The Center for Internet Security (CIS) has released CIS Controls v8.1, an iterative update that adds governance recommendations and aligns the Controls with the NIST Cybersecurity Framework 2.0.
Key points
- Introduces a new ‘Govern’ security function, mirroring NIST CSF 2.0.
- Revises asset classes and maps them to individual safeguards.
- Adds and expands glossary definitions.
- Makes minor corrections and clarifications to safeguard descriptions.
- Designed to minimise disruption for existing v8 users.
The update makes it easier to use CIS Controls alongside NIST CSF 2.0 and ISO/IEC 27001. UK organisations already using v8 should review the governance safeguards and update their mappings.
Source: CIS Critical Security Controls v8.1 (CIS)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.