CIS Controls
The CIS Controls are a set of control points with associated safeguards that guide organisations in addressing their IT security. The methodology can be a good complement to, and enabler for, ISO certification and compliance with frameworks such as the NIST Cybersecurity Framework. Here we explain more about what this involves.
In the early 2010s, a grassroots effort began to identify the most common cyberattacks affecting small and large organisations in their day-to-day operations. The work continued by gathering and sharing knowledge about practical measures to defend against cyberattacks. The results were described as control points, the Critical Security Controls.
The Center for Internet Security (CIS) is a non-profit organisation established in 2000 and funded by U.S. government agencies as well as a number of companies across industries in the private and public sectors.
Today, CIS leads the work on the Critical Security Controls (CIS Controls).
- Shares experience of cyberattacks, identifying their causes and what is needed to stop them.
- Develops and shares tools, working methods, and problem-solving approaches.
- Maps the CIS Controls to legislation and frameworks so that the CIS Controls stay aligned with applicable legislation and established frameworks such as ISO 27001/27002 and NIST CSF.
- Identifies common problems and obstacles and works to solve them collectively.
There are 18 CIS Controls and 153 associated safeguards. Step by step, the organisation is reviewed in order to identify vulnerabilities, assess risk, and address it. The organisations in the CIS network regularly update and prioritise the CIS Controls and safeguards based on the real-world threat landscape and their collective expertise.
Implementation in three groups
The methodology consists of three Implementation Groups, IG1, IG2 and IG3, each of which contains recommended CIS Controls and safeguards. IG1 is the baseline level, described as essential cyber hygiene, and includes a smaller number of safeguards. IG2 includes all the safeguards in IG1, supplemented with further safeguards for a higher level of security. IG3 is the highest level and means that all safeguards are implemented.
IG1 — The controls in IG1 mean that the organisation inventories hardware, software and applications and introduces routines for keeping the documentation up to date, establishes processes for managing access rights and data protection, and trains employees in security.
IG2 — In addition to the controls in IG1, IG2 means that the organisation, for example, uses tools to detect new hardware and software on the network, classifies and encrypts data, centralises the management of access rights, establishes processes for log management, expands network security and monitoring, establishes processes for secure application development and software vulnerability management, expands its handling of security incidents, and carries out external penetration testing.
IG3 — IG3 means that all 153 safeguards across the 18 CIS Controls are to be implemented. In addition to IG1 and IG2, IG3 means that the organisation, for example, expands network security further, performs application-level penetration testing, performs internal penetration testing, and carries out threat modeling.
The first step is to identify which Implementation Group suits the organisation. The choice should be based on a risk and impact analysis, as well as the resources available for security work.
The 18 CIS Controls
Control 1 Inventory and Control of Enterprise Assets
Inventory all devices in the organisation's infrastructure (physical, virtual, remote, or in cloud environments), establish an inventory system for the organisation's devices, and keep the inventory system up to date.
Once assets are identified, they can be protected and monitored. Any unauthorised or unused devices can be dealt with.
Control 2 Inventory and Control of Software Assets
Inventory all software connected to the organisation's network, establish an inventory system for the organisation's software, and keep the inventory system up to date. Once all software has been identified, it can be protected and monitored, and the organisation can ensure that only authorised software is installed and run.
Control 3 Data Protection
Develop processes and technical systems to identify, classify, manage, store and delete information. Introduce safeguards to protect the organisation's information in line with the adopted classification model, across all applications and all of the organisation's devices.
Control 4 Secure Configuration
Establish secure configurations for the organisation's devices (desktop and laptop computers, tablets, phones, network equipment, IoT equipment, servers, and so on) and software, tailored to the organisation's security requirements. Develop a process for maintaining and updating secure configurations over time.
Control 5 Account Management
Develop processes for establishing user accounts, administrator accounts and other account types, and use tools to manage accounts over time.
Control 6 Access Control Management
Develop processes for assigning access rights for user accounts, administrator accounts and other account types, and use tools to manage access rights over time.
Control 7 Continuous Vulnerability Management
Develop processes for regular vulnerability scanning and patching of all the organisation's hardware and software assets to minimise attackers' opportunities to exploit vulnerabilities. Monitor public and private sources for new threat and vulnerability information.
Control 8 Audit Log Management
Develop processes for logging system events (such as the start/stop of system processes and system crashes) and user activity (such as login events and file access), and ensure that logs are monitored, reviewed and retained. Following an attack, logs are an important basis for investigating the scope of the incident.
Control 9 Email and Web Browser Protections
Ensure protection for email and web browsers. Attackers use email and the web to manipulate users into taking actions that help the attacker, for example, obtain information or lock systems for extortion purposes. Regularly update email systems and web browsers, limit users' ability to install browser extensions, and train users in information security (for example, on phishing techniques, password management, and web security).
Control 10 Malware Defenses
Ensure that malware protection is installed on all devices and is kept up to date with the latest updates.
Control 11 Data Recovery
Establish and maintain routines for recovering the organisation's data and infrastructure (hardware and software). Regularly test the routines to ensure that restoring to a safe state prior to an attack actually works.
Control 12 Network Infrastructure Management
Establish documentation of the organisation's network infrastructure and keep the documentation updated over time. Keep the network infrastructure updated with the latest software updates. Monitor and log all administrator activity.
Control 13 Network Monitoring and Defense
Monitor the network infrastructure and establish routines for handling incidents in the network infrastructure. Regularly review monitoring thresholds and manually analyze logs to look for abnormal events. Human expertise and intuition can never be fully replaced by automated log analysis tools.
Control 14 Security Awareness and Skills Training
Regularly train all employees in information security and risk assessment. Employees' security awareness and competence are important for protecting the organisation from threats.
Control 15 Service Provider Management
Evaluate new service providers that are given access to the organisation's information and IT environments to ensure that data and IT systems are protected in accordance with the requirements set. Regularly check that the agreed level of protection is being maintained. It is also important to have a routine for offboarding service providers when a contract ends.
Control 16 Application Software Security
Ensure the security of software that is developed or used within the organisation throughout the software's entire lifecycle. Create routines to prevent, detect and remediate vulnerabilities before they can negatively affect the organisation.
Control 17 Incident Response Management
Develop and maintain an incident response process with the ability and capacity to act on attacks and security incidents (for example, policies, plans, routines, defined roles, training and communication). Ensure that incident response works through exercises in which the organisation is subjected to simulated attacks.
Control 18 Penetration Testing
Test the organisation's ability to defend itself against attacks by simulating an attacker's methods for exploiting vulnerabilities in, for example, technical infrastructure, routines and processes, as well as the manipulation of employees through, for example, phishing, social media and other forms of influence.