Home / Insights / Glossary / CIS Controls

Glossary

CIS Controls

A prioritised set of defensive actions published by the Center for Internet Security.

What it means

The CIS Critical Security Controls are a prioritised, prescriptive set of safeguards grouped into implementation groups by organisation size and capability. They are more concrete than outcome-based frameworks, which is their appeal to smaller teams.

Prescriptive lists answer what to do. They do not record why an organisation chose to defer one, or on what basis that deferral was reasonable.

Where MyRISK fits

What we do about it

MyRISK does not assess or score CIS implementation. The deferrals and exceptions — the parts of a control set an organisation consciously does not do yet, and why — are decisions, and Trace is where those are held.

MyRISK Trace

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.