Asurvo
Security framework

Run CIS Controls with
confidence.

The CIS Critical Security Controls are a prioritized set of actions that collectively form a defense-in-depth set of best practices to mitigate the most common attacks against systems and networks.

Who it's for

Organizations that want a practical, prioritized hardening roadmap.

Scope

18 controls, 153 safeguards

Category
Security

How Asurvo helps

What you get for CIS Controls.

18 controls, 153 safeguards
Implementation Group (IG1–IG3) scoping
Prioritized, outcome-driven hardening
Cross-mapped to NIST CSF and ISO 27001

Hardening roadmap

Putting the CIS Controls to work

The CIS Critical Security Controls are published by the Center for Internet Security, a nonprofit that also maintains the CIS Benchmarks for secure configuration. Where frameworks such as ISO 27001 tell you to build a management system and decide your own controls, the CIS Controls start from the other end: a prioritized list of specific defensive actions drawn from how real attacks succeed. That makes them a favorite with IT leads who need to know what to do first on Monday.

Version 8 was released in 2021 and reorganized the controls around activities rather than who manages a device, reflecting cloud, remote work, and outsourced services. It contains 18 controls and 153 safeguards. CIS published version 8.1 in June 2024, which added a Govern security function to align with NIST CSF 2.0, refined safeguard wording and asset classes, and expanded the glossary. The core structure of 18 controls stayed the same, so a v8 program carries forward to v8.1 with targeted updates rather than a rebuild.

Implementation Groups: the part people skip

Every safeguard is assigned to one of three Implementation Groups. The groups are cumulative: IG2 includes all of IG1, and IG3 includes everything. They exist so an organization can pick a realistic target based on its resources, the sensitivity of its data, and the attackers it is likely to face, instead of treating all 153 safeguards as equally urgent.

Group, Safeguards, Typical organization, Goal comparison
IG156Small to medium organizations with limited IT and security expertise, handling mostly low-sensitivity dataEssential cyber hygiene: the minimum every enterprise should have against common, untargeted attacks
IG2130 (IG1 plus 74)Organizations with dedicated IT staff, multiple departments, and sensitive client or company dataHandle more complex environments and resist a broader range of attacks
IG3153 (all)Organizations with security specialists and sensitive data or functions subject to regulatory oversightWithstand targeted, sophisticated attacks and limit their impact

The 18 controls

CIS Critical Security Controls v8

CIS Critical Security Controls v8
1Inventory and Control of Enterprise Assets10Malware Defenses
2Inventory and Control of Software Assets11Data Recovery
3Data Protection12Network Infrastructure Management
4Secure Configuration of Enterprise Assets and Software13Network Monitoring and Defense
5Account Management14Security Awareness and Skills Training
6Access Control Management15Service Provider Management
7Continuous Vulnerability Management16Application Software Security
8Audit Log Management17Incident Response Management
9Email and Web Browser Protections18Penetration Testing

The ordering is intentional. Controls 1 and 2 come first because you cannot configure, patch, monitor, or recover assets you do not know about. Many later safeguards assume those inventories exist, so an organization that jumps to network monitoring before it has an asset list usually ends up with alerts it cannot attribute to an owner.

A 12-month path to IG1

Window, Focus, Output comparison
Months 1 to 2Controls 1 and 2: enterprise asset and software inventories, with a process for handling unauthorized itemsAuthoritative inventories fed from endpoint management, cloud accounts, and identity systems
Months 2 to 4Controls 4, 5, and 6: secure configuration baselines, account inventory, MFA, and access granting and revocationDocumented configuration standards and a joiner, mover, leaver process that works
Months 4 to 6Controls 7 and 10: vulnerability management process, automated patching, anti-malwareRemediation SLAs you define, tracked against scan results
Months 6 to 8Controls 3, 8, and 11: data inventory and handling, audit logging, automated and isolated backupsData management process, log retention, and a tested restore
Months 8 to 10Controls 9 and 14: supported browsers and email clients, DNS filtering, awareness trainingTraining records and email and web protection settings
Months 10 to 12Controls 15 and 17: service provider inventory, incident response roles and contactsVendor list with owners, and an incident response process with contact details

The sequence is a suggestion, not a mandate from CIS. Adjust it to your gaps: a company with mature identity tooling may finish Controls 5 and 6 in weeks, while one with a large unmanaged endpoint fleet will spend longer on Control 1. Keep network infrastructure up to date (Control 12) alongside patching. Controls 13, 16, and 18 have no IG1 safeguards and come into play as you move toward IG2 and IG3.

