CIS Critical Security Controls v8.1
The CIS Critical Security Controls v8.1, released June 2024, are a prioritised set of 18 controls and 153 safeguards for defending against the most common cyber attacks. Organised into three Implementation Groups (IG1-IG3), they provide a scalable approach from basic cyber hygiene to advanced security operations applicable to organisations of all sizes.
18
Controls
153
Safeguards
3
Implementation Groups
v8.1
Current (June 2024)
Inventory of enterprise and software assets, data protection, secure configuration of enterprise assets and software, account management, and access control management.
Continuous vulnerability management, audit log management, email and web browser protections, malware defences, data recovery, and network infrastructure management.
Network monitoring and defence, security awareness and skills training, service provider management, and application software security.
Incident response management and penetration testing for validating security programme effectiveness.
IG1: 56 safeguards for basic hygiene (all orgs). IG2: 130 total for orgs with IT staff. IG3: all 153 safeguards for mature security programmes.
Determine IG1, IG2, or IG3 based on organisational risk profile, resources, and cybersecurity maturity.
Implement Controls 1-2 to establish comprehensive enterprise and software asset inventories.
Implement all 56 IG1 safeguards to establish essential cyber hygiene across the organisation.
Add 74 additional safeguards for organisations with dedicated IT security staff and resources.
Implement remaining 23 safeguards for mature security operations with advanced capabilities.
Use the CIS Controls Self Assessment Tool (CIS-CSAT) for ongoing benchmarking and progress tracking.