CIS Controls v8.0
Overview of CIS Controls v8.0
CIS Controls Version 8.0, published in 2021, represented the most significant update to the framework since its inception, fundamentally restructuring the controls from 20 to 18, introducing formal implementation groups (IG1, IG2, IG3), and providing comprehensive guidance for cloud computing, mobile devices, and supply chain security. This version responded to dramatic changes in technology environments and threat landscapes between 2018-2021, including widespread cloud migration, remote work expansion, supply chain compromises like SolarWinds, and ransomware proliferation.
Version 8.0 introduced a revolutionary approach enabling organizations to select appropriate control subsets based on their size, sophistication, and risk profile through implementation groups. IG1 targets small organizations with limited cybersecurity resources (56 safeguards), IG2 addresses mid-size organizations with moderate risk exposure (74 additional safeguards), and IG3 covers large organizations or those facing sophisticated threats (23 additional safeguards for 153 total). This scaled approach made CIS Controls accessible to organizations previously overwhelmed by comprehensive coverage requirements.
Note: Version 8.0 has been superseded by v8.1 (2024), which refines safeguards and provides updated guidance. Organizations implementing CIS Controls should adopt v8.1 rather than v8.0 for the most current practices, though the fundamental structure and implementation groups remain consistent across v8.x versions.
The 18 CIS Controls and Implementation Groups
Version 8.0 consolidates and reorganizes controls with clearer focus on security outcomes, grouping related capabilities and eliminating overlaps present in v7.x versions.
Implementation Group 1 (IG1) - Essential Cyber Hygiene
IG1 contains 56 safeguards forming the foundation for all organizations, regardless of size or sector. These safeguards address basic cyber hygiene including asset inventory, access control, data protection, malware defense, and backup recovery. Small businesses with limited IT resources should implement IG1 as their baseline cybersecurity program. IG1 safeguards prevent the vast majority of opportunistic cyberattacks through fundamental security practices.
Key IG1 controls include hardware and software asset management, data protection, secure configuration, account management, access control management, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, data recovery, network infrastructure management, network monitoring, security awareness training, and incident response management.
Implementation Group 2 (IG2) - Enhanced Security for Mid-Size Organizations
IG2 includes all 56 IG1 safeguards plus 74 additional safeguards totaling 130, addressing more sophisticated threats and compliance requirements typical of mid-size organizations. IG2 safeguards emphasize automation, centralized management, enhanced monitoring and detection, and security testing. Organizations handling sensitive customer data, operating in regulated industries, or facing targeted attacks should implement IG2 minimum.
IG2 additions include automated asset discovery and inventory, enhanced vulnerability scanning with authenticated assessments, penetration testing, security operations center capabilities, advanced email security (SPF, DKIM, DMARC), enhanced network monitoring and intrusion detection, service provider management, and comprehensive security awareness training programs.
Implementation Group 3 (IG3) - Advanced Security for Large Organizations
IG3 includes all 130 IG1/IG2 safeguards plus 23 additional safeguards totaling 153, addressing sophisticated adversaries and protecting high-value assets. IG3 safeguards require substantial resources and mature security operations, including dedicated security engineering teams, 24/7 security operations centers, threat intelligence programs, and advanced testing capabilities. Organizations in critical infrastructure, defense, financial services, or facing nation-state threats should implement IG3.
IG3 additions include automated hardware and software asset management with detailed attributes, dedicated secure configurations for specialized systems, advanced penetration testing including purple team exercises, threat hunting, deception technologies, and comprehensive security architecture reviews.
Major Enhancements in Version 8.0
Version 8.0 introduced transformative changes addressing modern technology and threat environments.
Cloud Computing Guidance
Version 8.0 comprehensively addresses cloud security through dedicated safeguards for cloud asset inventory, secure cloud service configurations, cloud access monitoring, and cloud service provider management. The framework recognizes infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) deployment models, providing guidance for each. Organizations implementing cloud-first strategies receive practical direction previously absent in v7.x versions.
Supply Chain Risk Management
Supply chain compromises including SolarWinds, Kaseya, and Log4Shell prompted new supply chain security controls. Version 8.0 requires organizations to maintain software and service provider inventories, assess supplier security practices, establish vendor security requirements in contracts, and monitor for supply chain risks. These controls address both third-party software suppliers and managed service providers, covering the extended attack surface beyond organizational boundaries.
MITRE ATT&CK Alignment
Version 8.0 explicitly maps safeguards to MITRE ATT&CK tactics and techniques, providing clearer connections between controls and specific adversary behaviors. This alignment helps organizations understand which controls defend against which attack techniques, enabling threat-informed prioritization. The ATT&CK mapping also facilitates purple team exercises and security validation through realistic adversary simulation.
Implementation Strategies
Organizations should begin CIS Controls v8.0 implementation by determining their appropriate implementation group, then systematically deploying safeguards for that group before advancing to higher groups.
Determine Implementation Group: Assess organization size, risk profile, regulatory requirements, and resources to select IG1, IG2, or IG3. Small organizations (<100 employees) with standard risk typically target IG1. Mid-size organizations (100-1000 employees) or those in regulated industries target IG2. Large organizations (>1000 employees) or critical infrastructure operators target IG3. Organizations can achieve partial IG2 or IG3 implementation, focusing on high-priority safeguards for their threat environment.
Leverage Cloud Security Features: Cloud providers offer native security capabilities satisfying many CIS Controls safeguards. Organizations should maximize cloud-native security features including identity and access management, encryption, logging and monitoring, and security configuration management before implementing third-party tools. Cloud-native approaches often provide better integration, lower costs, and automatic updates compared to custom implementations.
Automate Asset Management: Version 8.0 emphasizes automated asset discovery and inventory for both hardware and software. Implement tools providing continuous asset discovery, configuration management, and drift detection. Automation ensures inventories remain current as environments change rather than becoming outdated between periodic manual reviews.
Frequently Asked Questions
Should organizations implement v8.0 or v8.1?
Organizations should implement CIS Controls v8.1 (2024) rather than v8.0, as v8.1 refines safeguards, improves measurement criteria, and provides updated threat intelligence. However, the fundamental structure and implementation groups remain consistent, so organizations currently implementing v8.0 can transition to v8.1 with minimal effort. New implementations should start with v8.1 directly to avoid rework.
Which implementation group should my organization target?
IG1 suits small organizations with <100 employees, limited IT resources, and standard risk profiles. IG2 suits mid-size organizations (100-1000 employees), regulated industries, or those handling sensitive customer data. IG3 suits large enterprises (>1000 employees), critical infrastructure, organizations with sophisticated threats, or those handling classified/highly sensitive information. Conduct risk assessments and gap analyses to determine appropriate targets—organizations can implement partial IG2 or IG3 for high-value systems while maintaining IG1 baseline enterprise-wide.
How long does v8.0 implementation take?
IG1 implementation typically requires 6-12 months for organizations starting from basic security postures. IG2 requires 12-24 months depending on starting maturity and organizational complexity. IG3 often requires 24-36 months for comprehensive implementation including building security operations capabilities, implementing advanced tools, and developing necessary expertise. Organizations with mature v7.x implementations can migrate to v8.0 faster, as many existing controls satisfy v8.0 requirements.
Can organizations skip IG1 and implement IG2 directly?
While IG2 includes all IG1 safeguards, organizations should not skip IG1 implementation. IG1 establishes foundational capabilities that IG2 builds upon—attempting IG2 without solid IG1 foundations creates unsustainable implementations. Organizations should systematically implement IG1, validate effectiveness through testing and metrics, then advance to IG2. Progressive implementation ensures mature, operational security programs rather than checkbox compliance.
Does v8.0 address operational technology and ICS security?
Version 8.0 improved operational technology (OT) and industrial control system (ICS) guidance compared to v7.x, providing specific safeguards and implementation notes for OT environments. However, organizations with substantial OT/ICS infrastructure should supplement CIS Controls with specialized frameworks like IEC 62443 or NIST SP 800-82 that provide more detailed OT security guidance. CIS Controls provides excellent IT security foundations that organizations extend to OT environments using sector-specific frameworks.