About this Framework
The CIS Controls v8 is a prioritised set of 18 security best practices addressing today's most pervasive cyberattacks, organised into three Implementation Groups (IG1–IG3) by organisational risk profile. Over 153 safeguards cover asset inventory, data protection, secure configuration, access management, email security, application security and penetration testing. Freely available and mapped to NIST CSF, ISO 27001 and PCI DSS.
Key Control Domains
Inventory & Control of Assets
Data Protection
Secure Configuration
Account Management
Access Control
Vulnerability Management
Audit Log Management
Email & Browser Protection
Malware Defenses
Network Monitoring
Security Awareness Training
Application Software Security
Incident Response
Penetration Testing
Who Needs This?
- Small businesses (IG1 cyber hygiene baseline)
- Mid-market organisations (IG2)
- Large enterprises and high-risk sectors (IG3)
- Any organisation building a practical cybersecurity program
Compliance Benefits
- Prescriptive and immediately actionable controls
- Free to use — no licensing fees
- Phased adoption via Implementation Groups
- Maps to all major compliance frameworks
Official Reference
CIS Controls Official Page
https://www.cisecurity.org/controls
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/center-for-internet-security-cis-controls-v8