The Center for Internet Security (CIS) has released CIS Controls Version 8, a significant update to its prioritised set of cyber security best practices.
Key points
- Controls are consolidated from 20 to 18 groups.
- Organised by activity rather than by who manages devices, reflecting cloud, mobile and remote working.
- Adds a new control on service provider management.
- Safeguards are prioritised into Implementation Groups IG1 to IG3, scaled to organisation size and risk.
- IG1 defines essential cyber hygiene for smaller organisations.
CIS Controls are increasingly referenced by cyber insurers and customers. UK organisations can use the Implementation Groups as a practical roadmap alongside Cyber Essentials and ISO/IEC 27001.
Source: CIS Critical Security Controls v8 (CIS)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.