CIS Controls v8
What is CIS Controls v8?
Center for Internet Security Critical Security Controls - prioritized set of actions to protect organizations and data from known cyber attack vectors. It comprises 153 controls organised across 18 domains, published by CIS, and applies in International.
How CIS Controls v8 maps to other frameworks
All 153 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 18 domains CIS Controls v8 groups its controls into
Where CIS Controls v8 overlaps with the standards you already hold
Step-by-step implementation of CIS Controls v8
More CIS Controls v8 comparisons
Analysis of CIS Controls v8
What CIS Controls v8 means in your sector
What CIS Controls v8 means for your job
Questions people ask about CIS Controls v8
What is CIS Controls v8?
How many controls does CIS Controls v8 have?
Where does CIS Controls v8 apply?
What frameworks does CIS Controls v8 map to?
How do I get started with CIS Controls v8 compliance?
Query CIS Controls v8 programmatically
CIS Controls v8, its 153 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
CIS Controls v8 API reference and MCP config →What CIS Controls v8 requires, control by control
Each page carries the requirement text for one CIS Controls v8 control and what an assessor expects to see as evidence.
- CIS-1-1 Establish and Maintain Detailed Enterprise Asset Inventory
- CIS-1-2 Address Unauthorized Assets
- CIS-1-3 Utilize an Active Discovery Tool
- CIS-1-4 Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
- CIS-1-5 Use a Passive Asset Discovery Tool
- CIS-10-1 Deploy and Maintain Anti-Malware Software
- CIS-10-2 Configure Automatic Anti-Malware Signature Updates
- CIS-10-3 Disable Autorun and Autoplay for Removable Media
- CIS-10-4 Configure Automatic Anti-Malware Scanning of Removable Media
- CIS-10-5 Enable Anti-Exploitation Features
How much of another standard CIS Controls v8 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- ACSC Essential Eight to CIS Controls v8 crosswalk
- ANSSI Guide d'hygiene informatique (42 mesures, v2.0) to CIS Controls v8 crosswalk
- APRA CPS 234 to CIS Controls v8 crosswalk
- ASD Strategies to Mitigate Cyber Security Incidents to CIS Controls v8 crosswalk
- Australia Consumer Data Right - Banking (CDR) to CIS Controls v8 crosswalk
- Australia My Health Records Act 2012 to CIS Controls v8 crosswalk
- AWS Well-Architected Security Pillar to CIS Controls v8 crosswalk
- Azure Security Benchmark to CIS Controls v8 crosswalk
How ready are you for CIS Controls v8?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.