Hands typing on a laptop keyboard surrounded by floating digital graphics of lock icons, user profiles, AI, and data windows.

CIS Releases Community Defense Model v3.0

The model links essential cyber hygiene to coverage of 84% to 89% of techniques across five attack categories.

The Center for Internet Security (CIS) released version 3.0 of its Community Defense Model, which combines attack data, threat intelligence and the MITRE ATT&CK framework to evaluate cybersecurity safeguards against techniques used in five attack categories.

The analysis found Implementation Group 1 of the CIS Critical Security Controls, also known as essential cyber hygiene, covered:

  • System intrusion: 89%
  • Basic web application attacks: 88%
  • Denial-of-service: 88%
  • Social engineering: 86%
  • Privilege misuse: 84%

Coverage increased to between 99% and 100% across all five categories when all CIS Controls Safeguard were applied.

Safeguard 4.1, "Establish and Maintain a Secure Configuration Process," ranked highest among individual safeguards across all five categories. The update also introduces the CIS Controls Active Defense Lifecycle, which maps safeguards to stages of attacker behavior.

CIS concluded that foundational security practices remain effective against many AI-enabled attacks, while AI can increase attack speed and accessibility.

About the Author

Danielle Naidu is assistant editor for Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products