CIS Controls v8.1
Part of the core list for the United States. A consensus control set, not a law, cited by safeguard number.
edition CIS Controls v8.1. 43 requirements cited here. Every CIS Controls v8.1 clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 6.3 CIS Controls v8.1 | Require MFA for Externally-Exposed Applications Where supported, make every enterprise or third-party application exposed externally enforce MFA. Enforcing MFA via an SSO provider or a directory service is an acceptable way to meet this Safeguard. evidence an assessor asks for SSO or application MFA configuration for all externally exposed applications; List of external applications with MFA status and any exceptions; Authentication standard requiring MFA on every internet-facing enterprise and third-party application; SSO conditional access policy export showing MFA required for external sign-ins to each listed application; Sign-in log sample for external apps showing MFA challenge satisfied, with legacy authentication attempts blocked |
Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 6.3 CIS Controls v8.1 | Require MFA for Externally-Exposed Applications Where supported, make every enterprise or third-party application exposed externally enforce MFA. Enforcing MFA via an SSO provider or a directory service is an acceptable way to meet this Safeguard. evidence an assessor asks for SSO or application MFA configuration for all externally exposed applications; List of external applications with MFA status and any exceptions; Authentication standard requiring MFA on every internet-facing enterprise and third-party application; SSO conditional access policy export showing MFA required for external sign-ins to each listed application; Sign-in log sample for external apps showing MFA challenge satisfied, with legacy authentication attempts blocked |
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 6.4 CIS Controls v8.1 | Require MFA for remote network access. evidence an assessor asks for Inventory of remote access paths, including VPN, ZTNA, RDP gateways and vendor support tools, each mapped to its MFA enforcement point; Access control standard requiring MFA on every remote network connection, including third parties, with the approver for any exception; VPN, ZTNA or remote desktop gateway configuration requiring a second factor for every remote session; Remote access logs showing MFA outcome per session, with any single-factor connections investigated |
| CIS 6.5 CIS Controls v8.1 | Require MFA for Administrative Access Where supported, require MFA on every account with administrative access, on every enterprise asset, whether the asset is managed on site or by a third-party provider. evidence an assessor asks for MFA configuration for all administrative accounts, on-site and third-party managed; Report of admin accounts with MFA enrolment status; Privileged access standard requiring MFA for all administrative logons, including provider-managed assets; PAM or identity provider policy export enforcing MFA on admin roles, cloud consoles and hypervisor management; Admin logon records sampled across on-site and hosted assets showing MFA used on each |
Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.1 CIS Controls v8.1 | Establish and Maintain a Data Recovery Process Set up and keep a process for recovering data that defines what recovery covers, the order of recovery priorities, and how backup data is kept secure. Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Data recovery process document defining recovery scope, recovery priority order and how backup data is secured, with version history; Record of the annual review of the recovery documentation, including changes triggered by major enterprise changes; Recovery priority list mapping business services and their systems to RTO and RPO targets, approved by the service owners; Backup security section of the recovery process covering encryption, access restriction and separation of backup credentials; Change records for major enterprise changes, such as new systems or a data centre move, showing the recovery documentation updated |
| CIS 11.2 CIS Controls v8.1 | Perform Automated Backups Back up in-scope enterprise assets automatically, at least weekly, with frequency set by how sensitive the data is. The requirement's own words: at least weekly evidence an assessor asks for Backup job schedule configuration showing automated backups at least weekly, with frequency mapped to data sensitivity; Backup job success and failure reports for the last 90 days, with failed jobs re-run or remediated; Data classification to backup frequency matrix, such as daily for sensitive databases and weekly for general file shares; Backup coverage report comparing protected systems in the backup tool with the asset inventory; Alerting configuration that notifies the backup team of failed or skipped jobs, with sample alert tickets |
Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.3 CIS Controls v8.1 | Protect Recovery Data Give recovery data protection equal to that of the original data, drawing on encryption or data separation as the requirements dictate. evidence an assessor asks for Backup encryption configuration showing the algorithm, key management arrangement and access restrictions on backup repositories; Access control list for backup storage and backup consoles, matched against the access list for the source data; Encryption settings for backup media and cloud backup storage, including tape encryption and key custody separate from backup operators; Data classification mapping showing backups of each sensitive data set protected at the same level as production; Access review of backup administrators and service accounts, with removals of staff who no longer need access |
| CIS 11.4 CIS Controls v8.1 | Establish and Maintain an Isolated Instance of Recovery Data Set up and keep a copy of recovery data that is isolated, for example by version-controlling backup targets held off site, in the cloud or offline, whether as systems or as services. evidence an assessor asks for Architecture or configuration record of the isolated backup copy: offline, immutable, air-gapped or versioned off-site or cloud target; Report confirming the isolated copy is current, with its retention and immutability settings and the date of the last successful write; Immutability or object lock configuration on the isolated backup target, with retention period and who can change it; Network and identity separation record showing the isolated copy is not reachable with production domain credentials; Off-site or offline media rotation log with dates, media IDs and custody signatures |
Administrator accounts (other than the backup administrator) cannot change or delete backups
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.3 CIS Controls v8.1 | Protect Recovery Data Give recovery data protection equal to that of the original data, drawing on encryption or data separation as the requirements dictate. evidence an assessor asks for Backup encryption configuration showing the algorithm, key management arrangement and access restrictions on backup repositories; Access control list for backup storage and backup consoles, matched against the access list for the source data; Encryption settings for backup media and cloud backup storage, including tape encryption and key custody separate from backup operators; Data classification mapping showing backups of each sensitive data set protected at the same level as production; Access review of backup administrators and service accounts, with removals of staff who no longer need access |
Restoring from backup is tested as part of a disaster recovery exercise
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 11.5 CIS Controls v8.1 | Test Data Recovery At least once a quarter, test recovery from backup for a sample of in-scope enterprise assets. The requirement's own words: At least once a quarter evidence an assessor asks for Quarterly recovery test reports naming the sample of assets restored, the restore time achieved and the integrity checks performed; Follow-up records for any recovery test failures, with the corrective actions taken and the retest result; Annual test schedule showing which systems are sampled each quarter so critical systems are covered over the year; Restore evidence such as application owner sign-off that restored data was complete and usable; Comparison of actual restore times achieved against the RTO targets, with gaps escalated |
Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.3 CIS Controls v8.1 | Perform Automated Operating System Patch Management Keep operating systems on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for OS patch management tool configuration with automated monthly deployment; OS patch compliance reports per asset; Patch management standard defining monthly OS patch cycles and emergency patch windows; Deployment rings or maintenance window settings in the patching tool covering workstations and servers; Monthly OS patch deployment reports showing success rate and failed devices remediated |
| CIS 7.4 CIS Controls v8.1 | Perform Automated Application Patch Management Keep applications on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites |
| CIS 7.7 CIS Controls v8.1 | Remediate Detected Vulnerabilities Fix vulnerabilities found in software, using processes and tools in line with the remediation process, at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Vulnerability remediation tracker showing monthly closure per the remediation process; Rescan results verifying fixes; Remediation tickets linked to scanner findings with severity, owner and due date; Monthly remediation metrics showing overdue vulnerabilities by severity and asset owner; Closed ticket sample with before and after scan evidence for each fix |
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.3 CIS Controls v8.1 | Perform Automated Operating System Patch Management Keep operating systems on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for OS patch management tool configuration with automated monthly deployment; OS patch compliance reports per asset; Patch management standard defining monthly OS patch cycles and emergency patch windows; Deployment rings or maintenance window settings in the patching tool covering workstations and servers; Monthly OS patch deployment reports showing success rate and failed devices remediated |
| CIS 7.4 CIS Controls v8.1 | Perform Automated Application Patch Management Keep applications on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites |
