The CIS Critical Security Controls are the most widely referenced prioritised action list in information security. Version 8.1's 18 controls and 153 safeguards are structured by Implementation Group so that organisations of any size can identify exactly what they need to do first. This guide maps the controls most directly enforced at the endpoint to Zecurit Endpoint Manager, giving IT and security teams an actionable compliance starting point.
The CIS Critical Security Controls, now in version 8.1, are maintained by the Center for Internet Security and are built differently from most compliance frameworks. Rather than beginning with risk assessment methodology or governance structure, they start with the most common attack patterns documented across real-world incidents and ask: what practical controls, implemented in this order, would have prevented or contained the most damage?
The result is a framework that security practitioners across government, enterprise, healthcare, and the SMB market reach for because it tells them what to do next, not just what to measure. The 2024 v8.1 revision refined safeguard language and clarified Implementation Group boundaries without restructuring the control set, making existing CIS programmes straightforward to maintain while giving new adopters the most precise guidance the framework has ever offered.
This guide maps CIS Controls v8.1's endpoint-relevant controls and safeguards to specific capabilities in Zecurit Endpoint Manager, so IT and security teams can move from the framework's language to operational, evidenced controls without rebuilding their toolkit.
A handful of terms shape how the CIS Controls are structured and applied in practice:
One of 18 high-level security domains, each addressing a category of risk. Controls are action-oriented: "Inventory and Control of Enterprise Assets", not "Asset Management Policy."
A specific, implementable action within a control. Each control contains multiple safeguards; these are the individual testable items organisations track for compliance. CIS Controls v8.1 contains 153 safeguards in total.
A tiered prioritisation system. IG1 covers essential cyber hygiene for all organisations. IG2 adds controls for organisations with moderate resources and risk. IG3 covers the full set for security-mature enterprises.
v8.1's term for any device, physical or virtual, that is part of an organisation's environment. The shift from "system" to "asset" reflects the breadth of modern environments including cloud, containers, and IoT.
Companion configuration guides produced by CIS for specific operating systems, applications, and cloud platforms. Benchmarks define the secure baseline that CIS Control 4 (Secure Configuration) references.
CIS Risk Assessment Method: a companion framework that helps organisations use the CIS Controls to conduct and document risk assessments, useful when aligning CIS with frameworks requiring formal risk treatment.
CIS Controls adoption spans virtually every sector, precisely because the Implementation Group structure allows organisations to begin with the safeguards most critical to their size and risk profile rather than attempting a full 153-safeguard programme at once:
Implementation Groups are the CIS Controls framework's most practically useful feature. Rather than presenting all 153 safeguards as equally urgent, IGs sequence them by organisational risk and resource profile, letting any organisation begin with a coherent, achievable programme.
The minimum set of controls every organisation should have in place. Designed for small teams with limited security expertise and budget. Addresses the most common, high-impact attack patterns. All IG1 safeguards are also required in IG2 and IG3.
For organisations with dedicated IT security staff managing multiple departments and handling more sensitive data. Adds detection, response, and more granular access controls on top of IG1's foundational hygiene.
For security-mature organisations with dedicated security teams and complex environments. Adds advanced logging, incident response, penetration testing, and supply chain security controls suited to high-value targets and regulated sectors.
The most substantive v8.1 changes affect safeguard language in Controls 1 through 4, the controls most directly associated with endpoint management. Several safeguard descriptions were sharpened to remove ambiguity about whether virtual assets, cloud-hosted workloads, and BYOD devices fall within scope; v8.1 confirms that they do, and that the same inventory, configuration, and vulnerability management expectations apply.
The v8.1 revision also clarified Implementation Group assignments for several safeguards that organisations had interpreted inconsistently in v8.0, particularly around automated patch management (CIS 7.3) and automated vulnerability scanning (CIS 7.5 and 7.6). These are now clearly IG1 requirements for automated patching and IG2 for authenticated scanning, resolving debate about how basic these expectations are meant to be. For most IT teams, this means the bar for what constitutes minimum viable vulnerability management has moved up rather than down.
The sections below translate each endpoint-relevant CIS Control and its key safeguards into the Zecurit Endpoint Manager capabilities that address them, with Implementation Group labels indicating the safeguards' priority tier.
Actively manage, track, and correct all enterprise assets connected to the infrastructure, including end-user devices, network devices, IoT, and cloud instances. Only assets inventoried can be secured, patched, or monitored. Unmanaged devices represent the attack surface organisations cannot see.
Key safeguards require maintaining an up-to-date asset inventory (1.1), addressing unauthorised assets (1.2), and using active discovery tools to find assets not in the inventory (1.4). Safeguard 1.5 (IG2) adds DHCP logging to aid discovery, while 1.3 ensures DHCP server log data is used to update asset records.
Asset Discovery continuously scans the environment to surface every managed and unmanaged device, populating the Hardware Inventory with real-time data on each asset, including device type, OS, hostname, IP, and last-seen timestamps. Hardware Change Alerts in the Monitoring and Alerts module flag any new or modified device the moment it appears, giving IT teams the active inventory management Control 1 demands rather than a quarterly spreadsheet exercise.
Actively manage all software on enterprise assets so that only authorised software is installed and can execute. Unauthorised and unmanaged software is one of the primary vectors for malware delivery and data exfiltration. Safeguard 2.1 requires maintaining an authorised software inventory; 2.3 requires addressing unauthorised software; 2.5 and 2.6 add application allow-listing for higher-risk environments.
Software Inventory discovers and tracks every installed application across all managed endpoints in real time, including version numbers and installation dates. Software Change Alerts immediately notify IT teams when any unauthorised application is installed on a managed device, supporting both the inventory requirement and the unauthorised software response safeguard without requiring a manual audit cycle.
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data. Safeguard 3.6 requires encryption of data on end-user devices. Safeguard 3.10 (IG1) requires that removable media be encrypted. Safeguard 3.11 (IG2) requires data classification and handling procedures. Safeguard 3.14 (IG2) adds logging for sensitive data access. These protections extend to data at rest on every managed endpoint.
BitLocker Management enforces full-disk encryption across every managed Windows endpoint from a central console, with TPM-only, TPM+PIN, and passphrase authentication modes, and automatic recovery key backup. BitLocker Compliance Reports surface any unencrypted device instantly. Device Control governs removable media connections with allow, block, or trusted-device-only policies, preventing unencrypted data movement through USB and external storage, supporting both 3.6 and 3.10 from a single platform.
Establish and maintain the secure configuration of enterprise assets and software. Safeguard 4.1 (IG1) requires establishing and maintaining a secure configuration process. Safeguard 4.2 (IG1) requires establishing and maintaining a secure configuration for end-user devices. Safeguard 4.5 (IG1) requires implementing and managing a firewall on end-user devices. Safeguard 4.8 (IG2) adds uninstallation or disabling of unnecessary services. Configuration drift between audit cycles is one of the most common causes of compliance failure and breach exposure.
Configuration Management enables IT teams to build named profiles that bundle firewall rules, Windows Update policies, power management settings, and security hardening parameters, then deploy and enforce them consistently across device groups. Hardware and Software Change Alerts detect the moment any endpoint deviates from its approved configuration baseline, giving CIS Control 4's monitoring requirement a continuous, automated implementation rather than a periodic manual review.
Use processes and tools to assign and manage authorisation to credentials for user accounts, including administrator accounts, ensuring only authorised users can access enterprise assets. Safeguard 5.2 (IG1) requires using unique passwords and disabling default credentials. Safeguard 5.3 (IG1) requires disabling dormant accounts after a defined inactive period. Safeguard 5.4 (IG2) requires restricting administrator privileges to dedicated administrator accounts and not using them for day-to-day activities.
