Most breaches don't come from exotic zero-days. They come from an unpatched server, a reused password, an admin account with no MFA, or a laptop nobody knew was on the network. The CIS Critical Security Controls exist because someone finally sat down, looked at how organizations actually get compromised, and wrote a prioritized list of the defenses that stop it.

Version 8.1 organizes that list into 18 Controls broken down into 153 Safeguards: concrete, checkable actions. If SOC 2 and ISO 27001 tell you what outcomes to achieve, CIS tells you exactly what to do, in rough priority order. That makes it one of the best starting points for a growing team that wants to be genuinely more secure, not just audit-ready.

What the 18 Controls cover

The Controls move roughly from "know what you have" to "be ready when something goes wrong":

  1. Inventory and Control of Enterprise Assets: you can't protect what you don't know exists.
  2. Inventory and Control of Software Assets: the same, for software.
  3. Data Protection: classify, handle, retain, and dispose of data safely.
  4. Secure Configuration of Assets and Software: no default passwords, hardened baselines.
  5. Account Management: know every account and who owns it.
  6. Access Control Management: grant, verify, and revoke access based on need. (This is where MFA lives.)
  7. Continuous Vulnerability Management: find and fix weaknesses on a cadence.
  8. Audit Log Management: collect the logs you'll need when something happens.
  9. Email and Web Browser Protections: the two biggest doors attackers knock on.
  10. Malware Defenses: modern endpoint protection, everywhere.
  11. Data Recovery: tested, restorable backups.
  12. Network Infrastructure Management: secure the routers, switches, and firewalls.
  13. Network Monitoring and Defense: watch traffic for the things that get past you.
  14. Security Awareness and Skills Training: your people are a control too.
  15. Service Provider Management: your vendors' security is your security.
  16. Application Software Security: build and buy software that isn't full of holes.
  17. Incident Response Management: a plan you've actually rehearsed.
  18. Penetration Testing: prove the whole thing works.

Implementation Groups: start where you are

CIS's best idea is that you don't do all 153 Safeguards at once. It sorts them into three Implementation Groups (IGs):

  • IG1: essential cyber hygiene. The ~56 safeguards every organization should do, achievable with off-the-shelf tools and no dedicated security staff. This is the floor.
  • IG2 adds safeguards for organizations managing more sensitive data or more complex IT.
  • IG3 is for organizations facing sophisticated, targeted attackers.

For most SMBs, IG1 is the goal for year one. It's a genuinely defensible security posture, and it maps cleanly onto the evidence auditors want for SOC 2 and ISO 27001.

Why CIS pairs so well with an audit

Here's the part teams miss: the CIS Safeguards overlap heavily with what SOC 2, ISO 27001, PCI DSS, and HIPAA already ask for. MFA, asset inventory, vulnerability management, access reviews, incident response. They all show up in every framework. Do the CIS work once and you've done most of the evidence-gathering for the audit you're actually chasing.

That's the whole idea behind a crosswalked control library: one implementation, mapped to every framework it satisfies. Instead of running "a CIS project" and "a SOC 2 project" side by side, you build the control once and watch your readiness rise across all of them at the same time.

Getting started without a security team

  1. Inventory first (Controls 1–2). Even a spreadsheet of every device and SaaS app beats nothing. Most of the later controls depend on this.
  2. Turn on MFA everywhere (Control 6). Fastest risk reduction per hour of work you'll ever get.
  3. Fix the configuration basics (Control 4). Kill default credentials, close unused ports, enable disk encryption.
  4. Get patching on a cadence (Control 7). Automated where possible.
  5. Write down the plans (Controls 11, 17). Backups you've tested, and an incident response runbook you've actually read.

Work IG1 top to bottom and you'll close the gaps that account for the overwhelming majority of real-world compromises.


Keel now ships all 18 CIS Controls and 153 Safeguards as a crosswalked framework, so you can track your CIS coverage and have it count toward SOC 2, ISO 27001, PCI, and HIPAA at the same time. Start free at keelgrc.com. No credit card, no sales call.