Standards
CIS Controls v8.1CIS

CIS Critical Security Controls

Eighteen priority-ordered controls, expressed in three implementation groups by organisation size and maturity. Control 11 — data recovery — is the one most directly tied to IT continuity.

Official text

Who it applies to

  • Technical teams
  • SMEs looking for a pragmatic path
  • Backup owners

Structuring points

  • Control 11 mandates isolated and tested backups — the 3-2-1-1-0 rule follows from it
  • Implementation groups IG1 to IG3 grade the effort without losing structure
  • Maps easily to ISO/IEC 27002 and the NIST CSF

Operational cyber hygiene, from endpoint to cloud.