Other business applications are patched within the timeframe in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.4 CIS Controls v8.1 | Perform Automated Application Patch Management Keep applications on enterprise assets updated by automated patch management, running at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Application patch management configuration with automated monthly deployment; Application patch compliance reports; Patch standard covering third-party applications, not only operating system updates; Third-party patching tool catalogue showing which applications are auto-updated; Monthly application version compliance report for browsers, runtimes, PDF readers and office suites |
Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 7.5 CIS Controls v8.1 | Perform Automated Vulnerability Scans of Internal Enterprise Assets Scan internal enterprise assets for vulnerabilities automatically at least once a quarter, running both authenticated and unauthenticated scans with a SCAP-compliant scanner. The requirement's own words: at least once a quarter evidence an assessor asks for Quarterly authenticated and unauthenticated internal scan reports from a SCAP-compliant scanner; Scanner configuration showing credentials and scope; Scanning standard requiring quarterly authenticated and unauthenticated internal scans; Scan schedule export showing recurring internal jobs and credential test success per target range; Scanner coverage reconciliation against the asset inventory, listing hosts not scanned |
| CIS 7.6 CIS Controls v8.1 | Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets Scan externally exposed enterprise assets for vulnerabilities automatically with a SCAP-compliant scanner, at least once a month. The requirement's own words: at least once a month evidence an assessor asks for Monthly external vulnerability scan reports from a SCAP-compliant scanner; Scan scope list matched to externally exposed assets; External scanning procedure naming the monthly schedule and who reconciles the public IP and domain list; Scheduled external scan job settings and the public IP and DNS list fed to the scanner; Month-by-month external scan history with no missed months and findings routed to remediation |
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 2.2 CIS Controls v8.1 | Ensure Authorized Software is Currently Supported Only software that still receives vendor support may be marked as authorised in the enterprise software register. Where unsupported software is still needed for the mission, record an exception that sets out the compensating controls and the acceptance of remaining risk. Unsupported software with no recorded exception is to be marked unauthorised. Check the list for support status no less often than monthly. evidence an assessor asks for Authorised software list compared with vendor support status, showing only supported software authorised; Exception register for unsupported software with mitigating controls and residual risk acceptance; Monthly support status check record comparing each authorised title with vendor end-of-life announcements; Software register entries for end-of-support titles marked unauthorised where no exception exists; Risk acceptance sign-offs by a named business owner for each unsupported title kept for the mission |
Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 5.4 CIS Controls v8.1 | Restrict Administrator Privileges to Dedicated Administrator Accounts Confine administrator privileges on enterprise assets to accounts used only for administration. Everyday computing, for example web browsing, email and office productivity tools, is to be done from the user's main account without privileges. evidence an assessor asks for List of dedicated admin accounts separate from users' everyday accounts; Privilege review showing everyday accounts hold no administrator rights; Membership exports of privileged groups showing only admin-designated accounts; Policy settings blocking email and web browsing for administrator accounts; Sample of administrators showing a separate standard account used for daily work |
Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 5.1 CIS Controls v8.1 | Establish and Maintain an Inventory of Accounts Keep a register of every account the enterprise manages, covering both user and administrator accounts. At a minimum each entry should hold the person's name, the username, the start and end dates, and the department. Confirm that every active account is authorised on a regular cycle of at least once a quarter. The requirement's own words: at least once a quarter evidence an assessor asks for Account inventory showing name, username, start and end dates and department for user and admin accounts; Quarterly account validation records; Identity management standard naming who authorises accounts and the quarterly validation cadence; Reconciliation of the account inventory against the HR system showing mismatches and actions taken; Inventory entries for service and shared accounts with an accountable owner recorded |
Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 5.3 CIS Controls v8.1 | Disable Dormant Accounts Where supported, remove or disable any account that has been dormant for 45 days. evidence an assessor asks for Directory report of accounts inactive for 45 days or more; Automated disablement configuration or tickets showing dormant accounts disabled; Scheduled job or identity governance rule configuration disabling accounts after 45 days without logon; Exception list for dormant accounts retained, with owner approval; Cloud identity provider and SaaS inactive user reports checked alongside the directory |
Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 5.2 CIS Controls v8.1 | Use Unique Passwords Give every enterprise asset its own unique password. Good practice sets a floor of 8 characters for accounts protected by MFA and 14 characters for accounts without MFA. evidence an assessor asks for Password policy configuration enforcing 8-character minimum with MFA and 14 without; Privileged access tool records showing unique local administrator passwords per asset; Local administrator password solution deployment report showing coverage across workstations and servers; Network device and appliance credential vault entries showing a distinct password per device; Directory fine-grained password policy for accounts not protected by MFA showing the 14-character minimum |
| CIS 4.7 CIS Controls v8.1 | Manage Default Accounts on Enterprise Assets and Software Control the default accounts that come with enterprise assets and software, for example root, administrator and other accounts preset by vendors, by disabling them or rendering them unusable. evidence an assessor asks for Default account inventory and configuration showing default accounts disabled or renamed with changed credentials; Scan results confirming no vendor default credentials remain active; Hardening checklist entries showing root, administrator and vendor preset accounts handled at build time; Credential audit results for network devices, appliances and databases testing for vendor defaults; Service account inventory showing default vendor accounts disabled or password changed |
Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 2.5 CIS Controls v8.1 | Allowlist Authorized Software Apply technical measures, for instance application allowlisting, so that only authorised software is able to run or be opened. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Application allowlisting policy configuration, such as AppLocker or WDAC, showing enforcement mode; Blocked execution logs and records of the twice-yearly allowlist reassessment; Allowlist rule set export showing publisher, path or hash rules and who approved each addition; Endpoint policy assignment report showing allowlisting in enforce mode rather than audit-only across device groups; Minutes or ticket from the twice-yearly allowlist review listing rules added and removed |
| CIS 2.7 CIS Controls v8.1 | Allowlist Authorized Scripts Apply technical measures, such as digital signing and version control, so that only authorised scripts (for example particular .ps1 or .py files, among others) can run, and stop unauthorised scripts from running. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Script control configuration requiring signing or version control for .ps1, .py and similar scripts; Logs of blocked unsigned scripts and records of the twice-yearly reassessment; Script execution policy and constrained language settings enforced centrally; Code signing certificate issuance records and the repository approval workflow for scripts; Sample of production scripts showing a valid signature or a commit in the controlled repository |
Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 2.5 CIS Controls v8.1 | Allowlist Authorized Software Apply technical measures, for instance application allowlisting, so that only authorised software is able to run or be opened. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Application allowlisting policy configuration, such as AppLocker or WDAC, showing enforcement mode; Blocked execution logs and records of the twice-yearly allowlist reassessment; Allowlist rule set export showing publisher, path or hash rules and who approved each addition; Endpoint policy assignment report showing allowlisting in enforce mode rather than audit-only across device groups; Minutes or ticket from the twice-yearly allowlist review listing rules added and removed |
| CIS 2.6 CIS Controls v8.1 | Allowlist Authorized Libraries Apply technical measures so that a system process can load only authorised software libraries (for example particular .dll, .ocx or .so files, among others), and stop unauthorised libraries from loading. Reassess at least twice a year. The requirement's own words: at least twice a year evidence an assessor asks for Library allowlisting configuration covering .dll, .ocx and .so files; Logs of blocked library loads and records of the twice-yearly reassessment; DLL rule collection or WDAC policy export showing library enforcement enabled, not just executable rules; Sample of blocked library load events with triage outcome for each; Approved library list with signing certificate or hash for each authorised module |