Configuration Management's User and Group Management module lets IT teams create, modify, disable, and remove local user accounts remotely across the entire fleet, enforcing password complexity and expiry policies consistently without requiring manual intervention on each device. Role-based access controls within the Zecurit console enforce the principle of least privilege for IT staff managing endpoints, and User Logon Reports provide the access history record that account governance safeguards require as evidence.
Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software. Safeguard 6.3 (IG1) requires requiring MFA for externally exposed applications. Safeguard 6.4 (IG2) extends MFA to all administrative access. Safeguard 6.5 (IG2) requires requiring MFA for remote network access. Safeguard 6.8 (IG3) adds centralised access control management for all assets.
Remote Access requires the end user on the managed device to explicitly confirm any incoming session before the IT administrator is granted access, adding a mandatory user-side verification layer to every remote session. Session logs record the initiating account, the accessed device, session duration, and timestamp, building the access history record Control 6's safeguards expect to see during a review or investigation. Role-based access within the Zecurit console ensures that only authorised staff can initiate remote sessions into specific device groups.
Develop a plan to continuously assess and track vulnerabilities in enterprise assets within the infrastructure, and remediate them based on risk. Safeguard 7.1 (IG1) requires establishing and maintaining a vulnerability management process. Safeguard 7.2 (IG1) requires establishing and maintaining a remediation process. Safeguard 7.3 (IG1) requires performing automated operating system patch management. Safeguard 7.4 (IG1) requires performing automated application patch management. Safeguards 7.5 and 7.6 (IG2) add internal and external authenticated vulnerability scanning. CIS Controls v8.1 clarified that automated patching is an IG1 baseline requirement, not an IG2 enhancement.
Patch Management continuously scans every managed endpoint for missing OS and third-party application patches, ranking them by CVSS score and active exploit intelligence so critical vulnerabilities surface first and can be deployed during defined maintenance windows. Vulnerability Management maps installed software against a live CVE database fleet-wide, giving security teams the continuous, prioritised vulnerability data that safeguards 7.1 through 7.6 require. Patch Compliance Reports document remediation timelines, providing the evidence that both the process and its execution are functioning as required.
CIS Control 10 covers data recovery, but safeguards 10.3 and 10.4 apply directly to the endpoint: organisations must test the integrity of backups (10.3) and protect sensitive data by disabling the use of removable media on assets unless a documented business need exists (10.4, IG2). The removable media safeguard is among the most consistently overlooked IG2 requirements in endpoint hardening assessments.
Device Control enforces allow, block, or trusted-device-only policies for removable storage devices, Bluetooth peripherals, and wireless adapters across the entire managed fleet. BadUSB keystroke injection prevention protects against malicious USB device attacks, and policies remain in force even when an endpoint is offline, closing the gap that remote and travelling users create. Every connection attempt and policy enforcement event is logged with a timestamp, device ID, and user account for audit purposes.
Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack. Safeguard 8.2 (IG1) requires collecting audit logs. Safeguard 8.3 (IG2) requires ensuring that audit logs are protected. Safeguard 8.5 (IG1) requires collecting detailed audit logs. Safeguard 8.9 (IG2) requires centralising, where possible, the collection of audit logs. Endpoints generate the most operationally relevant log data in most environments, and gaps in endpoint log coverage mean gaps in detection and forensics capability.
The Monitoring and Alerts module logs security, hardware, software, and user access events in real time across every managed endpoint, surfacing them in a unified console alongside configurable alert thresholds. User Logon Reports record access patterns by account and device, and Device Control logs every connection event with full metadata, building the comprehensive activity record that Control 8's safeguards define as a minimum baseline across all three Implementation Groups.
Prevent or control the installation, spread, and execution of malicious applications, code, and scripts on enterprise assets. Safeguard 10.1 (IG1) requires deploying and maintaining anti-malware software on all enterprise assets that support it. Safeguard 10.2 (IG1) requires configuring anti-malware software to scan automatically. Safeguard 10.6 (IG2) requires centrally managing anti-malware software. Disabled or out-of-date anti-malware on even a single unmonitored endpoint is consistently one of the first gaps an attacker locates and exploits.
