CIS Controls
Last updated
Definition
The CIS Controls (Center for Internet Security Critical Security Controls, currently v8.1) are a free, prescriptive set of 18 security controls broken into specific safeguards, ordered roughly by impact. What makes them usable is the Implementation Group tiering: IG1 – 56 safeguards across 15 controls, labeled "essential cyber hygiene" – is explicitly designed for small organizations without dedicated security staff; IG2 adds safeguards for organizations handling sensitive or regulated data; IG3 covers mature, high-risk environments.
Why it matters to an MSP
CIS is the MSP channel's favorite framework because it answers "what exactly should we do" rather than "how should we think about risk." The proven pattern: run your own MSP at IG1 and graduate toward IG2 – you're a higher-value target than any single client – and use IG1 as the client assessment checklist. An IG1 gap assessment is a natural paid entry engagement and a structured way to scope a managed security offering; regulated clients graduate to IG2. Because it's prescriptive, it converts directly into your service catalog: each safeguard maps to a deliverable – patch management, MFA rollout, backup testing, logging. Then map results to the NIST CSF when reporting to owners and insurers: CIS for the to-do list, CSF for the executive story.
Related terms: NIST CSF, Compliance, Vulnerability Management