CIS Controls
Who needs it
Organizations that want concrete, prioritized security actions rather than a broad risk-management framework to interpret, and companies building a security program from a low baseline who need to know what to do first.
Key requirements
Implementation of safeguards appropriate to your assigned Implementation Group, starting with foundational controls (asset inventory, access control, vulnerability management) before advancing to more sophisticated safeguards.
Cyber/privacy implications
Because the Controls are ranked by priority, gaps in the earliest controls (asset and software inventory, access control) undermine the effectiveness of every control built on top of them.
Assessment methodology
Implementation Group determination based on organization size and risk profile, safeguard-by-safeguard gap assessment, and a prioritized implementation roadmap starting from IG1.
Implementation phases
Scope
Determine your Implementation Group and assess current safeguard coverage.
Implement
Prioritized rollout starting from foundational IG1 safeguards.
Mature
Advance toward IG2/IG3 safeguards as your risk profile requires.
Evidence & documentation requirements
Asset and software inventories, access control records, vulnerability management logs, and a documented safeguard implementation status mapped to your Implementation Group.
Common mistakes
Jumping to advanced IG3 safeguards while foundational IG1 controls like asset inventory remain incomplete; treating the Controls as a static checklist instead of a prioritized, continuously maintained baseline.
Related standards
Expert review
FAQ
Request a Gap Assessment
Find out your Implementation Group and where your current safeguards stand.
Request a Gap Assessment →