Skip to content

CIS Controls

What is CIS Controls?

A prioritized set of cybersecurity best practices developed by the Center for Internet Security to help organizations defend against common cyber threats.

Compliance and Regulatory

Each of these is named in at least one of the same controls as cis controls. The number is how many controls name both.

What the standards actually require on cis controls

Requirements naming cis controls across 6 standards, quoted from the control text.

MITRE ATT&CK2 controls

Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable o...

MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation · MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control

Protect is the second of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Access Control - identity and access management for IT + OT systems + role-based access + least privilege + privileged access management (PAM) for OT engineer...

IMO-MSC-FAL-Protect-AccessControl-NetworkSegmentation-MalwareDefence-Patch-Awareness-DataSecurity · IMO MSC-FAL Protect Function - Access Control + Network Segmentation + Malware Defence + Patch Management + Awareness Training + Data Security + Crew BYOD + Removable Media

Coordination positions IRS Pub 1075 within the broader US federal + state + and industry security landscape. (1) NIST Standards: NIST SP 800-53 Rev 5 (primary control set incorporated by reference Section 9.3) + NIST SP 800-53A (assessment methodology) + NIST...

IRSPub1075-CoordNIST80053-FedRAMP-FISMA-CJIS-SSACDS-StateRevAgencies-PrivacyAct-SOC2-Industry · IRS Pub 1075 Coordination - NIST SP 800-53 Rev 5 + FedRAMP + FISMA + 26 USC 6103 + FBI CJIS + SSA CDS + State Revenue Agencies + Privacy Act + SOC 2 + Industry Frameworks + Federal Sectoral
ISMAP (Japan)1 control

ISMAP Assessment positions ISMAP within the comprehensive Japanese and international cloud security regulatory landscape. (1) External Assessment by ISMAP-Approved Auditor: CSP must undergo annual third-party assessment by ISMAP-approved audit organisation inc...

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017 · ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 27017 + PIPA + Japan Digital Agency

Audit + Drills + Training operationalise the Directions through ongoing assurance + cyber preparedness. (1) CERT-In Cyber Security Audit: organisations should undergo periodic cyber security audit by CERT-In Empanelled Information Security Auditing Organisatio...

CERTIN-Audit-Drills-Training-AwarenessProgram-CERTInExercises-CISO · CERT-In Audit + Cyber Security Drills + Training + Awareness + CERT-In Cyber Exercises + CISO + Information Security Auditor Empanelment

Adopt a recognised cybersecurity framework per NGC Regulation 5.260 including NIST Cybersecurity Framework 2.0 + NIST SP 800-53 + ISO 27001/27002 + CIS Controls v8 + PCI DSS 4.0 + FedRAMP + AICPA SOC 2 Type II.

NGCB-2 · Cybersecurity Best Practices Framework Adoption

Questions people ask about cis controls

What is CIS Controls?
A prioritized set of cybersecurity best practices developed by the Center for Internet Security to help organizations defend against common cyber threats.
Why is CIS Controls important for compliance?
CIS Controls is a key concept in Compliance and Regulatory. Understanding cis controls helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address CIS Controls?
CIS Controls appears in the requirement text of MITRE ATT&CK, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), IRS Publication 1075, ISMAP (Japan), India CERT-In Cyber Security Directions 2022. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about CIS Controls?
Explore our compliance framework pages to see how cis controls applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how CIS Controls applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.