
Explore CIS controls version 8 for IT, OT, and IoT, including asset inventory, software control, data protection, secure configurations, access management, and continuous vulnerability management.
Introduces CIS control version 8 with emphasis on email and web protection, malware defenses, network monitoring, security awareness, third-party risk, secure software development, incident response, and penetration testing.
Learn to establish and maintain a comprehensive inventory and control of enterprise assets across physical, virtual, and cloud environments using active and passive discovery to support security and incident response.
Establish and maintain a detailed software inventory, authorize only approved software, implement allow listing and denial controls, and biannually review licenses and security measures.
Identify, classify, and securely handle data to protect against breaches; implement encryption in transit and at rest, data retention and disposal, and a data breach and incident response framework.
Establish and maintain the secure configuration of enterprise assets and software, replacing default credentials. Disallow unused services, apply benchmarks, and manage updates to enforce secure DNS and device protections.
Define account management to assign and control access for user, administrative, and service accounts, enforcing password policy, MFA, inventory of accounts, and access reviews.
Implement the CIS control 6 access control by enforcing identity and access management, least privilege, need-to-know, provisioning, centralized audit trails, and multifactor authentication for remote and privileged access.
Develop and maintain a plan for continuous vulnerability management across internal and external assets, using scanning tools, ticketing workflows, and remediation to minimize the window of opportunity.
Implement audit log management with centralized logging, standardized time synchronization, and retention of at least 90 days to support incident investigation and enterprise analysis.
Protect email and web browsing by blocking phishing and social engineering, updating browsers, and limiting risky plugins. Enforce content filtering and anti-malware tools to secure email gateways.
CIS control 10 outlines malware defenses that prevent and control malicious code across enterprise endpoints, removable media, email, web applications, and cloud services through automated, updated protection and incident response.
Establish and maintain data recovery practices using full, incremental, and differential backups, automate backups, define backup frequency, test regularly, and restore systems to the original trusted state.
Implement an actively managed network infrastructure by inventorying devices, tracking changes, and correcting vulnerabilities. Document architecture diagrams, enforce RBAC and logging, and use secure protocols and multifactor authentication for administration.
Implement comprehensive network monitoring and defense through continuous monitoring, centralized security alerting, and threat intelligence. Deploy ids/ips, firewall filtering, log collection, and strict access controls to detect and respond quickly.
Establish and maintain a security awareness program to influence behavior and reduce cybersecurity risks. Deliver role-based training, phishing exercises, and incident reporting with emphasis on multifactor authentication and data handling.
Implement a third-party risk assessment for service providers handling sensitive data, including inventory, risk classification, contractual accountability, monitoring, and annual reassessment to meet HIPAA, PCI DSS, and FFIEC standards.
Improve application security under CIS control 16 by integrating vulnerability management into the development lifecycle, training developers in secure coding, and securing third-party components across multi-platform architectures.
Establish and maintain an incident response program to detect, respond, contain, and recover from cyber incidents, with clear roles, communication, training, root-cause analysis, and post-incident lessons.
Explore how penetration testing identifies and exploits vulnerabilities to assess the resilience of IT, OT, and IoT controls, including external and internal assessments and attacker impact.
What is CIS?
CIS stands for The Center for Internet Security.
It is a community-driven non profitable organization formed in Oct,2000.
It makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation.
Few CIS Controls
1. Inventory and Control of Enterprise Assets - Manage all enterprise assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise.
2. Inventory and Control of Software Assets - Manage all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
3. Data Protection - Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
4. Secure Configuration of Enterprise Assets & Software - Establish and maintain the secure configuration of enterprise assets and software.
5. Account Management - Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.
6. Access Control - Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.