Controls 1–2 · Know your estate
Inventory and control of enterprise assets and of software. You cannot defend what you do not know you have.
Frameworks · Foundational
The specific, prioritized things to actually do, in the order that buys you the most protection first.
The CIS Critical Security Controls are a prioritized, prescriptive set of defensive actions, ordered so that the things that stop the most common attacks come first. Where NIST tells you what outcomes to aim for, CIS tells you specifically what to do, which makes it the most actionable place for a small or mid-sized team to start.
They are maintained by the Center for Internet Security, a non-profit, and built from real-world attack and breach data rather than theory. Version 8 reorganized the controls around how work actually happens today (cloud, mobile, and remote), and the 2024 v8.1 refresh aligned them more tightly with NIST CSF 2.0.
Their defining feature is prioritization. Instead of treating every control as equally urgent, CIS sorts them into Implementation Groups so a lean organization can do the high-impact basics well before reaching for advanced measures.
There are 18 Controls, each broken into specific Safeguards (a bit over 150 in total). Every Safeguard is assigned to one of three Implementation Groups (IG1, IG2, IG3) that act as a maturity ladder. IG1 is the foundational set CIS calls "essential cyber hygiene," the minimum every organization should reach. IG2 adds controls for organizations managing more sensitive data and more complex IT. IG3 targets those facing sophisticated, targeted attacks.
The practical takeaway: you do not adopt all 18 controls at full depth at once. You secure IG1 across every control first, then deepen toward IG2 and IG3 as your risk and resources grow. The controls below are the 18 themes you work through.
Inventory and control of enterprise assets and of software. You cannot defend what you do not know you have.
Data protection and secure configuration of hardware and software, replacing risky defaults.
Account management and access control management, including MFA and least privilege.
Continuous vulnerability management and audit log management, so issues and activity are visible.
Email and browser protections, malware defences, data recovery, network infrastructure, and network monitoring and defence.
Security awareness training, service-provider management, application security, incident response, and penetration testing.
CIS Controls are the most natural fit for organizations that want a concrete to-do list rather than a governance framework: IT leaders and managed-service teams who need to know exactly what to configure, and in what order.
They are especially valuable for small and mid-sized organizations, where IG1’s "essential cyber hygiene" is a realistic, fundable target that demonstrably reduces risk. Larger organizations use the full IG2 and IG3 depth and the CIS Benchmarks (hardening guides for specific products) alongside them.
They are less suited to being your sole answer when a customer or regulator specifically demands a certifiable management system. In that case CIS is the implementation detail underneath ISO 27001 or a NIST-based program, not a replacement for it.
CIS and NIST are complementary, not competing. NIST CSF gives you the program structure and governance, and CIS gives you the specific safeguards that satisfy it. CIS publishes official mappings from its controls to NIST CSF and other frameworks for exactly this reason.
Compared with ISO 27001, CIS is lighter and more technical, and it does not require a formal management system, audits, or certification. Many organizations begin with CIS IG1 to get protected quickly, then formalize under NIST or ISO when the business case (insurance, contracts, certification) appears.
CIS Controls v8 is technology-neutral; FioSec's seven layers are where its outcomes become real controls. Here is roughly where each one lands.
Free readiness checklist
Answer honestly across the 6 areas below for an instant read on where you stand. "Not sure" is a valid answer. Nothing is sent anywhere; your answers are scored right here in your browser.
Your result
Know your estate (Controls 1–2)
—Accounts & access (Controls 5–6)
—Configuration & vulnerabilities (Controls 4, 7)
—Active defences (Controls 9–13)
—Recovery (Control 11)
—People & response (Controls 14, 17)
—This is a self-assessment, not a formal audit or a guarantee of compliance. Talk to our team for a detailed gap review.
Authoritative source: CIS Critical Security Controls (cisecurity.org)
FioSec helps Ontario organizations turn frameworks into working controls, vendor-agnostic, from assessment and design through implementation and ongoing support.