← ALL FRAMEWORKS

CIS Controls

Information Security

Issued by Center for Internet Security

The CIS Critical Security Controls are a prioritized set of safeguards published by the Center for Internet Security, organized into 18 controls mapped to three Implementation Groups (IG1–IG3) so adoption can scale to an organization's size and risk profile. The current version is v8.1 (June 2024), an iterative update to v8 that realigned mappings to NIST CSF 2.0. They aren't a regulatory mandate or certifiable standard — they're a voluntary, practical baseline, commonly adopted by smaller organizations without dedicated security staff, or used as a stepping stone toward frameworks like ISO 27001.

Get notified the moment CIS Controls actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.