Skip to main content
All answers

What is the difference between CIS Level 1 and Level 2?

CIS Level 1 (L1) controls are essential security settings that can be applied without significant operational impact, the baseline every organization should meet. CIS Level 2 (L2) controls provide defense-in-depth for sensitive environments but may affect functionality or performance. Most organizations target L1 across all systems and L2 selectively on systems handling sensitive data.

The longer answer.

L1 covers settings like disabling default accounts, enforcing password policies, configuring audit logging, and removing unnecessary services. These are widely accepted as table-stakes for production systems.

L2 covers more restrictive settings: disabling additional protocols, stricter cryptography requirements, additional logging, application allowlisting. L2 is appropriate for systems handling classified data, financial transactions, protected health information, or other regulated data categories.

More questions on Fundamentals?

Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.