Evidence that proves a safeguard is in place

The CIS Controls are not a certification, so there is no mandated artefact list. But customers, insurers, auditors, and boards may still ask you to show CIS alignment, and self-assessments are only as credible as the evidence behind them. CIS offers the CIS Controls Self Assessment Tool (CSAT) for tracking implementation. The records below are what a reviewer will reasonably ask for.

Records worth keeping

  • Asset and software inventory exports with the date they were generated and the sources they draw from
  • Configuration baselines, such as CIS Benchmark profiles, plus compliance scan results against them
  • MFA enforcement settings for externally exposed applications, remote access, and administrative accounts
  • Vulnerability scan reports with remediation tickets showing closure within your defined timelines
  • Backup job logs and the results of periodic restore tests
  • Audit log configuration and retention settings
  • Security awareness training completion records
  • A service provider inventory and the incident response plan with named roles

Mistakes that stall CIS programs

  • Targeting IG3 on day one. A 153-safeguard backlog overwhelms small teams. Finish IG1, then expand.
  • Scoring by policy instead of coverage. Having an MFA policy is not the safeguard; MFA enforced across the in-scope accounts is.
  • Inventories that drift. A one-time spreadsheet goes stale within weeks. Inventories need automated feeds and reconciliation.
  • Confusing Controls with Benchmarks. The CIS Benchmarks are configuration guides for specific products. Control 4 expects a secure configuration process, which Benchmarks can support.
  • Treating it as a certification. CIS alignment does not replace SOC 2 or ISO 27001 where customers require those, though it strengthens both.

How the CIS Controls map to other frameworks

CIS publishes mappings from the Controls to a range of frameworks, including NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, and PCI DSS. In practice, a CIS program gives you strong technical evidence for the operational controls of those frameworks, while they add the governance, risk assessment, and management system layers CIS does not emphasize. The evidence reuse article explains how to avoid collecting the same proof twice.

How Asurvo helps

Asurvo includes CIS Controls v8 with Implementation Group scoping, so you can filter the safeguard list to IG1, IG2, or IG3 and track progress against the target you choose. Native integrations with systems such as Okta, Entra ID, CrowdStrike, Defender, Wazuh, Qualys, and major cloud platforms feed inventory, configuration, and vulnerability evidence continuously, and AI cross-mapping links each safeguard to NIST CSF and ISO 27001. Teams starting out can pair it with the free access control policy template.

FAQ

Frequently asked questions

What is the difference between CIS Controls v8 and v8.1?

Version 8.1, released in June 2024, is a point update to version 8. It added Govern as a security function to align with NIST CSF 2.0, clarified safeguard descriptions and asset classes, and expanded the glossary. The 18-control structure and the Implementation Group model remain, so organizations aligned to v8 can adopt v8.1 by reviewing the changed safeguards.

Can you get certified against the CIS Controls?

No. The Center for Internet Security does not certify organizations against the Controls. Organizations demonstrate alignment through self-assessment, often using the CIS Controls Self Assessment Tool, or through a third-party review. If customers require a formal attestation, pair CIS with a certifiable framework such as ISO 27001 or a SOC 2 report.

Which Implementation Group should we target?

Start with IG1, which CIS defines as essential cyber hygiene and considers the minimum for every enterprise. Move to IG2 if you have dedicated IT staff, handle sensitive customer or company data, or run a more complex environment. IG3 suits organizations with security specialists, regulatory oversight, and a realistic exposure to targeted attacks.

How are the CIS Controls different from the CIS Benchmarks?

The CIS Controls are a prioritized set of security practices covering an entire organization, from asset inventory to penetration testing. The CIS Benchmarks are detailed secure configuration guides for specific technologies such as operating systems, cloud platforms, and applications. Benchmarks are a practical way to implement the secure configuration safeguards within the Controls.

Do the CIS Controls replace NIST CSF or ISO 27001?

Not usually. The CIS Controls are prescriptive technical safeguards, while NIST CSF describes outcomes and ISO 27001 defines a certifiable management system. Many organizations use CIS as the concrete how for the operational parts of those frameworks. CIS publishes mappings that make it straightforward to show where one safeguard supports another framework's requirement.

Ready to run CIS Controls on Asurvo?

Book a walkthrough and see the framework live.