Aetos One Aetos One Download
Aetos One mark

The Common Sense Security Framework

Align your organization's cybersecurity program with your executive leadership team's goals and objectives.

8areas
38controls
5loss scenarios
10load-bearing controls
What this is

Built for the people who own the outcome

The Common Sense Security Framework turns cybersecurity into governance questions a CEO, CFO, or COO answers without a technical background. Each control pairs one plain question with the evidence to demand from IT or a vendor. A no, or an honest "we don't know," names where to act next.

Fill in the critical processes first. Name an owner for the risk inventory. Work through all 38 controls from there. The framework scores what is measured, not what is assumed.

Primary audienceCEO, CFO, COO
Secondary audienceCMO, CIO, CTO
Built forOrganizations pursuing a business-aligned cybersecurity program
GoalShorten disruption, cut its cost
Next stepGraduate to NIST CSF or ISO 27001
CIS Critical Security Controls
The framework

Eight areas. Thirty-eight controls.

Each area covers one part of the business. Each control is a question to ask this week and a piece of evidence to request today.

Govern Your Risk

4 controls
  • GV1Executive accountability and decision rights
  • GV2Risk appetite and downtime tolerance
  • GV3One authoritative asset and identity inventory
  • GV4Cyber insurance coverage and terms

Protect Your Identities

5 controls
  • ID1Phishing-resistant sign-in
  • ID2Standing privileges and admin rights
  • ID3Service accounts, API keys, and tokens
  • ID4Identity and authentication logs
  • ID5AI tools, agents, and integrations

Protect Your Devices

5 controls
  • DV1Endpoint detection and response coverage
  • DV2Patch management and known exploited vulnerabilities
  • DV3Hardening baselines and configuration drift
  • DV4End-of-life technology
  • DV5Change control and vendor updates

Protect Your Networks

5 controls
  • NW1Internet-facing exposure
  • NW2Email authentication and filtering
  • NW3Network segmentation
  • NW4Security log collection
  • NW5Application and API vulnerability management

Protect Your Data

5 controls
  • DA1Immutable, tested backups
  • DA2Encryption at rest and in transit
  • DA3Data discovery, classification, and access scope
  • DA4Wire transfer and payment verification
  • DA5Data protection compliance and breach readiness

Protect Your People

4 controls
  • PE1Security awareness and help desk verification
  • PE2Incident response exercises
  • PE3Hiring, onboarding, and offboarding controls
  • PE4Remote and off-premises device security

Protect Your Partnerships

5 controls
  • PA1Vendor posture monitoring
  • PA2Vendor access governance
  • PA3On-site vendor and OT access
  • PA4Vendor concentration risk
  • PA5Contractual notification and audit terms

Protect Your Uptime

5 controls
  • UP124/7 detection and containment authority
  • UP2Tested recovery time objectives
  • UP3Manual and degraded-mode procedures
  • UP4Dependency mapping
  • UP5Crisis management and disclosure readiness
Get the framework

Get the framework

Download the full workbook. Score all 38 controls, map your critical business processes, and see what a five-day outage would cost before one happens.

CSSF-v2.0.xlsx
Download CSSF v2.0 (XLSX)
Aetos One mark
Who built this

Built by Aetos One

Aetos One is a managed cybersecurity firm based in Columbus, Ohio. The Common Sense Security Framework is the assessment behind Aetos One's Guardian, Bastion, and Citadel programs, built around one idea: map the business processes that matter before buying another control.

Visit Aetos One to see the framework become a working security program, run by a named security leader.

Visit aetosone.com