← Back to Library
CIS Controls

CIS Controls v6.0

Full Name:
Center for Internet Security (CIS) Controls
Acronym:
CIS Controls
Type:
Industry Standard
Organization:
Center for Internet Security
Version:
6
Year Published:
2016
Popularity:
Low

Overview of CIS Controls v6.0

CIS Controls Version 6.0, published in 2016, represented an evolutionary update to the Critical Security Controls framework (formerly known as the SANS Top 20). This version introduced 20 prioritized security controls designed to protect against the most pervasive cyber threats, with enhanced focus on automated asset discovery, continuous vulnerability management, and controlled use of administrative privileges. Version 6.0 emphasized actionable, measurable security practices that organizations could implement progressively based on resources and risk exposure.

As a legacy version now superseded by v7.0 (2018), v7.1 (2019), v8.0 (2021), and v8.1 (2024), version 6.0 is no longer recommended for new implementations. Organizations currently using v6.0 should plan transitions to v8.1 for current best practices addressing cloud computing, mobile devices, supply chain risks, and modern threat techniques. However, v6.0 remains historically important as it established control prioritization based on adversary tactics, laying groundwork for subsequent versions' attack-centric approach.

The 20 Critical Security Controls (v6.0)

Version 6.0 organized 20 controls into Quick Win controls (easily implementable with high impact) and additional prioritized controls. The framework emphasized implementation over documentation, with detailed sub-controls providing specific implementation guidance.

Quick Win Controls (1-5)

CSC 1 - Inventory of Authorized and Unauthorized Devices: Actively manage hardware assets to ensure only authorized devices can access networks. Organizations cannot defend what they don't know exists. Automated asset discovery tools should continuously identify new devices connecting to networks.

CSC 2 - Inventory of Authorized and Unauthorized Software: Maintain inventories of approved software and prevent execution of unauthorized applications. Application whitelisting prevents malware execution even when perimeter defenses fail. Focus on identifying and removing unauthorized software that introduces vulnerabilities.

CSC 3 - Secure Configurations for Hardware and Software: Establish, implement, and actively manage security configurations for laptops, servers, workstations, and network devices. Default configurations rarely provide adequate security—organizations must harden systems according to vendor and industry best practices like CIS Benchmarks.

CSC 4 - Continuous Vulnerability Assessment and Remediation: Continuously acquire, assess, and take action on vulnerability information to close windows of opportunity for attackers. Version 6.0 emphasized automation and continuous assessment over periodic scanning, recognizing that new vulnerabilities emerge daily.

CSC 5 - Malware Defenses: Control installation, spread, and execution of malicious code at multiple points across the enterprise. Deploy anti-malware solutions on all systems with automatic signature updates, but also implement application whitelisting and network-level malware blocking for defense-in-depth.

Additional High-Priority Controls (6-20)

Controls 6-20 addressed application software security, wireless access control, data recovery capabilities, security skills assessment, secure network engineering, boundary defense, data protection, controlled access based on need to know, controlled use of administrative privileges, secure network engineering for servers/workstations/network devices, incident response and management, penetration tests and red team exercises, and security awareness and training programs.

Version 6.0 vs. Modern Versions

Version 6.0 predated widespread cloud adoption, did not adequately address mobile device security, lacked guidance on supply chain risk management, and organized controls differently than modern versions' implementation group approach. Current versions (v8.x) provide implementation groups (IG1, IG2, IG3) that scale recommendations based on organization size and sophistication—a capability v6.0 lacked. Modern versions also align more explicitly with MITRE ATT&CK framework, providing clearer connections between controls and specific adversary tactics.

Organizations using v6.0 should recognize significant gaps in cloud security, containerization, DevSecOps practices, zero trust architecture principles, and operational technology/industrial control system security. Version 8.1 addresses these modern environments comprehensively while maintaining the practical, actionable approach established in v6.0.

Migration Path to Current Versions

Organizations should plan migrations from v6.0 to CIS Controls v8.1 rather than attempting interim updates through v7.x versions. The Center for Internet Security provides mapping documents showing relationships between v6.0's 20 controls and v8.1's 18 controls, though many v6.0 controls split or merged in later versions requiring careful analysis.

Conduct Comprehensive Gap Analysis: Compare current v6.0 implementations against v8.1 requirements using CIS-provided mapping tools. Many v6.0 control implementations satisfy portions of v8.1 requirements, but significant gaps will exist in cloud security, mobile management, and supply chain domains.

Determine Appropriate Implementation Group: Version 8.1 introduces implementation groups enabling scaled implementations. Organizations should assess which IG (IG1 for small organizations, IG2 for mid-size, IG3 for large/mature) aligns with their risk profile, resources, and operational complexity. This scoping approach simplifies migration by focusing on relevant controls.

Prioritize Cloud and Supply Chain Enhancements: Version 6.0 lacked adequate cloud and supply chain guidance—areas receiving extensive attention in v8.1. Prioritize implementing v8.1 safeguards addressing cloud asset management, cloud service configurations, supplier assessment, and software/service supply chain management. These domains represent critical gaps in v6.0.

Phase Implementation Over 12-18 Months: Organizations with mature v6.0 implementations can typically migrate to v8.1 within 12-18 months through phased approaches. Begin with gap remediation for foundational controls (asset management, access control, data protection), then address advanced controls (application security, incident response), and finally implement specialized controls (penetration testing, security awareness).

Frequently Asked Questions

Should organizations implement CIS Controls v6.0 today?

No, organizations should implement CIS Controls v8.1 rather than v6.0. Version 6.0 is outdated, lacking guidance for cloud computing, mobile devices, operational technology, containerization, and modern threat techniques including supply chain attacks and ransomware-as-a-service. Current versions provide better alignment with contemporary technology environments and threat landscapes.

What are the major differences between v6.0 and v8.1?

Version 8.1 consolidates 20 v6.0 controls into 18 reorganized controls with clearer logical flow, introduces implementation groups (IG1, IG2, IG3) enabling scaled implementations, adds comprehensive cloud and mobile security guidance, includes supply chain risk management controls, provides enhanced operational technology/ICS guidance, aligns explicitly with MITRE ATT&CK framework, and offers more granular safeguards with measurable outcomes.

Can organizations claim compliance with v6.0?

While organizations can claim implementation of specific legacy versions, doing so signals outdated security practices. Cyber insurance providers, regulators, customers, and auditors increasingly expect implementation of current CIS Controls versions (v8.x). Organizations should avoid prominently advertising v6.0 compliance as it may create negative impressions about security program currency. Instead, transition to v8.1 and demonstrate implementation of current best practices.

How long does migration from v6.0 to v8.1 take?

Organizations with comprehensive v6.0 implementations typically require 12-18 months to migrate to v8.1, depending on organizational complexity and resources. Primary effort involves implementing new controls for cloud security, mobile devices, supply chain risk management, and enhanced logging/monitoring capabilities absent from v6.0. Phased approaches enable progressive migration while maintaining existing control effectiveness.

Where can I find v6.0 documentation?

The Center for Internet Security archives historical versions including v6.0 on their website for reference purposes. However, CIS strongly encourages organizations to reference and implement current versions (v8.1) rather than legacy documentation. Version 6.0 documentation serves primarily as historical reference for understanding control evolution rather than as current implementation guidance.