The CIS Critical Security Controls for Effective Cyber Defense
The CIS Critical Security Controls are a recommended set of actions for cyber defense that provide specific and actionable ways to stop today's most pervasive and dangerous attacks. A principal benefit of the Controls is that they prioritize and focus a smaller number of actions with high pay-off results. The Controls are effective because they are derived from the most common attack patterns highlighted in the leading threat reports and vetted across a very broad community of government and industry practitioners. They were created by the people who know how attacks work - NSA Red and Blue teams, the US Department of Energy nuclear energy labs, law enforcement organizations and some of the nation's top forensics and incident response organizations - to answer the question, "what do we need to do to stop known attacks." That group of experts reached consensus and today we have the most current Controls. The key to the continued value is that the Controls are updated based on new attacks that are identified and analyzed by groups from Verizon to Symantec so the Controls can stop or mitigate those attacks.
The Controls take the best-in-class threat data and transform it into actionable guidance to improve individual and collective security in cyberspace. Too often in cybersecurity, it seems the "bad guys" are better organized and collaborate more closely than the "good guys." The Controls provide a means to turn that around.
SANS Supports the CIS Critical Security Controls with Training, Certifications, and Research
To support information security practitioners and managers implement the CIS Critical Security Controls, SANS provide a number of resources and information security courses.
Information Security Courses
- SEC440: Critical Security Controls: Planning, Implementing and Auditing
- SEC511: Continuous Monitoring and Security Operations
- SEC566: Implementing and Auditing the Critical Security Controls - In-Depth
Information Security Resources
- NewsBites: Bi-weekly email of top news stories with commentary from SANS Editors. View recent editions & Subscribe
- Whitepapers: Research from SANS instructors and masters students. Download the latest papers related to the Critical Controls
- Webcasts: Topical content presented by SANS Instructors, vendors, and leaders in infosec security. View upcoming webcasts
CIS Critical Security Controls - Version 6.0
To learn more about the CIS Critical Security Controls and download a free detailed version please visit: http://www.cisecurity.org/critical-controls/
The SANS "What Works" program highlights success stories in cybersecurity - real examples of how real security teams have made measurable improvements in the effectiveness and efficiency of their security controls. While most of the press coverage focuses on breaches and other security failures, there are thousands of cybersecurity leaders quietly working hard and make advances against threats while enabling business and mission needs.
SANS expert John Pescatore interviews the end user and decision maker and produces a Q&A formatted case study and a live webcast that allows security practitioners to take advantage of lessons learned and accelerate their own cybersecurity improvements.
Check out recent SANS WhatWorks case studies: