Lição 6 de 9 · 8 min
CIS Controls applied to AI systems
Use CIS Controls v8.1 and the three AI companion guides CIS published in 2026 to check that baseline hygiene covers models, agents and their tool connections.
Por agora esta página está em inglês.
The other three frameworks in this course are about AI. The CIS Critical Security Controls are about everything, and that is their value here. A prompt-injection finding is often only as damaging as the missing basics around it: an unlogged tool call, an over-privileged token, an unknown application. CIS Controls give you a plain checklist of those basics, and in 2026 CIS extended them to AI directly.
CIS Controls v8.1 in brief
CIS describes v8.1 as an iterative update to version 8. It was guided by three principles, context, coexistence (alignment with other security frameworks) and consistency (continuity for existing users), and it realigned the NIST Cybersecurity Framework mappings to CSF 2.0, added the Govern function from CSF 2.0, revised asset classes and clarified some safeguard descriptions. The 18 controls are:
- Inventory and Control of Enterprise Assets
- Inventory and Control of Software Assets
- Data Protection
- Secure Configuration of Enterprise Assets and Software
- Account Management
- Access Control Management
- Continuous Vulnerability Management
- Audit Log Management
- Email and Web Browser Protections
- Defenses against harmful software
- Data Recovery
- Network Infrastructure Management
- Network Monitoring and Defense
- Security Awareness and Skills Training
- Service Provider Management
- Application Software Security
- Incident Response Management
- Penetration Testing
The AI companion guides
On 20 April 2026, CIS announced three companion guides for CIS Controls v8.1, released with Astrix Security and Cequence Security. They cover large language models, AI agents and the Model Context Protocol (MCP). The press release describes them as extending the Controls into AI systems and adapting them to AI-driven architectures. So the answer to the common question, “is there CIS guidance for AI?”, is yes, and you should read the guide that matches your system:
| Guide | Focus (as CIS describes it) |
|---|---|
| AI and LLM Companion Guide | Text-centric generative AI across the lifecycle: training and fine-tuning, deployment, inference, monitoring and retirement |
| AI Agents Companion Guide | The agent layer where planning, reasoning, tool invocation and multi-step workflows occur; risks named include unauthorised actions, data leakage and unintended system changes |
| MCP Companion Guide | Secure tool access, management of non-human identities, and auditable interactions across the protocol layer |
The LLM guide’s central message is useful to memorise. Many existing safeguards apply directly: asset management, secure configuration, identity, logging, vulnerability management and supplier governance. But implementation must account for prompt injection, retrieval poisoning, over-permissioned tool integrations and provider-driven model updates. It also highlights controls that are new in emphasis: prompt and guardrail change control, context boundary enforcement, model and dataset provenance, and containment levers to respond quickly when AI-driven workflows behave unexpectedly. The agents guide says each section interprets relevant safeguards in the context of agent behaviour, showing where traditional controls still apply and where new patterns must be considered.
A mapping you can use in a review
The table below is this course’s own illustration of how the control families translate to AI. It works at the level of control names; the companion guides map to individual safeguards, so consult them for numbered detail.
| CIS control (name) | Question to ask about an AI system |
|---|---|
| 1 and 2: Asset inventories | Do we know every AI application, agent, model file, plugin and MCP server in use, including ones staff installed themselves? |
| 3: Data Protection | What data can reach prompts, retrieval indexes and logs, and who can read it? |
| 4: Secure Configuration | Are system prompts and guardrail settings under change control, like any other configuration? |
| 5 and 6: Accounts and Access | Does each agent have its own identity, with the minimum permissions for its task? |
| 7: Vulnerability Management | Who patches AI frameworks and libraries, and who tracks provider model updates that change behaviour? |
| 8: Audit Logs | Do logs record tool invocations, data access and the identity used? |
| 13: Network Monitoring and Defense | Can we see and restrict where AI tools send data? |
| 15: Service Provider Management | Have we reviewed the model provider’s documentation and terms? |
| 17: Incident Response | Can we switch off a tool, revoke a credential or disable an agent quickly? |
| 18: Penetration Testing | Has the AI system been tested by someone trying to misuse it? |
Control 18 is the entry point to the next lesson: red teaming is the AI-specific form of penetration testing. But it works best as the last check, after the earlier rows are answered. If you cannot list your agents (row 1) or tell what they did last night (row 8), a red team will mostly discover that.
A reter
- CIS Controls v8.1 has 18 controls, and CIS published AI LLM, AI Agents and MCP companion guides on 20 April 2026.
- Many existing safeguards (assets, configuration, identity, logging, vulnerability and supplier management) apply directly to AI, but must account for prompt injection, retrieval poisoning, over-permissioned tools and provider model updates.
- New emphasis areas include prompt and guardrail change control, context boundaries, model and dataset provenance, and containment levers.
- Use CIS controls as the baseline check before an AI red-team engagement, so testing finds new problems rather than missing basics.
Teste-se
1. What did CIS publish on 20 April 2026?
- CIS Controls v9
- Three companion guides adapting CIS Controls v8.1 to LLMs, AI agents and MCP — Certo.
- A model certification scheme
- A scoring scheme for AI models
CIS, Astrix Security and Cequence Security released the AI LLM, AI Agent and MCP companion guides for CIS Controls v8.1.
2. According to CIS’s LLM guide, which is true of existing safeguards?
- They are irrelevant to LLMs
- Many apply directly, but implementation must account for AI-specific risks — Certo.
- Only Data Recovery applies
- They apply only during model training
The guide lists asset management, secure configuration, identity, logging, vulnerability management and supplier governance as applying directly, while stressing AI-specific risks.
3. Which CIS control is closest to AI red teaming?
- Control 3 Data Protection
- Control 14 Security Awareness and Skills Training
- Control 18 Penetration Testing — Certo.
- Control 11 Data Recovery
Red teaming an AI system is the AI-specific counterpart of penetration testing, which is CIS Control 18.
Praticar com o FireAI
Ponha esta lição em prática no seu próprio Mac.
- Regras: app, sítio, domínio, IP ou um intervalo, para sempre ou até reiniciar — Escreva uma regra tão precisa como um único endereço ou tão ampla como um domínio inteiro.
- Investigue uma ligação — Decida com os factos à sua frente, não com um aviso vago.
- O Mapa-múndi — Veja para onde os seus dados vão de facto, não apenas um nome de anfitrião que teria de procurar você mesmo.
- Requests by country and upload spikes — See at a glance where your Mac talks to, and notice at once when it suddenly sends a lot of data somewhere.
- Listas de ameaças (opcional) — Compare o seu tráfego com dados públicos de ameaças sem o enviar para lado nenhum.
- Modos de segurança: Casa, Café, Paranoico, Sob ataque — Ajuste o rigor do FireAI ao sítio onde o seu Mac está de facto, com um toque.
Fontes
- CIS: CIS Controls v8.1
- CIS: The 18 CIS Critical Security Controls
- CIS press release: new AI security companion guides (20 April 2026)
- CIS: Artificial Intelligence and Large Language Models Companion Guide
- CIS: Artificial Intelligence (AI) Agents Companion Guide
Ponha em prática no seu Mac
Experimente todas as funcionalidades grátis durante 17 dias, sem cartão.