International

CIS Controls v8

153 controls. 44 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

153 controls 44 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

CIS Controls v8 Evidence & Implementation Kit

153 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CIS-1.1Establish and Maintain Detailed Enterprise Asset Inventory32
CIS-1.2Address Unauthorized Assets23
CIS-1.3Utilize an Active Discovery Tool19
CIS-1.4Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory8
CIS-1.5Use a Passive Asset Discovery Tool13
CIS-10.1Deploy and Maintain Anti-Malware Software28
CIS-10.2Configure Automatic Anti-Malware Signature Updates23
CIS-10.3Disable Autorun and Autoplay for Removable Media18
CIS-10.4Configure Automatic Anti-Malware Scanning of Removable Media20
CIS-10.5Enable Anti-Exploitation Features16
CIS-10.6Centrally Manage Anti-Malware Software22
CIS-10.7Use Behavior-Based Anti-Malware Software22
CIS-11.1Establish and Maintain a Data Recovery Process30
CIS-11.2Perform Automated Backups26
CIS-11.3Protect Recovery Data27
CIS-11.4Establish and Maintain an Isolated Instance of Recovery Data25
CIS-11.5Test Data Recovery29
CIS-12.1Ensure Network Infrastructure is Up-to-Date25
CIS-12.2Establish and Maintain a Secure Network Architecture27
CIS-12.3Securely Manage Network Infrastructure19
CIS-12.4Establish and Maintain Architecture Diagram(s)22
CIS-12.5Centralize Network Authentication, Authorization, and Auditing (AAA)14
CIS-12.6Use of Secure Network Management and Communication Protocols25
CIS-12.7Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure24
CIS-12.8Establish and Maintain Dedicated Computing Resources for All Administrative Work26
CIS-13.1Centralize Security Event Alerting29
CIS-13.10Perform Application Layer Filtering19
CIS-13.11Tune Security Event Alerting Thresholds19
CIS-13.2Deploy a Host-Based Intrusion Detection Solution20
CIS-13.3Deploy a Network Intrusion Detection Solution24
CIS-13.4Perform Traffic Filtering Between Network Segments25
CIS-13.5Manage Access Control for Remote Assets24
CIS-13.6Collect Network Traffic Flow Logs22
CIS-13.7Deploy a Host-Based Intrusion Prevention Solution17
CIS-13.8Deploy a Network Intrusion Prevention Solution20
CIS-13.9Deploy Port-Level Access Control17
CIS-14.1Establish and Maintain a Security Awareness Program34
CIS-14.2Train Workforce Members to Recognize Social Engineering Attacks21
CIS-14.3Train Workforce Members on Authentication Best Practices20
CIS-14.4Train Workforce on Data Handling Best Practices24
CIS-14.5Train Workforce Members on Causes of Unintentional Data Exposure18
CIS-14.6Train Workforce Members on Recognizing and Reporting Security Incidents26
CIS-14.7Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates10
CIS-14.8Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks17
CIS-14.9Conduct Role-Specific Security Awareness and Skills Training34
CIS-15.1Establish and Maintain an Inventory of Service Providers28
CIS-15.2Establish and Maintain a Service Provider Management Policy30
CIS-15.3Classify Service Providers24
CIS-15.4Ensure Service Provider Contracts Include Security Requirements32
CIS-15.5Assess Service Providers32
CIS-15.6Monitor Service Providers28
CIS-15.7Securely Decommission Service Providers20
CIS-16.1Establish and Maintain a Secure Application Development Process29
CIS-16.10Apply Secure Design Principles in Application Architectures23
CIS-16.11Leverage Vetted Modules or Services for Application Security Components18
CIS-16.12Implement Code-Level Security Checks18
CIS-16.13Conduct Application Penetration Testing20
CIS-16.14Conduct Threat Modeling20
CIS-16.2Establish and Maintain a Process to Accept and Address Software Vulnerabilities23
CIS-16.3Perform Root Cause Analysis on Security Vulnerabilities21
CIS-16.4Establish and Manage an Inventory of Third-Party Software Components24
CIS-16.5Use Up-to-Date and Trusted Third-Party Software Components28
CIS-16.6Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities21
CIS-16.7Use Standard Hardening Configuration Templates for Application Infrastructure23
CIS-16.8Separate Production and Non-Production Systems25
CIS-16.9Train Developers in Application Security Concepts and Secure Coding24
CIS-17.1Designate Personnel to Manage Incident Handling32
CIS-17.2Establish and Maintain Contact Information for Reporting Security Incidents28
CIS-17.3Establish and Maintain an Enterprise Process for Reporting Incidents33
CIS-17.4Establish and Maintain an Incident Response Process36
CIS-17.5Assign Key Roles and Responsibilities32
CIS-17.6Define Mechanisms for Communicating During Incident Response30
CIS-17.7Conduct Routine Incident Response Exercises30
CIS-17.8Conduct Post-Incident Reviews29
CIS-17.9Establish and Maintain Security Incident Thresholds27
CIS-18.1Establish and Maintain a Penetration Testing Program31
CIS-18.2Perform Periodic External Penetration Tests28
CIS-18.3Remediate Penetration Test Findings30
CIS-18.4Validate Security Measures28
CIS-18.5Perform Periodic Internal Penetration Tests25
CIS-2.1Establish and Maintain a Software Inventory26
CIS-2.2Ensure Authorized Software is Currently Supported28
CIS-2.3Address Unauthorized Software27
CIS-2.4Utilize Automated Software Inventory Tools12
CIS-2.5Allowlist Authorized Software25
CIS-2.6Allowlist Authorized Libraries21
CIS-2.7Allowlist Authorized Scripts21
CIS-3.1Establish and Maintain a Data Management Process27
CIS-3.10Encrypt Sensitive Data in Transit27
CIS-3.11Encrypt Sensitive Data at Rest28
CIS-3.12Segment Data Processing and Storage Based on Sensitivity25
CIS-3.13Deploy a Data Loss Prevention Solution24
CIS-3.14Log Sensitive Data Access24
CIS-3.2Establish and Maintain a Data Inventory26
CIS-3.3Configure Data Access Control Lists26
CIS-3.4Enforce Data Retention26
CIS-3.5Securely Dispose of Data27
CIS-3.6Encrypt Data on End-User Devices19
CIS-3.7Establish and Maintain a Data Classification Scheme24
CIS-3.8Document Data Flows22
CIS-3.9Encrypt Data on Removable Media20
CIS-4.1Establish and Maintain a Secure Configuration Process33
CIS-4.10Enforce Automatic Device Lockout on Portable End-User Devices19
CIS-4.11Enforce Remote Wipe Capability on Portable End-User Devices18
CIS-4.12Separate Enterprise Workspaces on Mobile End-User Devices16
CIS-4.2Establish and Maintain a Secure Configuration Process for Network Infrastructure22
CIS-4.3Configure Automatic Session Locking on Enterprise Assets16
CIS-4.4Implement and Manage a Firewall on Servers24
CIS-4.5Implement and Manage a Firewall on End-User Devices19
CIS-4.6Securely Manage Enterprise Assets and Software22
CIS-4.7Manage Default Accounts on Enterprise Assets and Software23
CIS-4.8Uninstall or Disable Unnecessary Services on Enterprise Assets and Software25
CIS-4.9Configure Trusted DNS Servers on Enterprise Assets12
CIS-5.1Establish and Maintain an Inventory of Accounts26
CIS-5.2Use Unique Passwords26
CIS-5.3Disable Dormant Accounts24
CIS-5.4Restrict Administrator Privileges to Dedicated Administrator Accounts29
CIS-5.5Establish and Maintain an Inventory of Service Accounts20
CIS-5.6Centralize Account Management18
CIS-6.1Establish an Access Granting Process30
CIS-6.2Establish an Access Revoking Process28
CIS-6.3Require MFA for Externally-Exposed Applications28
CIS-6.4Require MFA for Remote Network Access26
CIS-6.5Require MFA for Administrative Access28
CIS-6.6Establish and Maintain an Inventory of Authentication and Authorization Systems18
CIS-6.7Centralize Access Control21
CIS-6.8Define and Maintain Role-Based Access Control32
CIS-7.1Establish and Maintain a Vulnerability Management Process32
CIS-7.2Establish and Maintain a Remediation Process31
CIS-7.3Perform Automated Operating System Patch Management26
CIS-7.4Perform Automated Application Patch Management27
CIS-7.5Perform Automated Vulnerability Scans of Internal Enterprise Assets27
CIS-7.6Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets26
CIS-7.7Remediate Detected Vulnerabilities31
CIS-8.1Establish and Maintain an Audit Log Management Process27
CIS-8.10Retain Audit Logs23
CIS-8.11Conduct Audit Log Reviews31
CIS-8.12Collect Service Provider Logs19
CIS-8.2Collect Audit Logs27
CIS-8.3Ensure Adequate Audit Log Storage17
CIS-8.4Standardize Time Synchronization16
CIS-8.5Collect Detailed Audit Logs26
CIS-8.6Collect DNS Query Audit Logs16
CIS-8.7Collect URL Request Audit Logs13
CIS-8.8Collect Command-Line Audit Logs16
CIS-8.9Centralize Audit Logs22
CIS-9.1Ensure Use of Only Fully Supported Browsers and Email Clients19
CIS-9.2Use DNS Filtering Services17
CIS-9.3Maintain and Enforce Network-Based URL Filters17
CIS-9.4Restrict Unnecessary or Unauthorized Browser and Email Client Extensions17
CIS-9.5Implement DMARC9
CIS-9.6Block Unnecessary File Types17
CIS-9.7Deploy and Maintain Email Server Anti-Malware Protections22

Tell me when CIS Controls v8 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for CIS Controls v8, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition