How to Prioritize CIS Controls on a Small Budget

TL;DR
Start with hardware and software inventories, then build vulnerability management, administrative privilege controls, and secure configurations on that foundation. Organizations with limited budgets can improve security without buying expensive tools by adopting measurable policies, matching requirements to actual capabilities, documenting approved exceptions, and prioritizing controls that address the greatest share of observed breaches.
Transcript
Good morning, everyone. We'll get started. For the session on prioritizing the top twenty on a shoestring, please welcome the VP of Information Security at Police and Fire FCU, Mr. William Bailey. Hello. Hopefully everyone is excited to still be here. I know it's the very last day of RSA. Oh, a little bit more enthusiasm. There was good coffee outs... Read More
Key Insights
- Hardware asset identification is the essential starting point because an organization must know what it owns before it can reliably manage software, vulnerabilities, configurations, or other security controls. The CIS crosswalk also connects this control with corresponding requirements in frameworks such as NIST and ISO.
- Software inventory is directly dependent on hardware inventory and helps establish the scope for later security work. Without an accurate understanding of both hardware and installed software, an organization cannot determine whether its vulnerability scanning covers the assets and applications that actually require assessment.
- The first five CIS controls addressed 85 percent of the breaches examined in Tripwireβs study of the 2017 data breach report, either eliminating those breaches or drastically reducing their impact. An Australian study cited in the talk attributed about 80 percent coverage to the first three controls.
- Security policies are rules of the road that define expected behavior and give operational controls a basis for enforcement. The presenter describes a case where inappropriate web activity could not be addressed effectively because the organization had no policy prohibiting or governing that behavior.
- A good policy is aligned with actual organizational capabilities, including available personnel, skills, funding, and tools. A highly restrictive requirement is not useful when the organization cannot perform or defend it, so policy maturity may need to develop gradually over time.
- Measurable policies are necessary because organizations must be able to verify and prove that stated requirements are being followed. Each policy should direct a check, measurement, or other evidence-producing activity, particularly when an organization is preparing for an assessment such as a SOC assessment.
- Regular policy review is an important indicator of governance discipline, with yearly review presented as the general practice. Outdated references, such as requiring an older mobile operating system version, can reveal to an auditor that the policy has not been examined or updated recently.
- Policy exceptions are acceptable when they are documented, approved by senior management, time-limited, periodically reviewed, and accompanied by additional controls where appropriate. Exception records do not require an expensive governance system and may be stored through practical methods such as SharePoint or retained memoranda.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How should a small organization prioritize CIS controls?
A small organization should begin by identifying and controlling its hardware assets, then determine which software is installed on those assets. Those inventories establish the scope needed for vulnerability management. The organization can then address administrative privileges and secure configurations, choosing practical controls that fit its budget while concentrating first on measures associated with the largest reduction in observed breaches.
Q: Why should hardware and software inventories come first?
Hardware and software inventories come first because later controls depend on knowing what exists in the environment. An organization cannot confirm that a vulnerability scan is complete if it has not identified the relevant devices and applications. Hardware identification establishes the initial asset population, while software identification adds the application-level information needed to scope vulnerability and configuration work.
Q: How much breach coverage can the first CIS controls provide?
The presentation cites a Tripwire study using the 2017 data breach report that found implementing the first five controls would address 85 percent of the examined breaches, either eliminating them or drastically reducing them. It also cites an Australian study reporting that the first three controls would have addressed about 80 percent, illustrating the value of prioritizing early controls.
Q: Why are security policies necessary before enforcing controls?
Security policies define the rules that employees and systems are expected to follow, while tactical and procedural controls help enforce those rules. The presenter recalls detecting improper web activity but being unable to act effectively because no policy addressed it. A written policy gives the organization an approved basis for accountability, enforcement, measurement, and supporting operational controls.
Q: How specific should an information security policy be?
An information security policy should contain enough specificity to establish meaningful requirements without becoming so narrow that changing technology makes it difficult to follow. It should avoid unnecessary dependence on named vendors or products when broader language will work. Detailed implementation expectations can instead appear in supporting standards, baselines, procedures, and guidelines that are easier to update.
Q: How can an organization make security policies measurable?
An organization can make a policy measurable by including requirements that produce a check or evidence showing whether the policy is being carried out. The presenter treats this as a metric even if organizations prefer different terminology. Measurability is especially important when preparing for assessments because the organization must prove that its documented requirements are operating in practice.
Q: How should security policy exceptions be managed?
A security policy exception should document why compliance is not currently possible, identify any additional controls, obtain senior management approval, and assign a defined duration such as three months, six months, or a year. The exception should also be reviewed periodically. Records can be maintained in a practical repository such as SharePoint or preserved memoranda rather than an expensive governance platform.
Q: How often should security policies be reviewed?
Security policies should generally be reviewed yearly, even when the review only confirms that their contents remain current. Regular review helps detect obsolete technical references and demonstrates that governance documents remain active. The presenter notes that an outdated mobile operating system requirement can signal to an auditor that nobody has examined the policy for approximately two years.
Summary & Key Takeaways
-
Organizations may need to implement security controls because of regulations such as PCI, HIPAA, FERPA, or NERC CIP, or because of contractual obligations inherited through business relationships. When budgets are extremely limited, security leaders must prioritize investments, optimize available resources, demonstrate value, and follow a deliberate strategy instead of pursuing every control equally.
-
The CIS controls are grouped into basic, foundational, and organizational levels, but even the basic controls require thoughtful sequencing. Hardware inventory comes first, followed by software inventory, because vulnerability scanning depends on knowing which assets and applications exist. Administrative privilege controls and secure configurations can then build upon that verified foundation.
-
Policies establish enforceable expectations and support the organizationβs long-term security strategy. Effective policies match available people, skills, and tools, include measurable requirements, and receive regular review. Exceptions are acceptable when their reasons, approvals, duration, and additional controls are documented. Standards, baselines, procedures, and guidelines should provide the supporting operational detail.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator