This document introduces version 6.0 of the Center for Internet Security's Critical Security Controls (CIS CSCs) for effective cyber defense. It provides an overview of the 20 CIS CSCs, which are a prioritized set of actions that collectively form a defense-in-depth approach to security. The controls focus on systematically improving an organization's cyber defenses to mitigate known attack techniques. The document also includes appendices that discuss evolving attack models, aligning the controls with other frameworks like NIST, and considerations for privacy impact assessments.
Related topics: