← Back to Library
CIS Controls

CIS Controls v7.0

Full Name:
Center for Internet Security (CIS) Controls
Acronym:
CIS Controls
Type:
Industry Standard
Organization:
Center for Internet Security
Version:
7
Year Published:
2018
Popularity:
Low

Overview of CIS Controls v7.0

CIS Controls Version 7.0, published in 2018, represented a major revision of the Critical Security Controls framework, maintaining 20 controls while completely reorganizing their structure and expanding sub-controls to 171 specific safeguards. This version introduced explicit mapping to common attack patterns and techniques, aligning controls with how adversaries actually compromise systems. Version 7.0 emphasized practical, defensive measures proven effective against real-world attacks rather than theoretical security concepts.

As a legacy version now superseded by v7.1 (2019), v8.0 (2021), and v8.1 (2024), version 7.0 should not be used for new implementations. Organizations currently using v7.0 should plan transitions to v8.1 for current best practices addressing cloud computing, supply chain risks, and modern threat techniques. Version 7.0 remains significant historically as it established the attack-focused control organization that subsequent versions refined.

The 20 Controls and Sub-Control Structure

Version 7.0 organized 20 controls with 171 sub-controls providing specific implementation guidance. Unlike previous versions' Quick Win grouping, v7.0 numbered controls 1-20 in priority order, with early controls delivering highest impact against common attack techniques.

Basic CIS Controls (1-6)

CIS Control 1 - Inventory and Control of Hardware Assets: Actively manage all hardware devices to ensure only authorized devices can access networks. Organizations cannot defend assets they don't know exist. Sub-controls addressed automated discovery, unauthorized device detection, and hardware asset management systems.

CIS Control 2 - Inventory and Control of Software Assets: Maintain authorized software inventories and prevent execution of unauthorized applications. Application whitelisting prevents malware execution. Sub-controls covered software inventory tools, unauthorized software detection and removal, and software asset management.

CIS Control 3 - Continuous Vulnerability Management: Continuously acquire, assess, and remediate vulnerabilities. Version 7.0 emphasized automation and speed, requiring vulnerability scanning and remediation processes that close attack windows before exploitation.

CIS Control 4 - Controlled Use of Administrative Privileges: Control and monitor administrative privileges to prevent abuse by attackers or insiders. Sub-controls addressed privileged account inventories, just-in-time access, privileged access management tools, and administrative activity monitoring.

CIS Control 5 - Secure Configuration for Hardware and Software: Establish, implement, and maintain secure configurations for hardware and software. Version 7.0 referenced CIS Benchmarks extensively, providing prescriptive hardening guidance for common platforms.

CIS Control 6 - Maintenance, Monitoring, and Analysis of Audit Logs: Collect, manage, and analyze audit logs to detect anomalous activity. Comprehensive logging enables incident detection and forensic analysis. Sub-controls specified log collection, centralization, retention, and automated analysis requirements.

Foundational and Organizational Controls (7-20)

Controls 7-20 addressed email and web browser protections, malware defenses, network ports and protocols limitations, data recovery capabilities, secure network engineering, boundary defense, data protection, controlled access, wireless access control, account monitoring, security skills assessment, application software security, incident response, and penetration testing.

Version 7.0 Innovations and Improvements

Version 7.0 introduced significant improvements over v6.0 including reorganized control structure prioritizing by defensive value, 171 specific sub-controls providing detailed implementation guidance, explicit mapping to common attack techniques, alignment with MITRE ATT&CK tactics, improved measurement and metrics guidance, and enhanced cloud computing considerations (though still limited compared to v8.x).

The version also introduced Implementation Groups concept in initial form, though not as clearly defined as v8.0's IG1/IG2/IG3 structure. Version 7.0 suggested organizations implement controls progressively based on resources and maturity, laying groundwork for the formal implementation group approach in later versions.

Limitations and Gaps

Despite improvements, v7.0 had limitations including insufficient cloud security guidance for modern hybrid/multi-cloud environments, limited mobile device management coverage, inadequate supply chain risk management guidance, minimal DevSecOps and CI/CD pipeline security, and lack of explicit operational technology/ICS controls. These gaps drove development of v8.0 and v8.1, which address modern technology environments comprehensively.

Migration Path to Current Versions

Organizations should migrate from v7.0 to CIS Controls v8.1 rather than interim versions. While v7.0 and v8.1 share similar foundations, v8.1 consolidates 20 controls into 18 with reorganized structure, introduces formal implementation groups (IG1, IG2, IG3), adds comprehensive cloud and supply chain safeguards, provides enhanced operational technology guidance, and aligns explicitly with updated MITRE ATT&CK framework.

Migration typically requires 12-18 months for organizations with mature v7.0 implementations. Primary effort involves implementing new safeguards for cloud asset management, cloud service configurations, supply chain security, and enhanced logging/monitoring. Many v7.0 sub-controls map directly to v8.1 safeguards, enabling organizations to leverage existing implementations while filling gaps in modern domains.

Frequently Asked Questions

Should organizations use CIS Controls v7.0 today?

No, organizations should implement CIS Controls v8.1 rather than v7.0. Version 7.0 is outdated, lacking adequate guidance for cloud computing, containerization, DevSecOps, supply chain risks, and modern threat techniques. Current versions provide better alignment with contemporary technology environments and regulatory expectations. Organizations using v7.0 should plan migrations to v8.1 within 12-18 months.

What are the main differences between v7.0 and v8.1?

Version 8.1 consolidates 20 v7.0 controls into 18 reorganized controls with clearer focus on security outcomes, introduces formal implementation groups (IG1, IG2, IG3) enabling scaled implementations based on organization size/maturity, adds comprehensive cloud and mobile security safeguards, includes supply chain risk management controls, provides enhanced operational technology guidance, aligns with updated MITRE ATT&CK framework, and offers more prescriptive safeguards with measurable success criteria.

Can organizations claim v7.0 compliance?

While technically possible to claim v7.0 implementation, doing so signals outdated security practices. Cyber insurance providers increasingly require v8.x implementation, regulators reference current versions in guidance, customers expect current frameworks in vendor assessments, and auditors evaluate against current standards. Organizations should avoid prominently advertising v7.0 compliance and instead transition to v8.1 to demonstrate current security maturity.

How does v7.0 relate to v7.1?

Version 7.1 (2019) was a minor update to v7.0, refining sub-control language, clarifying implementation guidance, improving measurement criteria, and enhancing framework mappings to other standards. Version 7.1 maintained v7.0's 20 control structure and did not introduce new controls. Organizations using v7.0 could adopt v7.1 with minimal effort, though both are now superseded by v8.x versions requiring more substantial updates.

Where can I find v7.0 documentation and implementation guides?

The Center for Internet Security maintains historical versions including v7.0 in their archives for reference purposes. However, CIS strongly recommends implementing current versions rather than legacy frameworks. Version 7.0 documentation serves primarily as historical reference for organizations transitioning to v8.1. CIS provides migration guides and mapping documents showing relationships between v7.0 sub-controls and v8.1 safeguards to facilitate transitions.