Security Strategy

CIS v8.1: Turn 18 Security Controls Into Business Priorities

Make sense of the 18 CIS Controls, choose a starting point, and ask for evidence that connects cybersecurity work to business priorities.

By Tom Brennan

Featured image for CIS v8.1: Turn 18 Security Controls Into Business Priorities

Your security team reports that patching is improving, training is complete, and backups are running. Those are useful updates. But they leave a business leader with a harder question: are we protecting the operations, information, and relationships that matter most?

The CIS Controls provide a practical structure for that conversation. Instead of starting with a shopping list of tools, start with what the business needs to protect, who owns each responsibility, and what evidence shows the work is effective.

What CIS v8.1 actually gives you

The Center for Internet Security (CIS) publishes a prioritized set of cybersecurity practices. Version 8.1 organizes 153 safeguards into 18 control areas. A control describes an area of responsibility, such as account management; a safeguard describes a more specific action within that area.

Version 8.1 refines definitions, asset classes, and safeguard descriptions, and updates alignment with NIST Cybersecurity Framework 2.0, including its Govern function. It is an iterative update, not a reason to discard a working security program.

For leaders, the value is a shared language for priorities and evidence. Using CIS does not, by itself, establish regulatory compliance or certify an organization.

Choose a starting point, not a company-size label

CIS Implementation Groups help prioritize safeguards according to risk and available resources. IG1 is essential cyber hygiene and the starting point CIS recommends for every enterprise. IG2 builds on IG1 with additional safeguards. IG3 includes all safeguards, addressing more sophisticated threats.

Headcount alone is not the decision. Consider sensitive data, operational dependencies, contractual obligations, threats, and the people available to run the program. Document the rationale, identify gaps, and revisit priorities as the business changes.

Six business conversations covering all 18 controls

The following themes are our editorial reading guide, not official CIS categories or Implementation Groups. Use the complete CIS executive guide for individual control descriptions, evidence examples, and service alignment.

1. Know your assets and data: Controls 1–3

1: Inventory and Control of Enterprise Assets; 2: Inventory and Control of Software Assets; 3: Data Protection.

You cannot reliably protect systems nobody owns or sensitive information nobody has located. Ask which devices, applications, and data support essential business processes, including cloud services and remote work. Request current inventories, named owners, and data-handling rules—not just a list of purchased licenses.

Ask: “What important assets or data could be missing from our current view?”

2. Secure systems and access: Controls 4–6

4: Secure Configuration of Enterprise Assets and Software; 5: Account Management; 6: Access Control Management.

Secure settings and appropriate access should survive staff changes and system updates. Ask how accounts are approved, reviewed, and removed, and how privileged access is protected. ManageIT℠ MSOC can support endpoint operations and identity administration within the agreed scope. Physical access protection complements, but does not replace, digital access controls.

Ask: “Can we show that a departed employee no longer has access?”

3. Reduce everyday threats: Controls 7–10

7: Continuous Vulnerability Management; 8: Audit Log Management; 9: Email and Web Browser Protections; 10: Malware Defenses.

The priority is repeatable prevention, detection, and follow-through. Look for evidence that serious weaknesses are fixed, relevant activity is recorded, email and browsers are protected, and affected devices can be isolated. FraudShield™ helps employees recognize threats; phishing exercises complement rather than replace technical email and browser protections.

Ask: “Which high-risk weaknesses remain open, and who is accountable for closing them?”

4. Recover and defend networks: Controls 11–13

11: Data Recovery; 12: Network Infrastructure Management; 13: Network Monitoring and Defense.

A successful backup job is not proof that operations can recover. Ask for restoration test results, agreed recovery objectives, maintained network configurations, and monitoring coverage. Identify who can authorize containment when a suspicious event threatens a critical service. Recovery priorities should reflect business impact, not simply which system is easiest to restore.

Ask: “When did we last prove we could restore an essential business service?”

5. Prepare people, vendors and software: Controls 14–16

14: Security Awareness and Skills Training; 15: Service Provider Management; 16: Application Software Security.

Security responsibilities extend beyond the IT team. Training should match job responsibilities, vendors should receive oversight proportionate to their access and importance, and software needs security throughout its lifecycle. RISKWatch℠ supports vendor oversight. Application testing helps identify weaknesses, but does not replace secure software development.

Ask: “Which vendor or application dependency could interrupt our most important service?”

6. Respond and test: Controls 17–18

17: Incident Response Management; 18: Penetration Testing.

Plans need practice, and defenses need testing. Leaders should know who coordinates a response, makes business decisions, and communicates with stakeholders. CyberTrain℠ supports incident-response exercises; CATSCAN® tests agreed attack paths. Findings should produce assigned corrective actions and evidence of retesting—not just another report.

Ask: “What changed after our last exercise or security test?”

Turn the conversation into a manageable plan

Choose one critical business process. Identify its systems, data, people, and providers. Review the applicable safeguards against evidence, then assign an owner and due date to each priority gap. Separate implemented and verified work from planned work and accepted exceptions.

A short leadership review can track overdue high-risk actions, recovery test results, unresolved vendor concerns, and lessons from incidents or exercises. Avoid treating a single percentage as proof of security: ask what was measured, which systems were covered, and what remains unknown.

CyberAdvisor℠ can support prioritization and program oversight; MeasureRISK℠ can support gap analysis and evidence collection. These are examples of control-level support, not a guarantee of complete safeguard coverage. Delivery depends on the service agreement, and your organization retains accountability.

Start with understanding: explore the 18-control guide and service mapping, then use the service catalog to identify help for a defined gap.

Official sources

Back to the Proactive Risk blog · Talk with Proactive Risk