← Glossary

CIS Controls

The prioritized, prescriptive set of security safeguards maintained by the Center for Internet Security, ordered to stop the most common attacks first.

Updated

The CIS Critical Security Controls are a prioritized, prescriptive set of security safeguards maintained by the Center for Internet Security, designed to stop the most common attacks first. Where NIST CSF says what to think about, CIS says what to do, in order.

Key facts:

  • Version 8.1 organizes 18 controls into safeguards, tiered by Implementation Groups (IG1 to IG3) so small organizations start with the essential subset.
  • IG1 is positioned as "essential cyber hygiene", a floor every organization should reach.
  • The controls map to NIST CSF and ISO 27001, making them a practical implementation layer under either.

The controls that run through email

Several controls hit the mailbox directly: email and web browser protections (an entire control of its own), malware defenses, account management (what phished credentials unlock), data protection (where sensitive data actually flows, including to unsanctioned apps), and incident response management. The email-and-browser control exists because that pair is how commodity attacks arrive, and phishing is the top vector the safeguards list addresses.

Where email security fits, honestly

Sentaro implements the email side of the email/browser protections control and contributes to malware defense, account monitoring and incident response with AI-native detection and OAuth visibility in Google Workspace and Microsoft 365. Asset inventories, configuration hardening, patching and the broader program remain yours. For UK organizations, Cyber Essentials covers similar hygiene ground with lighter formality.

This page is general guidance, not legal advice.

Questions we get asked.

What are the CIS Controls in simple terms?

A prioritized to-do list of security safeguards, maintained by the Center for Internet Security, ordered so that the actions stopping the most common attacks come first.

What is IG1?

Implementation Group 1: the essential-hygiene subset of safeguards recommended as the minimum for every organization, regardless of size.

How do CIS Controls relate to NIST CSF and ISO 27001?

They are the prescriptive layer: CIS mappings show which safeguards satisfy which CSF functions or ISO controls, so many organizations use CIS to implement what the other frameworks require.

Which CIS Controls involve email security?

Most directly the email and web browser protections control, plus malware defenses, account management, data protection and incident response, since email is the leading initial attack vector.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.