Security Alerts in the Monitoring and Alerts module notify IT teams immediately when antivirus or antimalware protection is disabled, out of date, or has produced a threat detection on any managed endpoint. This closes the gap between a policy requiring anti-malware deployment and verified, continuous enforcement of it across the entire fleet, supporting both the deployment safeguard (10.1) and the centralised management safeguard (10.6) from a single console.
CIS Controls compliance is increasingly assessed through formal evaluations, whether internal security reviews, customer security questionnaires, regulatory alignment audits, or third-party CIS certification assessments. Producing evidence that the controls are operationally in place, not just documented in policy, requires data from the endpoint environment that is current, accurate, and exportable on demand.
Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for CIS Controls, ISO 27001, PCI-DSS, HIPAA, GDPR, and NIST. Security Reports surface BitLocker gaps, firewall status, antivirus health, patch compliance, and software inventory data across all managed endpoints in a single view. Scheduled Report Delivery automates evidence generation on a recurring basis, so the data is ready well ahead of any assessment rather than assembled reactively under deadline pressure.
A consolidated reference mapping each endpoint-relevant CIS Control to the relevant Zecurit features and the Implementation Group that requires each safeguard.
| CIS Control | IG | Zecurit Endpoint Manager Capability |
|---|---|---|
| Control 1: Asset Inventory | IG1+ | Asset DiscoveryHardware InventoryHardware Change Alerts |
| Control 2: Software Inventory | IG1+ | Software InventorySoftware AlertsSoftware Licence Management |
| Control 3: Data Protection (3.6, 3.10) | IG1+ | BitLocker ManagementDevice ControlBitLocker Compliance Reports |
| Control 4: Secure Configuration (4.2, 4.5) | IG1+ | Configuration ManagementCentralised Profile ManagementChange Alerts |
| Control 5: Account Management | IG1+ | User and Group ManagementPassword Policy EnforcementRole-Based Access |
| Control 6: Access Control (6.3 – 6.5) | IG1+ | Remote AccessSession Confirmation and AuditUser Logon Reports |
| Control 7: Vulnerability Management (7.1 – 7.6) | IG1+ | Patch ManagementVulnerability ManagementCVSS PrioritisationPatch Compliance Reports |
| Control 8: Audit Log Management | IG1+ | Real-Time Monitoring and AlertsUser Logon ReportsAudit Device Logs |
| Control 10: Malware Defences (10.1, 10.6) | IG1+ | Security AlertsAntivirus Status MonitoringCentralised Security Dashboard |
| Control 10: Removable Media (10.4) | IG2+ | Device ControlUSB/Removable Storage PoliciesBadUSB Protection |
| Cross-Control Compliance Evidence | IG1+ | 100+ Compliance ReportsCIS Controls TemplatesScheduled Report Delivery |
The CIS Critical Security Controls are built on a simple premise: the attacks most organisations face most often exploit the same small set of gaps. Unmanaged assets, out-of-date software, missing patches, weak configurations, uncontrolled removable media, and inactive antimalware are the recurring entry points, and six of the first seven CIS Controls exist specifically to close them.
What distinguishes successful CIS programmes from compliance paper exercises is not documentation: it is continuous enforcement at the endpoint, where these controls actually need to operate. Policy statements about asset inventory or patch management carry no weight in a security assessment or an incident investigation without the real-time data and evidence to back them up, device by device.
Zecurit Endpoint Manager addresses CIS Controls v8.1's core endpoint-relevant safeguards from IG1 upwards, from a single lightweight agent and unified console, giving IT and security teams the continuous asset visibility, automated patch management, configuration enforcement, device control, and audit-ready reporting that the CIS Controls framework was designed to produce as operational outcomes, not documentation artefacts.
Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.
To learn more about Zecurit Endpoint Manager and how it supports your CIS Controls programme, start a free 14-day trial or contact the Zecurit team.
Contact Zecurit