Overview
The CIS Critical Security Controls are a prioritized set of cyber defence practices published by the Center for Internet Security, a US non-profit. Version 8.1 is current. It has 18 controls broken into 153 safeguards, and each safeguard asks for one specific action, such as keeping an inventory of enterprise assets or requiring multi-factor authentication for remote access. Version 8.1 realigned the framework's security function mappings with NIST CSF 2.0, added the Govern function, revised asset classes, and expanded the glossary.
Safeguards are sorted into 3 implementation groups. IG1, with 56 safeguards, is what CIS calls essential cyber hygiene, the starting point for every enterprise. IG2 adds 74 safeguards for organizations with more resources and risk to manage, for a total of 130, and IG3 covers all 153. CIS also publishes the CIS Benchmarks, consensus-built secure configuration recommendations for more than 25 vendor product families, available as free PDFs, along with hardened images and the CIS-CAT assessment tool.
No certification exists for the CIS Controls, and no Canadian regulator enforces them. They work as a next step. The Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations name the CIS Controls and CIS Benchmarks as resources for organizations that want to go beyond the baseline. Many teams use IG1 as a starting checklist and the Benchmarks as the source for the configuration standards that other frameworks, such as PCI DSS Requirement 2, ask for.
Who it applies to in Canada
Any organization of any size that wants a prioritized list of security safeguards, from small businesses starting with basic hygiene to large enterprises facing skilled attackers.
The Canadian Centre for Cyber Security's baseline controls for small and medium organizations point those that want to go further toward the CIS Controls. Canadian IT teams also use the free CIS Benchmarks to build secure configuration standards.
Controls at a glance
CIS Controls v8.1 has 18 controls, listed here in order in groups of 3, with 153 safeguards across them.
Controls 1 to 3: assets and data
- Control 1: inventory and control of enterprise assets
- Control 2: inventory and control of software assets
- Control 3: data protection
Controls 4 to 6: configuration and access
- Control 4: secure configuration of enterprise assets and software
- Control 5: account management
- Control 6: access control management
Controls 7 to 9: vulnerabilities, logs, and user-facing threats
- Control 7: continuous vulnerability management
- Control 8: audit log management
- Control 9: email and web browser protections
Controls 10 to 12: malware, recovery, and networks
- Control 10: malware defences
- Control 11: data recovery
- Control 12: network infrastructure management
Controls 13 to 15: monitoring, people, and providers
- Control 13: network monitoring and defence
- Control 14: security awareness and skills training
- Control 15: service provider management
Controls 16 to 18: software, incidents, and testing
- Control 16: application software security
- Control 17: incident response management
- Control 18: penetration testing
Certification and assessment
Organizations measure themselves against the safeguards in their chosen implementation group and track progress over time. CIS-CAT Pro can check system settings against the CIS Benchmarks.
Dates to know
- 2020-02-18
- Canadian Centre for Cyber Security baseline controls (v1.2) updated, pointing organizations beyond the baseline to the CIS Controls
Resources
Official texts and free tools for CIS Controls. Links open the publisher’s site.
- CIS Critical Security Controls, Center for Internet Security
- CIS Critical Security Controls v8.1, Center for Internet Security
- CIS Controls implementation groups, Center for Internet Securityguidance
- CIS Benchmarks, Center for Internet Securitytool
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Securityguidance
Need help? Browse the directory or read the guides.
References
- CIS Critical Security Controls v8.1, Center for Internet Security
- The 18 CIS Critical Security Controls, Center for Internet Security
- CIS Controls implementation group 1, Center for Internet Security
- CIS Controls implementation group 2, Center for Internet Security
- Baseline cyber security controls for small and medium organizations, Canadian Centre for Cyber Security
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.