Center For Internet Security Critical Security Controls 8.1 

With regard to Critical Security Controls, CSC “…failure to implement all of the controls that apply to an organization’s environment constitutes a lack of reasonable security.”  Kamala Harris, then-Attorney General, CA, Breach Report 2016


When it's been up to me, I make sure the Security Organization has a paid membership with CIS CSC. If I work for you, it will be in my first five suggestions. This article won't provide a means to skip your membership, but it may help you reinforce how you approach your management to say, "this is a critical budget item for me and my team." There are products that build the CIS membership into their product, so listen carefully for that. If your Cloud Security provider can demonstrate currency with all CIS benchmarks, consider that as worth at least the first 15K. Regardless, you need to know what's in CIS CSC 8.1 framework and you must understand how to leverage the CIS Benchmark and membership resources. Start by requesting and downloading CIS RAM | Download CIS RAM

FYI Changes in the CIS CSC from versions 6 to 7 and 7 to 8 involve substantial change. Mapping based on the number of controls will fail.

CIS Controls Version 8
Control 1: Inventory and Control of Enterprise Assets
Control 2: Inventory and Control of Software Assets
Control 3: Data Protection
Control 4: Secure Configuration of Enterprise Assets and Software
Control 5: Account Management
Control 6: Access Control Management
Control 7: Continuous Vulnerability Management
Control 8: Audit Log Management
Control 9: Email and Web Browser Protections
Control 10: Malware Defenses
Control 11: Data Recovery
Control 12: Network Infrastructure Management
Control 13: Network Monitoring and Defense
Control 14: Security Awareness and Skills Training
Control 15: Service Provider Management "New!"
Control 16: Application Software Security
Control 17: Incident Response Management
Control 18: Penetration Testing

Yes, we all have to know this. It's foundational.

Cybersecurity Challenge

Reputation is the new target for cyberattacks

  • Criminals value information – financial, health, critical infrastructure
  • When assessing and documenting Cyber risk it’s hard to know if we’ve got it right
  • The pace of technology increases unknown dependency on third parties
  • IT cannot trace or control our data – exfiltration occurs
  • The role of government and information custody is often misunderstood
  • External auditors share how well your systems, software, and procedures worked with actual data collected across a specified timeframe.
  • Findings in audit reports become barriers to business.
  • In today’s cloud economy, customer due diligence has gone from nice to have to mandate.

Learn about CIS Controls v8Tools and Resources | Companion Guides for CIS Controls v8 | CIS Controls v8 Mappings

Follow the CIS YouTube Channel CIS - YouTube

Main Menu