CIS Controls v8.1

Glossary

CIS Controls v8.1

Definition: The CIS Controls are a prioritised, vendor-neutral set of 18 safeguards published by the Center for Internet Security, organised into three Implementation Groups (IG1 through IG3) scaled to an organisation’s size and resource maturity.

CIS Controls are foundational, which is exactly why they get treated as table stakes and under-examined. Every one of the seven CIS Controls TAB has covered maps to a real, named breach, not a hypothetical: Control 3 (Data Protection) to EY’s support-ticket classification gap, Control 5 (NHI account management) to unrotated Cloudflare/Okta credentials, Control 6 (Access Control Management) to the Salesforce OAuth connected-app breach, Control 7 (Continuous Vulnerability Management) to Oracle PeopleSoft’s zero-day exposure window, Control 12 (Network Infrastructure Management) to OpenAI’s own sandbox missing a network boundary, Control 15 (Service Provider Management) to Marquis Software’s SonicWall VPN exposure, and Control 17 (Incident Response Management) to Sysco’s IR scope stopping at the primary vector instead of the whole estate.

Read the full case study on Substack: They Walked Into 100 Enterprise HR Systems Without a Password (Oracle PeopleSoft, CIS Control 7) →

← Back to Glossary