Elnion
No Result
View All Result
Saturday, September 5, 2026
  • Login
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
Subscribe
Elnion
  • AI
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain
No Result
View All Result
Elnion
No Result
View All Result
Home Cloud

CIS Controls, Safeguards, and Benchmarks for SMBs

by Heather Noggle
October 9, 2024
in Cloud, Cyber Security, Data Protection, Digital Enterprise, Disaster Recovery, Training
0
Share on TwitterShare on LinkedInShare on Facebook

The Center of Information Security, or CIS, is an American non-profit corporation that has compiled, revised, and released standards for cybersecurity controls and safeguards. It also built and maintains recommended settings for standardizing configuration settings for operating systems and browsers (and more) with its benchmarks. You can – and should – visit the CIS website at https://www.cisecurity.org/, where you’ll be greeted by the tagline, Creating Confidence in the Connected World.

We are indeed a fully connected world, so SMBs, dig in.  I’ve built a guide for you about these resources.

NIST CSF and CIS Controls

The CIS 18 controls are current with version 8.1, which considers the addition of Govern to the NIST (National Institute of Standards and Technology) CSF (Cybersecurity Framework). There’s a deep and healthy interrelationship between CIS 18 v8.1 and the NIST CSF. Download and analyze both.

The CIS controls are listed in priority order for implementation.  NIST CSF is heavily integrated; each safeguard shows whether it is primarily categorized as identify, protect, detect, respond, or recover.

Controls

The 18 controls begin with Controls 1-4  with regard to identification (and documentation) of hardware and software assets. They then discuss data protection and configuration.  Controls 5 and 6 help SMBs manage accounts and control access to those accounts. Controls 7 and 8 discuss continuous vulnerability management and the audit logs that are required to be implemented to properly do so.

Controls 9 and 10 are defense for email, web browser, and systems as a whole.  Control 11 helps a business manage backups and other data recovery initiatives.  Controls 12 and 13 concern network infrastructure and monitoring and defense of those networks.

Control 14 formalizes the components of security awareness and training.

The remaining controls discuss management of service providers, software applications, and incident response.  Finally, Control 18 regards Penetration Testing, a maturity measure of the preceding controls.

Safeguards

While the high-level controls help business managers understand the progression of the program and practice, the 153 safeguards contained within the controls show the “how” to implement. Measurement of success occurs against the safeguards listed within each control.

Three implementation groups help organisations determine the “now” and “in a later iteration” implementation of the framework.  For example, all safeguards noted within Control 18 (Penetration Testing) are listed in either Implementation Group 2 or Implementation Group 3.

The language in the safeguards is clearly explained and often includes timeframes and frequency for completing and noting recommended activities and events.

Benchmarks

The CIS Benchmarks offer extremely specific setting advice for best practices for Microsoft Windows, various browsers, Amazon Web Services configurations, and more.  There’s a full list on its site.  Manual implementation of these benchmarked settings can be labor-filled and time intensive. The implementation itself is called “hardening.” Software vendors offer benchmark-setting automation solutions, and CIS itself also offers hardened images for some of its benchmarks.

These benchmarks are extremely technical and should be incorporated within discussion of higher-order policies, processes, procedures, and other cybersecurity activities.

SMB Gains from the Framework Relationship

Consider the many gains to realize from the CIS Controls and Safeguards and understanding of the underlying NIST Cybersecurity Framework’s Identify, Protect, Detect, Respond, Recover, and, of course, Govern.

Both documents are very human readable and work well with supporting arguments you may need to make to senior management. Be prepared to use the information therein to make business arguments as well as technical requests.

Clear standardization leads to a strong foundation and a manageable path. This foundation includes clarity and through those standards offers a clear “where you should be” against which you can measure the gaps between that and “where we are.” As such, there’s clear risk reduction emphasis inherent in adopting this framework and using it also to justify requests and change management.

Implementation Groups show a path to maturity in cybersecurity, further reducing risk and emphasizing the journey aspect via a series of projects and not a one-and-done “we’re secure!” flawed approach.

Important! SMBs – add one thing to how you implement. Simultaneous with when you’re categorizing assets by implementing those early controls, also begin your training on cybersecurity awareness with your staff members and extended team. Control 14 is fairly low in the list of prioritized controls, but early activities that use Control 14’s safeguards should help increase effectiveness of communication about the “why” of changes that arise from analysis of what you uncover during implementation of earlier controls. Additionally, training you offer can help these key people be more cybersecurity aware, and that knowledge is applicable both at work and at home.

So, yes, train your people to recognize social engineering attacks, to authenticate properly and well, how to handle data, and when, where, and how to report security risks.  Train them to keep current on security updates and what websites and networks are – and are not – secure. Do this now, and improve upon it often. (Maybe I can convince CIS that this Control 14 needs to be concurrent with Control 1 and 2 in implementation for SMBs, just like I’m asserting to everyone reading).

Conclusion

If you’re not using these free resources, please download them from the CIS website. The mixture of the NIST CSF and the CIS 18 v8.1 helps you identify your assets, both software and hardware; protect your organisation by instituting policy and good cyber hygiene; detect cyberattacks; respond to those cyberattacks; and recover if any cyberattacks are successful.  The addition of governance helps surround the cycle to ensure that these functions are continuous and improving. Cybersecurity may be a mix of people, process, and technology; the technology, however, is only effective when properly governed by people implementing proper processes.

NIST SCF and CIS 18 v8.1 can help you do that, SMBs. Involve your team and partners today.

Tags: cyber hygienecybersecuritycybersecurity framework
Heather Noggle

Heather Noggle

Heather Noggle is the owner of Codistac, a company that provides writing and software guidance to startups and other technology companies. She excels with work that addresses the intersection of people and technology. Heather has built a career consisting of over 25 years of experience in technology and operations, and is a Certified Secure Software Lifecycle Practitioner (CSSLP) by (ISC)² and also holds the Security+ from CompTIA. She regularly shares insights & expertise in blogs & articles on topics such as process and cybersecurity integration, strategic writing, entrepreneurship, SMB advocacy, systems thinking, export compliance and automation, and innovation.

Related Posts

AI

The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI

September 3, 2026
AI

Data Crisis: Nearly 80% of the EU’s Data Leaders Warn Our Data Isn’t Ready for the AI Revolution

August 31, 2026
AI

Data Crisis: Nearly 80% of Japan’s Data Leaders Warn Our Data Isn’t Ready for the AI Revolution

August 29, 2026
No Result
View All Result

Recent Posts

  • The 80% Crisis: America’s Data Leaders Warn Our Data Isn’t Ready for AI
  • Building No-Regret Quantum Readiness in the Mining Sector
  • The Quantum Cybersecurity Imperative: Securing the Mining Enterprise for the Future
  • Data Crisis: Nearly 80% of the EU’s Data Leaders Warn Our Data Isn’t Ready for the AI Revolution
  • The Architectural Convergence: Quantum, AI, and HPC in the Modern Mining Enterprise
Elnion

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Cloud
  • Data
  • Digital Enterprise
  • Telco & Mobile
  • Cyber Security
  • Infrastructure
  • Automation
  • Supply Chain

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In