Skip to content

Resource

CIS Controls vs NIST CSF: What Each One Is, and What Your Business Needs

The CIS Controls are a prioritized list of specific security practices: what to do, in what order. The NIST Cybersecurity Framework (CSF) is a broader structure for managing cybersecurity risk: the outcomes you should achieve. They aren't competing standards. Most well-run environments use NIST to organize the program and CIS as the practical to-do list.

Owners usually run into these names in a client security questionnaire, an insurance application, or a vendor contract, and assume they were written for enterprises with security departments. They weren't. Both are designed to scale down, and the foundational controls are things a business with 10 to 250 employees can put in place.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting ·

What the CIS Controls are

The CIS Controls, published by the Center for Internet Security, are 18 groups of specific safeguards, covering everything from asset inventory and data protection to account management and incident response. They're organized into three Implementation Groups. Implementation Group 1, which CIS calls essential cyber hygiene, is the baseline every organization should meet, and it's the natural starting point for a smaller business.

What the NIST CSF is

The NIST Cybersecurity Framework, from the National Institute of Standards and Technology, organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Version 2.0 added Govern, which puts leadership accountability for cybersecurity risk at the center. NIST tells you what outcomes to achieve. It leaves the specific how to you.

CIS vs NIST at a glance

CIS ControlsNIST CSF
What it isPrioritized list of specific safeguardsFramework of outcomes and functions
Best forDeciding what to do nextOrganizing and explaining the program
Level of detailSpecific and technicalHigh level
Starting point for smaller businessesImplementation Group 1Govern and Identify functions
Who uses itIT and security teamsLeadership, auditors, insurers

Which one should you use?

Both. NIST gives leadership, auditors, and insurers a common language. CIS gives the people doing the work a clear sequence. The practices underneath largely overlap, so aligning to one gets you most of the way to the other.

The foundational controls, in plain terms

  • Multi-factor authentication on every account, especially email, remote access, and admin accounts. It blocks the most common way attackers get in: a stolen or guessed password.
  • A current inventory of devices and software. You can't protect what you don't know is there.
  • Patching on a schedule for operating systems, applications, and firmware.
  • Backups that get tested by actually restoring from them.
  • Access reviews, so accounts are removed when people leave and permissions match the job.
  • Email security, including SPF, DKIM, and DMARC, plus tagging for external mail.
  • Security awareness training that happens more than once a year.
  • Monitoring and logging, so a problem gets noticed before it spreads.

Our own security baseline is built on the CIS Controls as a non-negotiable minimum.

Why most businesses can't answer where they stand

The frameworks themselves are rarely the problem. The problem is not knowing which controls are in place today, so there's no clear answer when a questionnaire or renewal asks.

You don't need every control perfect to make progress. Knowing exactly what's done and what isn't is more useful than an all-or-nothing view.

Schedule an IT Environment Review

How this shows up by industry

Healthcare practices apply these same controls through the HIPAA Security Risk Analysis. Manufacturers add a deliberate boundary between office and production networks.

Common questions

Questions leadership usually asks first.

Next step

Want to see where your environment stands against these controls?

Schedule an IT Environment Review.