Terminology Index

Glossary

2953 terms

Open concept maps
C
32

CIS Control Categories

The way the CIS Controls group their safeguards into logical areas, such as asset and software inventory, data protection, access control, and incident response. The categories organize the controls into a coherent program rather than a flat list.

The CIS Controls bundle dozens of safeguards into a set of categories that each address a domain of defense, helping teams see the program's structure and find the controls relevant to a given concern. Understanding the categories makes the framework navigable and supports planning coverage across the breadth of security, complementing the prioritization that Implementation Groups provide.

Introduced in: Security Frameworks and Control Mapping

Examples

  • Locating data-protection safeguards within their CIS control category.
  • Using the categories to check coverage across asset, access, and response domains.
  • Organizing a roadmap around the control categories.