As cyber threats evolve and business models change, maintaining a mature cybersecurity program can be challenging. You need to be confident that your organization’s current security tools and techniques are effective. A single error or postponement in resolving a software problem can create weaknesses in your IT infrastructure, increasing the likelihood of cyber attacks.
Fortunately, the Center for Internet Security (CIS) provides a set of standards that your organization can use to gauge the effectiveness of its cybersecurity program. These 18 standards – known as CIS Critical Security Controls – evolve each year to match the changing tide of threat actors.
What are CIS Critical Security Controls?
The 18 controls prescribed by CIS are prioritized into three implementation groups (IGs). Each IG identifies a set of safeguards (previously referred to as CIS sub-controls) that your enterprise should implement based on its risk profile and available resources.
IG1
For instance, IG1 outlines basic cyber hygiene measures that guard against the most common attacks and should be implemented by every organization, regardless of size. These include maintaining an inventory of all digital assets so that security teams know the totality of what needs to be monitored and protected. These assets include end user devices, network devices, IoT devices, servers, cloud environments, and remote machines. IG1 also encompasses best practices for data protection, secure configuration, account management, access control management, continuous vulnerability management, and more.