Урок 6 из 9 · 8 мин
CIS Controls applied to AI systems
Use CIS Controls v8.1 and the three AI companion guides CIS published in 2026 to check that baseline hygiene covers models, agents and their tool connections.
Пока эта страница на английском.
The other three frameworks in this course are about AI. The CIS Critical Security Controls are about everything, and that is their value here. A prompt-injection finding is often only as damaging as the missing basics around it: an unlogged tool call, an over-privileged token, an unknown application. CIS Controls give you a plain checklist of those basics, and in 2026 CIS extended them to AI directly.
CIS Controls v8.1 in brief
CIS describes v8.1 as an iterative update to version 8. It was guided by three principles, context, coexistence (alignment with other security frameworks) and consistency (continuity for existing users), and it realigned the NIST Cybersecurity Framework mappings to CSF 2.0, added the Govern function from CSF 2.0, revised asset classes and clarified some safeguard descriptions. The 18 controls are:
- Inventory and Control of Enterprise Assets
- Inventory and Control of Software Assets
- Data Protection
- Secure Configuration of Enterprise Assets and Software
- Account Management
- Access Control Management
- Continuous Vulnerability Management
- Audit Log Management
- Email and Web Browser Protections
- Defenses against harmful software
- Data Recovery
- Network Infrastructure Management
- Network Monitoring and Defense
- Security Awareness and Skills Training
- Service Provider Management
- Application Software Security
- Incident Response Management
- Penetration Testing
The AI companion guides
On 20 April 2026, CIS announced three companion guides for CIS Controls v8.1, released with Astrix Security and Cequence Security. They cover large language models, AI agents and the Model Context Protocol (MCP). The press release describes them as extending the Controls into AI systems and adapting them to AI-driven architectures. So the answer to the common question, “is there CIS guidance for AI?”, is yes, and you should read the guide that matches your system:
| Guide | Focus (as CIS describes it) |
|---|---|
| AI and LLM Companion Guide | Text-centric generative AI across the lifecycle: training and fine-tuning, deployment, inference, monitoring and retirement |
| AI Agents Companion Guide | The agent layer where planning, reasoning, tool invocation and multi-step workflows occur; risks named include unauthorised actions, data leakage and unintended system changes |
| MCP Companion Guide | Secure tool access, management of non-human identities, and auditable interactions across the protocol layer |
The LLM guide’s central message is useful to memorise. Many existing safeguards apply directly: asset management, secure configuration, identity, logging, vulnerability management and supplier governance. But implementation must account for prompt injection, retrieval poisoning, over-permissioned tool integrations and provider-driven model updates. It also highlights controls that are new in emphasis: prompt and guardrail change control, context boundary enforcement, model and dataset provenance, and containment levers to respond quickly when AI-driven workflows behave unexpectedly. The agents guide says each section interprets relevant safeguards in the context of agent behaviour, showing where traditional controls still apply and where new patterns must be considered.
A mapping you can use in a review
The table below is this course’s own illustration of how the control families translate to AI. It works at the level of control names; the companion guides map to individual safeguards, so consult them for numbered detail.
| CIS control (name) | Question to ask about an AI system |
|---|---|
| 1 and 2: Asset inventories | Do we know every AI application, agent, model file, plugin and MCP server in use, including ones staff installed themselves? |
| 3: Data Protection | What data can reach prompts, retrieval indexes and logs, and who can read it? |
| 4: Secure Configuration | Are system prompts and guardrail settings under change control, like any other configuration? |
| 5 and 6: Accounts and Access | Does each agent have its own identity, with the minimum permissions for its task? |
| 7: Vulnerability Management | Who patches AI frameworks and libraries, and who tracks provider model updates that change behaviour? |
| 8: Audit Logs | Do logs record tool invocations, data access and the identity used? |
| 13: Network Monitoring and Defense | Can we see and restrict where AI tools send data? |
| 15: Service Provider Management | Have we reviewed the model provider’s documentation and terms? |
| 17: Incident Response | Can we switch off a tool, revoke a credential or disable an agent quickly? |
| 18: Penetration Testing | Has the AI system been tested by someone trying to misuse it? |
Control 18 is the entry point to the next lesson: red teaming is the AI-specific form of penetration testing. But it works best as the last check, after the earlier rows are answered. If you cannot list your agents (row 1) or tell what they did last night (row 8), a red team will mostly discover that.
Главное
- CIS Controls v8.1 has 18 controls, and CIS published AI LLM, AI Agents and MCP companion guides on 20 April 2026.
- Many existing safeguards (assets, configuration, identity, logging, vulnerability and supplier management) apply directly to AI, but must account for prompt injection, retrieval poisoning, over-permissioned tools and provider model updates.
- New emphasis areas include prompt and guardrail change control, context boundaries, model and dataset provenance, and containment levers.
- Use CIS controls as the baseline check before an AI red-team engagement, so testing finds new problems rather than missing basics.
Проверьте себя
1. What did CIS publish on 20 April 2026?
- CIS Controls v9
- Three companion guides adapting CIS Controls v8.1 to LLMs, AI agents and MCP — Верно.
- A model certification scheme
- A scoring scheme for AI models
CIS, Astrix Security and Cequence Security released the AI LLM, AI Agent and MCP companion guides for CIS Controls v8.1.
2. According to CIS’s LLM guide, which is true of existing safeguards?
- They are irrelevant to LLMs
- Many apply directly, but implementation must account for AI-specific risks — Верно.
- Only Data Recovery applies
- They apply only during model training
The guide lists asset management, secure configuration, identity, logging, vulnerability management and supplier governance as applying directly, while stressing AI-specific risks.
3. Which CIS control is closest to AI red teaming?
- Control 3 Data Protection
- Control 14 Security Awareness and Skills Training
- Control 18 Penetration Testing — Верно.
- Control 11 Data Recovery
Red teaming an AI system is the AI-specific counterpart of penetration testing, which is CIS Control 18.
Примените на практике в FireAI
Примените этот урок на своём Mac.
- Правила: приложение, сайт, домен, IP или диапазон, навсегда или до перезагрузки — Напишите правило, точное как один адрес, или широкое как целый домен.
- Исследовать подключение — Принимайте решение, опираясь на факты перед глазами, а не на смутное предупреждение.
- Карта мира — Видьте, куда на самом деле уходят ваши данные, а не просто имя хоста, которое пришлось бы искать самостоятельно.
- Requests by country and upload spikes — See at a glance where your Mac talks to, and notice at once when it suddenly sends a lot of data somewhere.
- Списки угроз (по желанию) — Сверяйте свой трафик с открытыми данными об угрозах, никуда его не отправляя.
- Режимы безопасности: Дом, Кофейня, Параноидальный, Под атакой — Подстройте строгость FireAI под реальное местоположение вашего Mac одним касанием.
Источники
- CIS: CIS Controls v8.1
- CIS: The 18 CIS Critical Security Controls
- CIS press release: new AI security companion guides (20 April 2026)
- CIS: Artificial Intelligence and Large Language Models Companion Guide
- CIS: Artificial Intelligence (AI) Agents Companion Guide
Примените это на своём Mac
Все функции бесплатно на 17 дней, без банковской карты.