18 controls, 153 safeguards, 3 Implementation Groups. The IGs are CIS's version of "how much of this actually applies to you" — same job CSF Tiers do, different shape.
| 1 | Inventory and Control of Enterprise Assets |
| 2 | Inventory and Control of Software Assets |
| 3 | Data Protection |
| 4 | Secure Configuration of Enterprise Assets and Software |
| 5 | Account Management |
| 6 | Access Control Management |
| 7 | Continuous Vulnerability Management |
| 8 | Audit Log Management |
| 9 | Email and Web Browser Protections |
| 10 | Malware Defenses |
| 11 | Data Recovery |
| 12 | Network Infrastructure Management |
| 13 | Network Monitoring and Defense |
| 14 | Security Awareness and Skills Training |
| 15 | Service Provider Management |
| 16 | Application Software Security — where an ASVS-based, secure-coding-first AppSec program actually lives in the CIS structure |
| 17 | Incident Response Management |
| 18 | Penetration Testing |
CSF is outcome-based and framework-agnostic — good for governance conversations and gap analysis at the leadership level. CIS Controls are concrete and prescriptive — good for "what do we actually configure" conversations with the engineers who have to implement it. Same client engagement often uses both: CSF for the Profile and roadmap, CIS Controls IG1 as the literal punch list for a small business that has nothing in place yet.