Eighteen controls, in a deliberate order. The first two are an inventory, because everything after them depends on knowing what you have.
The CIS Critical Security Controls are a prescriptive, prioritised and simplified set of best practices. The prioritisation is the whole point: the order is not alphabetical or thematic, it reflects what protects most for least effort. Version 8.1 adds a governance function and updated alignment to other frameworks.

- 18 controlsCIS Controls version 8.1
- PrioritisedThe order is the guidance
- GovernanceThe security function added in v8.1
- MeasurableAssessed, scored, and re-assessed
Seven reasons the CIS Controls are the right starting framework for most organisations.
It is prioritised, and the order is the advice
Control 1 is inventory and control of enterprise assets. Control 2 is inventory and control of software assets. They are first because every subsequent control depends on knowing what exists. An organisation that starts at control 10, malware defences, because it feels urgent, is protecting an estate it cannot enumerate. The sequence is the most valuable thing the framework provides.
It is prescriptive, which is rarer than it sounds
Many frameworks tell you to have appropriate controls and leave the definition to you, which produces documents that satisfy an auditor and change nothing. The CIS Controls describe specific things to do. That makes an assessment produce a task list rather than a maturity narrative, and a task list is what actually gets funded and finished.
Version 8.1 adds a governance function
CIS describes v8.1 as introducing a governance security function alongside updated alignment to evolving industry standards and frameworks. That reflects the same direction other frameworks have moved in, and it matters because it makes explicit what previous versions left implicit: somebody has to own each control and answer for it.
It maps to the frameworks you may already be measured against
Updated alignment to evolving industry standards and frameworks is one of the stated changes in v8.1. For UAE organisations that are simultaneously being asked about NIST, ISO, a regulator questionnaire and a customer security review, doing the work once against the CIS Controls and mapping outwards is considerably cheaper than answering each independently.
It covers the whole estate, not only the technology
Control 14 is security awareness and skills training. Control 15 is service provider management. Control 17 is incident response management. Those sit alongside the technical controls deliberately, because an organisation with excellent technology, untrained people and unmanaged suppliers has a well-defended perimeter around an open door.
It produces a score you can move
Because the controls are specific, an assessment produces a position per control rather than an overall impression. That is what allows the second assessment, six or twelve months later, to demonstrate movement. A framework that only produces a narrative cannot show improvement, which makes the next round of funding much harder to justify.
It is a starting point, not a certification
The CIS Controls are not certifiable in the way ISO 27001 is, and that is a feature rather than a gap. An organisation can adopt them immediately, at whatever depth is realistic, without an audit body, a scope statement or a certification budget. Where certification is required later, the work done here transfers directly.
Controls 1 and 2 are an inventory. Almost nobody has one, and everything else depends on it.
The order of the eighteen controls is not arbitrary. The first two exist because the rest are unmeasurable without them.
- Control 1 is inventory and control of enterprise assets. Control 2 is inventory and control of software assets. Together they answer what you have and what is running on it.
- Every control after them is qualified by that answer. Vulnerability management covers the assets you know about. Malware defences protect the endpoints you know about. Audit log management collects from the systems you know about. Coverage percentages mean nothing without a denominator.
- In practice this is the least popular part of any assessment and the most valuable. It is unglamorous, it takes real effort, and it consistently produces the finding that changes the rest of the programme, which is usually that the estate is ten to thirty percent larger than the register says.
- That is also why external attack surface discovery and software inventory tooling belong in the first phase rather than the last. Building the inventory by hand from what people remember reproduces exactly the gap the control exists to close.
Four things that make a controls assessment worth more than the report.
We assess on evidence, not on a questionnaire
The answer to whether a control is implemented is frequently different from the answer given in a workshop, and it is not because anybody is being dishonest. It is because the person answering describes the intent and the evidence describes the reality. Asking for the artefact rather than the assurance is what makes the finding useful.
We keep the published order unless there is a reason not to
The prioritisation is the framework main contribution, and it is easy to argue away in favour of work that feels more interesting. Departing from the sequence is legitimate when there is a regulatory obligation, a customer requirement or a recent incident driving it. It is not legitimate because control 1 is tedious.
We name an owner per control, because v8.1 asks us to
Version 8.1 introduces a governance security function, and the practical expression of that is a named person accountable for each control rather than a collective assumption that IT has it covered. Controls with no owner are the ones that regress first, and the regression is invisible until the next assessment.
We book the re-assessment before delivering the first one
The second assessment is what converts a report into a programme. Comparable format, same eighteen controls, twelve months later, showing movement. Booking it in advance changes the behaviour of everybody involved, because remediation stops being optional the moment it will be measured again on a known date.
Four phases, and the assessment is the smallest part.
- 01Weeks 1 to 3
Assess against all eighteen
Evidence-based rather than questionnaire-based wherever possible, because the answer to whether a control is implemented is frequently different from the answer somebody gives in a workshop. Controls 1 and 2 get disproportionate attention, since the accuracy of everything else depends on the inventory being real.
- A documented position on each of the eighteen controls
- Evidence recorded against each finding, not assertion
- Asset and software inventory gap quantified
- Findings mapped to the frameworks you are also measured against
- 02Weeks 4 to 6
Prioritise using the published order, then adjust for you
The CIS order is the default prioritisation and it is a good one. Adjusting it means having a reason: a regulatory obligation, a customer requirement, a recent incident, or a control that is nearly complete and cheap to finish. Everything else follows the published sequence, because arguing with a prioritised framework usually means preferring the comfortable work.
- A remediation plan ordered by control number and adjusted for context
- Owner and target date against every item
- Quick wins separated from programme-level work
- Effort and dependency mapped so the plan is deliverable
- 03Months 2 to 9
Remediate, starting with the inventory
Controls 1 and 2 first, because every measurement after them depends on the denominator being right. Then through the sequence, with the governance question asked at each control: who owns this, and what happens when they leave. Version 8.1 makes governance an explicit function rather than an assumption.
- A real asset and software inventory, maintained rather than snapshotted
- Controls implemented in sequence with evidence retained
- An owner named against every control
- Progress reported in the same format the assessment used
- 04Month 12
Re-assess and show the movement
The same assessment, run again, in the same format. That is the artefact that justifies the next year of investment, because it converts security spending from a cost that produced a report into a cost that produced measurable movement across eighteen named controls.
- A second assessment directly comparable to the first
- Movement quantified per control
- The remaining gap re-prioritised for the following year
- A board-readable summary, because this framework produces one
Six UAE situations where the CIS Controls are the right framework to start with.
A business with no security framework and a growing list of requests
Customers asking for security questionnaires, an insurer asking about controls, a board asking whether the organisation is safe. Eighteen prescriptive controls in a prioritised order turns that into a plan, and because v8.1 aligns to other frameworks, the answers largely transfer to whatever questionnaire arrives next.
A regulated firm that needs technical substance behind a policy set
Regulatory frameworks in the UAE frequently require appropriate controls without prescribing them. The CIS Controls provide the prescription. Mapping the eighteen to the regulatory obligation gives you both a defensible technical baseline and a clear line from each control to the requirement it satisfies.
An organisation that has just had an incident
The instinct after an incident is to fix the thing that happened, which is necessary and insufficient. A full assessment against the eighteen answers the question the board will actually ask, which is what else looks like that. Controls 1, 2, 5, 6 and 8 usually explain how the incident progressed as far as it did.
An operator with an estate nobody has fully enumerated
Plants, yards and remote facilities accumulate technology locally. Controls 1 and 2 are the entire value of the engagement for this profile, because the gap between what the register says and what exists is where the risk lives. Everything downstream becomes measurable once that gap is closed.
A healthcare or education organisation with limited security resource
A prioritised framework matters most where there is least capacity. Knowing that controls 1 through 6 deserve the available effort, and that control 18 can wait, is more valuable to a small team than a comprehensive framework that gives equal weight to everything and is therefore never finished.
A group standardising security across several entities
The same eighteen controls, assessed the same way, across each entity, produces a comparable picture that a group function can act on. That is difficult with a narrative framework and straightforward with a prescriptive one, which is why multi-entity groups tend to end up here even when an individual entity would have chosen otherwise.
