The Center for Internet Security (CIS) developed a list of high-priority defensive actions that provide a “must-do, do-first” starting point for every enterprise looking to prevent cyberattacks. According to the SANS Institute, which developed the CIS controls, “CIS controls are effective because they are derived from the most common attack patterns highlighted in the leading threat reports and vetted across a very broad community of government and industry practitioners.”
Organizations can refer to these and other frameworks to develop their own security framework and IT security policies. A well-developed framework helps make sure that an organization:
- Enforces IT security policies through security controls
- Educates employees and users about security guidelines
- Meets industry and compliance regulations
- Achieves operational efficiency across security controls
- Continually assesses risks and addresses them through security controls
A security solution is only as strong as its weakest link. Therefore, you should consider multiple layers of security controls, also known as a defense-in-depth strategy, to implement security controls across identity and access management, data, applications, network or server infrastructure, physical security and security intelligence.