CIS Critical Security Controls (CSC)

View as Markdown

What are the Critical Security Controls?

The CIS Critical Security Controls (CIS Controls) are a prioritized collection of cybersecurity best practices, first developed by the SANS Institute in 2008 and now maintained by the Center for Internet Security. An informal community process updates the CIS Controls so they keep pace with the most effective security controls and the most relevant cyber attacks.

Who is the intended audience?

The CIS Critical Security Controls are for organizations of any size that want a prioritized approach to defending against cyber attacks. The framework is voluntary and does not replace any industry standard, regulatory framework, or other legal obligation.

Where can I find more information?

Download the CIS Critical Security Controls from the Center for Internet Security website.

How can runZero help me with these controls?

The table below maps runZero to the CIS Critical Security Controls v8. Strong alignment means runZero can play a significant role in helping an organization implement safeguards; Partial alignment means runZero can play a complementary role.

No Control Strong alignment Partial alignment
01 Inventory and Control of Enterprise Assets
02 Inventory and Control of Software Assets
03 Data Protection
04 Secure Configuration of Enterprise Assets and Software
05 Account Management
06 Access Control Management
07 Continuous Vulnerability Management
08 Audit Log Management
09 Email and Web Server Protection
10 Malware Defenses
11 Data Recovery
12 Network Infrastructure Management
13 Network Monitoring and Defense
14 Security Awareness and Skills Training
15 Service Provider Management
16 Application Software Security
17 Incident Response Management
18 Penetration Testing
Updated