
CIS Controls
CIS Critical Security Controls
Start with IG1. That is cyber hygiene, not a personality.
A prioritized punch list of defenses that actually show up in breaches.
Who it's for. Security teams that need sequence, not another 800-page catalog. Maps cleanly to CSF and ISO language.
01
IG1 — essential hygiene
Official-ish
Implementation Group 1: foundational controls for organizations with limited resources.
Monday version
Know devices and software, protect accounts, patch, recover. If IG1 is fiction, fancy detections will not save you.
Do this
- Inventory enterprise assets and software — including the shadow SaaS.
- MFA, unique passwords, and no shared admin mystery accounts.
- Automated backups you have restored this quarter.
02
IG2 — the security team exists
Official-ish
Implementation Group 2: additional controls when you have dedicated security staff.
Monday version
This is where vulnerability management, email/browser hardening, and a real audit trail stop being optional.
Do this
- Scan, ticket, and actually close vulns on a published SLA.
- Centralize logs from identity and endpoints before you buy a lake.
- Lock down admin workstations like they are production.
03
IG3 — reduce the blast
Official-ish
Implementation Group 3: advanced controls for mature programs and higher-risk data.
Monday version
Red team thinking, application security, and finer segmentation. Do not start here to look busy.
Do this
- Penetration tests with fixed findings, not PDF souvenirs.
- Secure SDLC gates that can fail a release.
- Network and identity segmentation around crown jewels.
04
Why the order matters
Official-ish
Controls are numbered and grouped so you implement high-value basics first.
Monday version
Skipping to “threat hunting” while guests can join Wi-Fi as Domain Admin is a comedy special.
Do this
- Score yourself against IG1 before you brief the board on AI SOC dreams.
- Assign each control a name and a budget line.
- Use CIS as the how; use CSF or ISO as the why.
Friendly translation, not legal advice. Always read the official text before you tell an auditor you “basically already do this.”