CROct 3, 2019

A Critical View on CIS Controls

arXiv:1910.01721v219 citations
Originality Synthesis-oriented
AI Analysis

This addresses the problem of evaluating security frameworks for organizations, but it is incremental as it builds on existing critiques without introducing new methods or data.

The paper critically assesses the CIS Controls, questioning their practical viability and effectiveness in improving organizational security, concluding that more scientific scrutiny and supporting material are needed for them to be a viable alternative to other approaches.

CIS Controls is a set of 20 controls and 171 sub-controls that were created with an idea of having a list of something to implement so that organizations can increase their security. While good in theory, it is a big question of how viable this approach is in practice, and does it really help. There is only a minor number of critical views of CIS Controls and since CIS Controls are marketed by two very influential organizations they are very popular. Yet, there are alternatives published by ISO, NIST and even PCI consortium. In this paper we critically assess CIS Controls, assumptions on which they are based as well as validity of approach and claims made in its favor. The conclusion is that scientific community should be more active regarding this topic, but also that more material is necessary. This is something that CIS and SANS should support if they want to make CIS Controls viable alternative to other approaches.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes