CISv7 Controls and Best Practices
Nadean H. Tanner · 2019
The Center for Internet Security (CIS) is a self-described forward-thinking, nonprofit entity dedicated to protecting private domains and public society against cyber threats. The CIS top 20 controls are broken into three sections. The first six controls are the basic ones. These six controls are essential in any organization for cyber defense. The rest of the controls are divided into foundational and organizational, which focus on technical best practices and processes. The top six CISv7 basic controls are as follows: inventory and control of hardware assets; inventory and control of software assets; continuous vulnerability management; controlled use of administrative privileges; secure configuration for hardware and software on mobile devices, laptops, workstations, and servers; and maintenance, monitoring, and analysis of audit logs.