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 9.4 CIS Controls v8.1 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions Uninstall or disable any browser or email client plugin, extension or add-on application that is unauthorised or not needed. evidence an assessor asks for Browser and email client extension allowlist policy; Endpoint report of installed extensions with unauthorised ones removed; Browser and email add-in standard defining the approval route for new extensions; Managed browser policy and Outlook add-in configuration enforcing the allowlist; Periodic extension inventory report with removals of unapproved add-ons recorded |
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 4.1 CIS Controls v8.1 | Establish and Maintain a Secure Configuration Process Set up and keep a process for configuring enterprise assets securely (end-user devices, portable and mobile ones included, IoT and other non-computing devices, and servers) as well as software (both operating systems and applications). Revisit the documentation each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Secure configuration process document covering end-user devices, network devices, IoT, servers and software; Secure configuration baselines the business has adopted, and the annual review record; Configuration standards per asset class, including IoT and mobile devices, with the deviations approved; Configuration compliance scan results against the approved baselines for a sample of assets; Evidence of the process reassessment after a major change such as a new OS release |
Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 8.2 CIS Controls v8.1 | Collect Audit Logs Gather audit logs, making sure logging has been switched on across enterprise assets as the audit log management process requires. evidence an assessor asks for Logging configuration per asset type enabled per the log management process; Log source coverage report against the asset inventory; Log collection standard specifying which assets must have audit logging switched on; Group policy, agent or cloud diagnostic settings enabling audit logging on each asset type; Log source silence alerts showing assets that stopped sending logs and the follow-up |
| CIS 8.11 CIS Controls v8.1 | Conduct Audit Log Reviews Review audit logs at least weekly to spot anomalies or unusual events that might signal a threat. The requirement's own words: at least weekly evidence an assessor asks for Weekly log review records with anomalies identified and follow-up; Reviewer sign-off or ticket evidence for each weekly review; Log review procedure defining weekly review scope, triage steps and escalation to incident response; SIEM dashboards or correlation rules used for the weekly review, with last-tuned dates; Incident or investigation tickets raised from weekly review findings |
There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 17.1 CIS Controls v8.1 | Designate Personnel to Manage Incident Handling Name one key person, plus at least one deputy, to run the enterprise incident handling process. These managers coordinate and document incident response and recovery, and may be enterprise employees, third-party vendors, or a mix of both. Where a third-party vendor is used, name at least one person inside the enterprise to oversee the vendor's work. Review this each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Appointment record naming the primary incident handling manager and at least one backup; Incident records showing the designated managers coordinated and documented response; Deputy incident manager named with contact details and coverage for leave; Named internal overseer for an outsourced incident response retainer or MSSP; Annual review record confirming incident manager appointments are still current |
| CIS 17.4 CIS Controls v8.1 | Establish and Maintain an Incident Response Process Set up and keep an incident response process that sets out who does what, which compliance requirements apply, and a plan for communications. Review it each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Incident response plan defining roles, applicable compliance requirements and the communication plan; Record of the annual incident response plan review and changes made; Mapping of the plan to legal and contractual notification duties, such as breach reporting deadlines; Communication plan templates for staff, customers, regulators and media, with approvers; Incident records showing the plan was followed in a real incident |
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 10.1 CIS Controls v8.1 | Deploy and Maintain Anti-Malware Software Install and keep anti-malware software running on every enterprise asset. evidence an assessor asks for Anti-malware console deployment report showing agent coverage against the full asset inventory, with unprotected assets listed; Exception register for assets that cannot run anti-malware, with the compensating control and approver for each; Endpoint security standard requiring the anti-malware agent on every workstation, server and mobile device class, and naming the approved product; Agent health report listing endpoints with the service stopped, tamper protection off or no check-in within the last 7 days; Reconciliation of the anti-malware console against the asset inventory and new-build tickets, showing agents installed at provisioning |
| CIS 10.6 CIS Controls v8.1 | Centrally manage anti-malware software. evidence an assessor asks for Reconciliation of the asset inventory against console-registered endpoints, listing unmanaged devices and the date each was enrolled; Malware defence standard naming the central console as the only approved management point and the owner accountable for policy changes; Central anti-malware console showing all endpoints registered, policy assignment by group and the administrators with console rights; Console audit log of policy changes, exclusions added and detections reviewed, with who made each change |
| CIS 10.7 CIS Controls v8.1 | Use behavior-based anti-malware software. evidence an assessor asks for Endpoint coverage report listing every device running the behaviour-based engine, reconciled to the enterprise asset inventory; Endpoint protection standard stating behavioural detection must run in block mode, with the approval route for any detect-only exception; Product configuration showing behaviour-based detection, such as heuristics, machine learning or EDR behavioural rules, enabled and in block mode; Sample of detections raised by behaviour rules rather than signatures, with the analyst disposition |
Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 9.5 CIS Controls v8.1 | Implement DMARC Put DMARC policy and verification in place to reduce the risk of forged or altered email appearing to come from legitimate domains, beginning with the SPF and DKIM standards. evidence an assessor asks for DNS records for SPF, DKIM and DMARC with the DMARC policy level; DMARC aggregate reports and review records; Email authentication standard setting the target DMARC policy and rollout timeline; Inventory of sending domains and third-party senders with SPF and DKIM alignment status; DMARC report review records showing unauthorised senders identified and policy moved to quarantine or reject |
| CIS 9.6 CIS Controls v8.1 | Block Unnecessary File Types Stop file types that are not needed from passing through the enterprise email gateway. evidence an assessor asks for Email gateway blocked file type policy; Gateway logs showing blocked attachments; Email security standard listing file types to block and the business exception process; Gateway attachment policy export blocking executables, scripts and macro-enabled types; Quarantine review records showing blocked file type releases approved by security |
| CIS 9.7 CIS Controls v8.1 | Deploy and Maintain Email Server Anti-Malware Protections Put in place and maintain anti-malware protection on email servers, for example scanning of attachments and/or sandboxing. evidence an assessor asks for Email server anti-malware and sandboxing configuration; Detection reports showing malicious attachments caught; Email security standard requiring attachment scanning and sandboxing on mail servers; Mail server or cloud email security configuration with signature updates and sandbox detonation enabled; Weekly detection summary showing sandbox verdicts, blocked malware and post-delivery removals |
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 14.1 CIS Controls v8.1 | Establish and Maintain a Security Awareness Program Set up and keep a security awareness programme whose aim is to teach the workforce how to use enterprise assets and data securely. Train people when they are hired and at least yearly after that. Revisit the content each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Security awareness programme document with content, audience, delivery methods and the annual review date; Training completion records showing new hires trained at onboarding and all staff trained at least annually; Management-approved awareness policy stating mandatory training, the target workforce population and consequences for non-completion; Learning management system export listing each worker's completion date, with contractors and temporary staff included; Annual content review record showing topics updated for new threats, systems or enterprise changes, with approver |
| CIS 14.2 CIS Controls v8.1 | Train Workforce Members to Recognize Social Engineering Attacks Teach the workforce to spot social engineering, for example phishing, pretexting and tailgating. evidence an assessor asks for Social engineering training module content covering phishing, pretexting and tailgating, with completion records; Phishing simulation campaign results showing click and report rates and the follow-up training for repeat clickers; Phishing simulation programme plan covering frequency, templates of increasing difficulty and target groups including executives; Tailgating and pretext awareness materials such as posters, briefings or physical social engineering test results; Report or dashboard of suspicious email reports through the report-phishing button, with time to report |
| CIS 14.6 CIS Controls v8.1 | Train Workforce Members on Recognizing and Reporting Security Incidents Teach the workforce to recognise a possible incident and to report it. evidence an assessor asks for Training content showing how to recognise a potential incident and the reporting channel to use; Completion records, plus a sample of workforce-originated incident reports showing the channel is being used; Incident reporting instructions issued to staff: examples of incidents, the report channel, hotline and expected response; Metrics on time from event to staff report for recent incidents, used to measure training effect; Tabletop or awareness exercise records where staff practised recognising and reporting an incident |
