What are the CIS Critical Security Controls v8.1, and how are their 18 Controls and 153 Safeguards meant to be used?
answer
- prescriptive, prioritized, simplified
- Controls hold Safeguards
- inventory comes first
- a to-do order, not an audit
- v8.1 adds Governance
basics
~20 sThe CIS Controls v8.1 are a prescriptive, prioritized set of 18 security Controls broken into 153 Safeguards. They tell an organization what to do first, starting with asset and software inventory, rather than serving as a certification standard.
solid answer
~40 sThe **CIS Critical Security Controls** are, in CIS's words, a prescriptive, prioritized and simplified set of best practices. Version **8.1** has **18 Controls**, each broken into specific actions called **Safeguards** - **153** in total across v8 and v8.1. The list starts with **Control 1** (inventory of enterprise assets) and **Control 2** (inventory of software assets), because you cannot configure, patch or monitor what you do not know exists; **Control 4** covers secure configuration. The Safeguards are sorted into **Implementation Groups** so an organization knows which to do first. v8.1 revised asset classes and Safeguard descriptions, updated alignment to other frameworks, and added a **Governance** security function. The Controls are a prioritized action list, not a certification scheme.
go deeper
Recall that there are 18 Controls and 153 Safeguards, and that the first two Controls are asset and software inventory.
Explain why the Controls are prioritized, how Safeguards relate to Controls, and why they are guidance rather than a certification standard.
Show how you would turn the Safeguards into a tracked work plan with owners and status, and report progress in another framework's terms through a mapping.
Discuss when a prioritized action list like the CIS Controls is the right first investment compared with a certifiable management-system standard.
## What the CIS Controls are The **CIS Critical Security Controls** (CIS Controls) are published by the Center for Internet Security, an independent nonprofit. CIS describes them as a **prescriptive, prioritized and simplified** set of best practices for strengthening cybersecurity posture. Three words in that description carry the interview answer: - **Prescriptive** - each Safeguard names a concrete action (for example, maintaining an inventory or establishing a secure configuration process), not a vague outcome. - **Prioritized** - the order and the Implementation Groups tell a resource-constrained team where to begin. - **Simplified** - the set is deliberately smaller than a full control catalog, so a small team can act on it. The current version is **v8.1**. According to CIS it brought updated alignment to evolving industry standards and frameworks, revised asset classes and Safeguard descriptions, and the addition of a **Governance** security function. ## Structure: Controls and Safeguards There are **18 Controls**. Each Control is broken into **Safeguards** (previously called Sub-Controls); CIS counts **153 Safeguards** in v8 and v8.1. | # | Control | # | Control | |---|---|---|---| | 1 | Inventory and Control of Enterprise Assets | 10 | Malware Defenses | | 2 | Inventory and Control of Software Assets | 11 | Data Recovery | | 3 | Data Protection | 12 | Network Infrastructure Management | | 4 | Secure Configuration of Enterprise Assets and Software | 13 | Network Monitoring and Defense | | 5 | Account Management | 14 | Security Awareness and Skills Training | | 6 | Access Control Management | 15 | Service Provider Management | | 7 | Continuous Vulnerability Management | 16 | Application Software Security | | 8 | Audit Log Management | 17 | Incident Response Management | | 9 | Email and Web Browser Protections | 18 | Penetration Testing | ## Why the order matters The first Controls are foundations for the rest: 1. **Control 1** - actively manage all enterprise assets (end-user devices, network devices, IoT devices, servers, including cloud and remote), so that unauthorized and unmanaged assets can be found and removed or remediated. 2. **Control 2** - actively manage software so that only authorized software is installed and can execute. 3. **Control 4** - establish and maintain secure configurations for those assets and that software. 4. **Control 7** - continuously assess and track vulnerabilities on the assets you now know about. A team that jumps to penetration testing (Control 18) before it has an asset inventory will be testing an estate it cannot describe. The numbering is a reading order, and the Implementation Groups turn it into a work order. ## Prioritized, not audited A frequent weak answer treats the CIS Controls like ISO/IEC 27001 or SOC 2. They are different in kind: - They are **guidance for doing**, not a standard an organization is certified or attested against. The CIS Controls themselves define no certificate. - They are **mapped** to other frameworks, so progress on them can be reported in another framework's terms. - They sit **beneath** policy frameworks: a governance framework says what outcomes to achieve, and the CIS Safeguards say which concrete actions to take first. ## How a team uses them - Start with the Safeguards in **Implementation Group 1**, which CIS calls essential cyber hygiene. - Record each Safeguard as implemented, partially implemented or not implemented, with an owner. - Move to the next Implementation Group when the risk profile and resources justify it. - For **Control 4**, choose a configuration standard per platform; the **CIS Benchmarks** are CIS's own per-platform configuration guides that serve that Safeguard. ## What the Controls are not - Not a compliance regime: they are best-practice guidance, and there is no CIS Controls audit opinion. - Not a replacement for a risk assessment: the prioritization reflects common attacks, not one organization's specific threats. - Not a configuration guide: they say *establish secure configuration*; the Benchmarks say *which settings*. A strong answer states the counts (18 and 153), explains Safeguards and Implementation Groups, names inventory as the starting point, and places the Controls as a prioritized action list rather than an audit standard.
- Why do the CIS Controls begin with asset and software inventory?Every later Control acts on assets and software: you cannot configure, patch, monitor or recover what you have not inventoried. Controls 1 and 2 also surface unauthorized and unmanaged assets and software so they can be removed or remediated.
- How do the CIS Controls relate to the CIS Benchmarks?The Controls say what to do, including establishing and maintaining secure configuration in Control 4. The Benchmarks are CIS's per-platform configuration recommendations, which give the settings an organization can adopt to meet that Safeguard.
saying these in an interview costs you the question
- Says organizations get certified against the CIS Controls
- Treats the 18 Controls as unordered, to be done in any sequence
- Confuses Safeguards with the CIS Benchmark configuration settings
- Starts with penetration testing before any asset inventory
- Believes the CIS Controls replace a risk assessment