How UAE organisations decide what security work to do.
| Feature | Assessed against a prioritised framework | Work driven by incidents and requests | No framework at all |
|---|---|---|---|
Known position on every control | Yes | No | No |
Work prioritised by impact | Yes | By urgency | No |
Asset and software inventory real | Yes | Partly | No |
Owner named per control | Yes | No | No |
Progress measurable year on year | Yes | No | No |
Maps to other frameworks asked about | Yes | No | No |
Non-technical controls included | Yes | Rarely | No |
Answer for a customer security review | Evidence | Assertions | None |
Budget case for next year | Straightforward | Difficult | Very difficult |
Cost to start | Assessment | None | None |
CIS Controls version 8.1, in published order.
| Control | Name | Where the gap usually is | |
|---|---|---|---|
| 1 | Inventory and Control of Enterprise Assets | The register is incomplete, and nobody knows by how much | |
| 2 | Inventory and Control of Software Assets | Software installed by users, and applications nobody owns | |
| 3 | Data Protection | No classification, so no way to prioritise anything | |
| 4 | Secure Configuration of Enterprise Assets and Software | A baseline was set once and has drifted since | |
| 5 | Account Management | Leavers, shared accounts and service accounts nobody owns | |
| 6 | Access Control Management | Access granted correctly and never taken back | |
| 7 | Continuous Vulnerability Management | Scanning happens, remediation does not | |
| 8 | Audit Log Management | Logs collected, retention undefined, nobody reviews them | |
| 9 | Email and Web Browser Protections | Licensed features that were never configured | |
| 10 | Malware Defenses | Servers running something different from endpoints | |
| 11 | Data Recovery | Backups exist, restores have never been tested | |
| 12 | Network Infrastructure Management | Firewall rules added, never removed | |
| 13 | Network Monitoring and Defense | Alerts generated, nobody works the queue | |
| 14 | Security Awareness and Skills Training | An annual module nobody remembers taking | |
| 15 | Service Provider Management | No inventory of who has access to what | |
| 16 | Application Software Security | Custom applications with no security testing | |
| 17 | Incident Response Management | A plan that has never been exercised | |
| 18 | Penetration Testing | Tested once, findings not fully remediated |
Five steps, and the second assessment is part of the first engagement.
- 1
Agree scope and gather evidence
Which entities, which environments, whether third-party managed systems and custom software are included. Then evidence collection rather than a questionnaire, because the artefact and the assurance frequently differ and only one of them survives an audit.
- 2
Assess all eighteen controls
A documented position on each, with the evidence recorded against it. Controls 1 and 2 get disproportionate attention because the accuracy of every coverage figure depends on the inventory being genuine rather than remembered.
- 3
Build the plan in the published order
The CIS sequence as the default prioritisation, adjusted where a regulatory obligation, customer requirement or recent incident gives a reason. Every item gets an owner and a target date, and quick wins are separated from programme-level work so the first three months show visible movement.
- 4
Remediate, with governance named
Starting with inventory, then through the sequence, with an owner named against each control per the governance function introduced in version 8.1. Evidence retained as work completes, in the format the re-assessment will use, so nothing has to be reconstructed later.
- 5
Re-assess and report the movement
The same assessment, same format, at the interval agreed at the start. Movement quantified per control, the remaining gap re-prioritised, and a summary that a board can read. That comparison is the single most useful security artefact most organisations can produce.
What organisations ask about the CIS Controls.
Fifteen questions that shape the engagement.
Scope
- Which entities are in scope?Groups often assess one and assume the rest.
- Are cloud and on-premises both included?The controls apply to both.
- Are third-party managed systems in scope?Control 15 covers service providers.
- Is custom software in scope?Control 16 covers application security.
- Are you also measured against another framework?v8.1 aligns to several.
Evidence
- Can you produce an asset inventory today?Control 1, and the usual first finding.
- Can you produce a software inventory?Control 2.
- Are configuration baselines documented?Control 4, and drift is the usual issue.
- Has a restore been tested this year?Control 11.
- Has the incident plan been exercised?Control 17.
Afterwards
- Who owns the remediation plan?A report without an owner is a document.
- Is there budget for the first phase?Inventory work is effort, not licences.
- Who owns each control long term?v8.1 makes governance explicit.
- When is the re-assessment booked?Before the first one is delivered.
- Who sees the results?This framework reports well upwards.
Ask whether anyone can produce a complete asset inventory today.
That is control 1, it is first for a reason, and the honest answer in most organisations is no. Knowing the size of that gap is the single most useful thing an assessment produces, and it takes days rather than weeks to establish.
Related Services
Explore more solutions that work great with this service
Gap Assessment
Distance to a target you actually have to meet
Security Policy Development
Policies you can actually comply with
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification
IT General Controls
What your external auditor tests, and the evidence they sample
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Cybersecurity Audit
Security assessment and compliance audit
Vulnerability Assessment
Continuous vulnerability scanning and remediation
Access Rights Review
Certification that removes access, not one that gets approved