Security Frameworks

CIS Controls: What They Are & Why They Matter

The CIS Controls are a prioritised set of safeguards, maintained by the Center for Internet Security, that help organisations focus first on the actions that block the most common attacks.

In this explainer

  • Understand what the CIS Controls are and who maintains them
  • Learn how the controls are prioritised and grouped
  • Understand the implementation groups concept
  • See why a prioritised list helps in vendor assessment
  • Know what to ask a vendor and how Merion approaches it

7 min

What it is

The CIS Controls are a set of prioritised, practical safeguards maintained by the Center for Internet Security, a not-for-profit organisation. They began as a community effort to answer a simple question: of all the things an organisation could do, which actions block the most common attacks first? The result is an ordered list designed to guide effort, not overwhelm it.

The controls are intentionally hands-on. They describe concrete safeguards, grouped into a manageable number of high-level controls, and they are updated as the threat landscape shifts. They are often used alongside broader frameworks as the practical layer that says what to actually do.

Key principles

Two ideas define the CIS Controls. The first is prioritisation: the controls are ordered so that an organisation can start with the safeguards that deliver the most protection per unit of effort. The second is implementation groups, which tailor the controls to an organisation's size and resources.

  • Know what you have — inventory of hardware and software so nothing is unmanaged.
  • Protect data and accounts — data protection, access control and account management.
  • Configure and maintain securely — secure configuration, continuous vulnerability management and audit logging.
  • Be ready to respond — malware defences, recovery and incident response.

The implementation groups (commonly IG1 through IG3) let a smaller organisation begin with essential cyber hygiene and add more advanced safeguards as it grows, so the same control set scales with the organisation.

Why it matters for debt recovery

For a provider handling debtor data, the CIS Controls offer a credible answer to the practical question of what good day-to-day security looks like. Because the list is prioritised, it discourages security theatre and encourages effort where it counts: knowing what assets exist, controlling access, managing vulnerabilities and being ready to respond.

The implementation groups also make the controls a fair benchmark across providers of different sizes. A smaller specialist provider can demonstrate solid essential hygiene without being judged against expectations meant for a large enterprise, which helps a risk team form a realistic view.

What to ask a provider

Useful questions include:

  • Do you use the CIS Controls, and which implementation group reflects your environment?
  • How do you maintain inventories of hardware, software and data?
  • How do you manage access, account lifecycle and audit logging?
  • How do you handle continuous vulnerability management and incident response?

A provider that can describe how it maps its work to the controls, and which safeguards it has prioritised, generally has a clearer picture of its own posture than one that simply asserts good security. Our security overview describes the kinds of safeguards we focus on.

How Merion approaches it

Merion follows good practice consistent with the CIS Controls: we prioritise foundational safeguards such as asset inventory, access control, secure configuration, vulnerability management and incident readiness.

This is general information and not a claim of a particular implementation-group rating or independent assessment for Merion. Practices evolve, so we recommend you verify a provider's current safeguards and any attestations directly during due diligence.

Key takeaways

  • The CIS Controls are a prioritised list of practical safeguards from the Center for Internet Security
  • They are ordered so organisations tackle the highest-impact actions first
  • Implementation groups scale the controls to an organisation's size and resources
  • Ask which controls and implementation group a provider uses, then verify directly

Frequently asked questions

How are the CIS Controls different from a framework like NIST CSF?

The NIST CSF describes outcomes across high-level functions, while the CIS Controls give a prioritised list of concrete safeguards. Many organisations use the framework to organise their programme and the CIS Controls to decide what to do in practice.

What are implementation groups?

They tailor the controls to an organisation's size and resources, commonly from IG1 for essential cyber hygiene through to more advanced groups, so the same control set scales as an organisation matures.

Are the CIS Controls free to use?

The controls are published by a not-for-profit and are widely available for organisations to adopt. Their value comes from how thoroughly they are implemented, which is what you should ask a provider about.

Built on trust

Security and compliance you can verify

Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.