Laptops, phones and removable media that hold sensitive data are encrypted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 3.6 CIS Controls v8.1 | Encrypt Data on End-User Devices Encrypt the data held on end-user devices that store sensitive data. (The held text goes on to give examples that name commercial products; they are left out here.) evidence an assessor asks for Endpoint encryption policy for the built-in disk encryption of each operating system; Encryption compliance report listing unencrypted end-user devices and remediation; MDM or endpoint management encryption status report for laptops and desktops holding sensitive data; Recovery key escrow records showing keys stored centrally for each encrypted device; Build standard showing encryption enabled before a device is issued |
| CIS 3.9 CIS Controls v8.1 | Encrypt data on removable media. evidence an assessor asks for Inventory of approved encrypted USB devices issued to staff, with serial numbers, holders and the encryption algorithm used; Data protection standard requiring encryption of any enterprise data written to removable media, with the approved tools and exemption process; Endpoint or device management policy forcing encryption before writes to USB drives; Device control logs showing unencrypted removable media blocked or set to read-only |
Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 4.4 CIS Controls v8.1 | Implement and Manage a Firewall on Servers Where servers support it, run and manage a firewall on them, for example a virtual firewall, the operating system's own firewall, or a firewall agent from a third party. evidence an assessor asks for Server firewall policy configuration showing default-deny rules; Compliance report of server firewall status across the server estate; Host firewall rule sets for sampled servers showing inbound allowed only for required services; Cloud security group or virtual firewall rules for server workloads with the rule owner recorded; Change tickets for server firewall rule changes with approval |
| CIS 4.5 CIS Controls v8.1 | Implement and Manage a Firewall on End-User Devices On end-user devices, run and manage a firewall on the host or a tool that filters ports, set to deny by default so that all traffic is dropped apart from explicitly permitted services and ports. evidence an assessor asks for End-user device firewall policy with default-deny and explicitly allowed ports; Endpoint compliance report of firewall status; Endpoint firewall profile settings showing default inbound block on domain, private and public networks; List of explicitly permitted ports and services with the business reason for each; Report of endpoints where users have disabled the firewall and the remediation raised |
IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CIS 15.1 CIS Controls v8.1 | Establish and Maintain an Inventory of Service Providers Keep an inventory of service providers that lists every known provider, gives its classification or classifications, and names an enterprise contact for each. Revisit the inventory each year, or sooner when a major change in the enterprise could affect this Safeguard. evidence an assessor asks for Service provider inventory listing each provider, its classification and the named enterprise contact; Record of the annual inventory review, with providers added, reclassified or removed; Accounts payable vendor list reconciled to the service provider inventory to find providers missing from it; Change or restructuring records that triggered an out-of-cycle inventory update, such as an acquisition or new cloud platform; Named contact entries checked against the HR directory, with leavers replaced |
| CIS 15.4 CIS Controls v8.1 | Ensure Service Provider Contracts Include Security Requirements Make sure contracts with service providers carry security requirements, for example minimum requirements for the security programme, notification of and response to security incidents and/or data breaches, encryption of data, and commitments on data disposal. The requirements must align with the enterprise service provider management policy. Check the contracts each year to confirm no security requirement is missing. evidence an assessor asks for Sample of service provider contracts with clauses on minimum security programme requirements, incident and breach notification, encryption and data disposal; Contract review checklist showing security clauses verified before signature; Annual contract review log listing each contract checked, missing security clauses found and the amendment raised; Standard security schedule or addendum template aligned to the service provider management policy; Amendment or side letter records adding breach notification timeframes to older contracts |
Questions
- When does CIS Controls v8.1 apply here?
- Part of the core list for the United States. A consensus control set, not a law, cited by safeguard number.
- Which edition is held?
- CIS Controls v8.1
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.