The 18 CIS Critical Security Controls (currently at version 8) are a prioritized set of cybersecurity practices published by the Center for Internet Security. They are not regulations, but they are widely used as a practical baseline, including in industrial and regulated environments.
The 18 CIS Critical Security Controls (v8)
- Inventory and Control of Enterprise Assets
Maintain an accurate, continuously updated inventory of all enterprise assets (servers, workstations, laptops, mobile devices, network devices, etc.). In plants, this must be adapted carefully for production equipment and OT devices where scanning can disrupt operations. - Inventory and Control of Software Assets
Track and manage all authorized software and prevent unauthorized software. In regulated manufacturing, this must align with validated software baselines, change control, and vendor/legacy constraints. - Data Protection
Identify, classify, and protect data at rest, in transit, and in use. For operations, this includes production recipes, NC programs, process parameters, quality records, and export-controlled technical data. - Secure Configuration of Enterprise Assets and Software
Establish and maintain secure configurations for hardware and software. In long-lifecycle equipment, you often need hardened but stable builds, carefully managed under change control and validation rather than frequent reconfiguration. - Account Management
Manage user and service accounts throughout their lifecycle. In plants, this includes shared workstation practices, operator accounts on HMI/MES, and ensuring proper deprovisioning across IT and OT systems. - Access Control Management
Implement and enforce appropriate access control policies (including least privilege). For regulated environments, this must match documented roles, training, and segregation of duties across MES, QMS, ERP, and control systems. - Continuous Vulnerability Management
Identify and remediate vulnerabilities on a risk-informed schedule. In OT, aggressive scanning or patching can break validated systems or disrupt production, so many plants use tiered approaches, offline testing, and maintenance windows. - Audit Log Management
Collect, store, and review event and audit logs. This should include AD, firewalls, MES, QMS, industrial firewalls, and key equipment where feasible. Constraints often include limited logging on legacy machines and storage/retention limits. - Email and Web Browser Protections
Protect against threats delivered via email and web browsers. This primarily affects office IT but also engineering workstations that handle CAD/PLM access, supplier files, and NC program transfers. - Malware Defenses
Deploy and manage anti-malware protections. On production and lab systems, this often requires careful tuning, offline updates, vendor-approved configurations, and testing to avoid impacting deterministic control behavior or validated software. - Data Recovery
Establish and test data backup and recovery processes. For manufacturing, backups must cover MES, historians, recipes, machine parameters, and configuration baselines, with proven restore procedures that respect validation and traceability. - Network Infrastructure Management
Securely configure, manage, and segment network devices and services. In mixed IT/OT networks, this includes DMZs, cell/zone segmentation, industrial firewalls, and careful planning to avoid unplanned downtime. - Network Monitoring and Defense
Detect and respond to network-based attacks through monitoring, detection, and alerting. In plants, passive OT monitoring is often preferred to avoid impacting legacy controllers and safety systems. - Security Awareness and Skills Training
Train personnel in cybersecurity awareness and role-specific skills. For regulated operations, training content and completion records often need to align with existing training management, SOPs, and competency requirements. - Service Provider Management
Manage cybersecurity risks associated with third-party service providers. This includes integrators, machine tool vendors, cloud MES/QMS providers, and remote support arrangements for critical equipment. - Application Software Security
Incorporate security throughout the software development lifecycle. In manufacturing, this matters for in-house tools, scripts, interfaces, and any customizations of MES/SCADA that interact with regulated data or validated processes. - Incident Response Management
Plan, test, and improve incident detection, reporting, and response. For plants, playbooks must account for safety, production continuity, regulatory reporting, and the reality of mixed IT/OT ownership and vendor dependencies. - Penetration Testing
Conduct penetration tests and red team exercises to validate the effectiveness of security controls. In operational environments, this must be tightly scoped and coordinated to avoid impacting validated systems, safety functions, or critical production.
How these controls apply in industrial and regulated environments
The CIS Controls are general-purpose, so direct, literal implementation is not always feasible in brownfield plants with legacy equipment, long validation cycles, and constrained downtime. Common realities include:
- Some controls (such as vulnerability scanning or penetration testing) must be adapted to avoid disrupting sensitive OT networks or validated systems.
- Network segmentation, logging, and access control improvements are often more practical than rapid patching of legacy equipment that is no longer vendor-supported.
- Integration with existing MES, ERP, PLM, and QMS systems is usually incremental. Full rip-and-replace moves to new platforms are often blocked by qualification, validation, and interface complexity.
- Changes to configurations, software baselines, and access models must pass through existing change control, documented risk assessment, and, where applicable, system revalidation.
Because of these constraints, many organizations treat the CIS Controls as a prioritization and gap-analysis tool, then build a pragmatic, risk-based roadmap that fits their specific plant architectures, regulatory requirements, and lifecycle constraints.