CIS CONTROLS UPDATED FOR ‘MUST HAVE’ CYBER SECURITY

The Center for Internet Security (CIS) has announced that it has released an update to its highly regarded CIS Controls best practice list. Published at the end of April 2018, the CIS Controls V7 feature the same twenty ‘must have’ counter measures that businesses around the world already depend upon to stay cyber secure.

 

New CIS Category Groupings

Designed to reflect the current cyber threat landscape, these controls have now been grouped into three distinct categories:

Basic (Controls 1-6) – include asset and vulnerability management and should be implemented in every organisation for essential cyber defence readiness.

Foundational (Controls 7-16) – the next step up from basic, these technical best practices provide clear security benefits and are a smart move for any organisation to implement.

Organisational (Controls 17-20) – different in character from 1-16 and while many are technical they are more focused on people and processes involved in cybersecurity.

 

Seven Key Principles

When designing the latest version of the CIS Controls, the following seven key principles were used to guide the development process:

  • – Improve the consistency and simplify the wording of each sub-control
  • – Implement “one ask” per sub-control
  • – Bring more focus on authentication, encryption, and application whitelisting
  • – Account for improvements in security technology and emerging security problems
  • – Better alignment with other frameworks (such as the NIST CSF)
  • – Support the development of related products (e.g. measurements/metrics, implementation guides)
  • – Identify types of CIS controls (basic, foundational, and organizational)

 

Consensus of over 300 cyber security professionals

The CIS Controls V7 best practices have been developed using a consensus approach involving discussion groups, forums, and community feedback. This includes contributions from over three hundred individual cyber security professionals who are leaders in academia, industry and government organisations. Unlike many similar cyber security recommendations, the CIS Controls are highly regarded as they are regularly updated, technically very accurate and published with free availability.

 

The bedrock for Wizard Cyber security audits

At Wizard Cyber, we use the CIS Controls as the basis for cyber security audits of new and existing customers. Version 7 will now allow us to tailor the audit to accommodate both small firms and larger enterprises. We don’t disagree with the Center for Information Security, but we believe that all companies should be applying both the Basic and Foundation control sets.

——————–

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation