skip to content

What are the CIS Critical Security Controls v8.1, and how are their 18 Controls and 153 Safeguards meant to be used?

level: juniorimportance: must knowfreq 50%

answer

  1. prescriptive, prioritized, simplified
  2. Controls hold Safeguards
  3. inventory comes first
  4. a to-do order, not an audit
  5. v8.1 adds Governance

basics

~20 s

The CIS Controls v8.1 are a prescriptive, prioritized set of 18 security Controls broken into 153 Safeguards. They tell an organization what to do first, starting with asset and software inventory, rather than serving as a certification standard.

solid answer

~40 s

The **CIS Critical Security Controls** are, in CIS's words, a prescriptive, prioritized and simplified set of best practices. Version **8.1** has **18 Controls**, each broken into specific actions called **Safeguards** - **153** in total across v8 and v8.1. The list starts with **Control 1** (inventory of enterprise assets) and **Control 2** (inventory of software assets), because you cannot configure, patch or monitor what you do not know exists; **Control 4** covers secure configuration. The Safeguards are sorted into **Implementation Groups** so an organization knows which to do first. v8.1 revised asset classes and Safeguard descriptions, updated alignment to other frameworks, and added a **Governance** security function. The Controls are a prioritized action list, not a certification scheme.

go deeper

for a junior

Recall that there are 18 Controls and 153 Safeguards, and that the first two Controls are asset and software inventory.

for a middle

Explain why the Controls are prioritized, how Safeguards relate to Controls, and why they are guidance rather than a certification standard.

for a senior

Show how you would turn the Safeguards into a tracked work plan with owners and status, and report progress in another framework's terms through a mapping.

for a principal

Discuss when a prioritized action list like the CIS Controls is the right first investment compared with a certifiable management-system standard.

## What the CIS Controls are The **CIS Critical Security Controls** (CIS Controls) are published by the Center for Internet Security, an independent nonprofit. CIS describes them as a **prescriptive, prioritized and simplified** set of best practices for strengthening cybersecurity posture. Three words in that description carry the interview answer: - **Prescriptive** - each Safeguard names a concrete action (for example, maintaining an inventory or establishing a secure configuration process), not a vague outcome. - **Prioritized** - the order and the Implementation Groups tell a resource-constrained team where to begin. - **Simplified** - the set is deliberately smaller than a full control catalog, so a small team can act on it. The current version is **v8.1**. According to CIS it brought updated alignment to evolving industry standards and frameworks, revised asset classes and Safeguard descriptions, and the addition of a **Governance** security function. ## Structure: Controls and Safeguards There are **18 Controls**. Each Control is broken into **Safeguards** (previously called Sub-Controls); CIS counts **153 Safeguards** in v8 and v8.1. | # | Control | # | Control | |---|---|---|---| | 1 | Inventory and Control of Enterprise Assets | 10 | Malware Defenses | | 2 | Inventory and Control of Software Assets | 11 | Data Recovery | | 3 | Data Protection | 12 | Network Infrastructure Management | | 4 | Secure Configuration of Enterprise Assets and Software | 13 | Network Monitoring and Defense | | 5 | Account Management | 14 | Security Awareness and Skills Training | | 6 | Access Control Management | 15 | Service Provider Management | | 7 | Continuous Vulnerability Management | 16 | Application Software Security | | 8 | Audit Log Management | 17 | Incident Response Management | | 9 | Email and Web Browser Protections | 18 | Penetration Testing | ## Why the order matters The first Controls are foundations for the rest: 1. **Control 1** - actively manage all enterprise assets (end-user devices, network devices, IoT devices, servers, including cloud and remote), so that unauthorized and unmanaged assets can be found and removed or remediated. 2. **Control 2** - actively manage software so that only authorized software is installed and can execute. 3. **Control 4** - establish and maintain secure configurations for those assets and that software. 4. **Control 7** - continuously assess and track vulnerabilities on the assets you now know about. A team that jumps to penetration testing (Control 18) before it has an asset inventory will be testing an estate it cannot describe. The numbering is a reading order, and the Implementation Groups turn it into a work order. ## Prioritized, not audited A frequent weak answer treats the CIS Controls like ISO/IEC 27001 or SOC 2. They are different in kind: - They are **guidance for doing**, not a standard an organization is certified or attested against. The CIS Controls themselves define no certificate. - They are **mapped** to other frameworks, so progress on them can be reported in another framework's terms. - They sit **beneath** policy frameworks: a governance framework says what outcomes to achieve, and the CIS Safeguards say which concrete actions to take first. ## How a team uses them - Start with the Safeguards in **Implementation Group 1**, which CIS calls essential cyber hygiene. - Record each Safeguard as implemented, partially implemented or not implemented, with an owner. - Move to the next Implementation Group when the risk profile and resources justify it. - For **Control 4**, choose a configuration standard per platform; the **CIS Benchmarks** are CIS's own per-platform configuration guides that serve that Safeguard. ## What the Controls are not - Not a compliance regime: they are best-practice guidance, and there is no CIS Controls audit opinion. - Not a replacement for a risk assessment: the prioritization reflects common attacks, not one organization's specific threats. - Not a configuration guide: they say *establish secure configuration*; the Benchmarks say *which settings*. A strong answer states the counts (18 and 153), explains Safeguards and Implementation Groups, names inventory as the starting point, and places the Controls as a prioritized action list rather than an audit standard.

  • Why do the CIS Controls begin with asset and software inventory?
    Every later Control acts on assets and software: you cannot configure, patch, monitor or recover what you have not inventoried. Controls 1 and 2 also surface unauthorized and unmanaged assets and software so they can be removed or remediated.
  • How do the CIS Controls relate to the CIS Benchmarks?
    The Controls say what to do, including establishing and maintaining secure configuration in Control 4. The Benchmarks are CIS's per-platform configuration recommendations, which give the settings an organization can adopt to meet that Safeguard.

saying these in an interview costs you the question

  • Says organizations get certified against the CIS Controls
  • Treats the 18 Controls as unordered, to be done in any sequence
  • Confuses Safeguards with the CIS Benchmark configuration settings
  • Starts with penetration testing before any asset inventory
  • Believes the CIS Controls replace a risk assessment