are three Implementation Groups that correspond to various objectives within the CIS Controls. Implementation Groups 1 through 3 (IG1, IG2, IG3) represent a graduated scale of cybersecurity readiness and sophistication as outlined by the Center for Internet Security (CIS) Controls, tailored to different types of enterprises' varying capacities and risks.
Small to medium-sized businesses with limited cybersecurity resources and expertise are an appropriate target for Implementation Group One (IG1). They focus on maintaining operational continuity with a low tolerance for downtime, protecting primarily non-sensitive data. The safeguards for IG1 are easy to implement with minimal expertise. They are aimed at defending against common, non-targeted cyber threats.
Enterprises that would use Implementation Group Two (IG2) have dedicated personnel for managing IT infrastructure and face a greater complexity due to multiple departments with diverse risk profiles. These organizations handle sensitive data and can tolerate short-term service interruptions. They require more sophisticated security measures that include enterprise-grade technology and specialized knowledge to protect against potential breaches that could erode public confidence.
Enterprises with cybersecurity specialists with expertise in various domains to protect assets and data are recommended to implement the controls from Implementation Group Three. The security measures for IG3 are complex, focusing on thwarting sophisticated, targeted attacks and mitigating zero-day vulnerabilities, reflecting a high stake in maintaining public welfare.
As the complexity of the IT environment increases and the sensitivity of the data handled increases, the sophistication of the safeguards needed to protect the enterprise's assets also increases.
Lessons Learned
By the end of this article, we hope you will have an introductory understanding of CIS Controls and how they differ from and can enhance other cybersecurity frameworks. There will be a significant amount of process and technology required to properly implement the CIS Controls; that information is beyond the scope of this article. Another critical area to consider when implementing the CIS Controls is to validate the controls are implemented to mitigate cyber-attacks. One of the best ways to accomplish this is to test the implementation of your controls against the MITRE ATT&CK Framework. If you need to become more familiar with the MITRE ATT&CK Framework, take a moment to review our article on the topic: What is the MITRE ATT&CK Framework? To learn more about MITRE, check our article: Who is MITRE?
Call-to-Action
If you've found this content valuable and want to learn more about cybersecurity and how to begin or grow your career, join the agoge.io Discord and sign up for additional content…