Skip to main content
FRAMEWORK

18 controls. Three Implementation Groups. One mapping.

CIS Controls v8 is the most practical list in this catalog. Eighteen controls, each broken into safeguards, ordered so that the ones that stop the most common attacks come first. It is not a regulation and not a certification — it is a prioritized answer to the question every small security team actually asks, which is what to do next.

That practicality is also where it gets lost. The list is easy to agree with and easy to leave in a spreadsheet, reviewed annually, drifting quietly out of date. A safeguard that was true in March and false in September is not a safeguard; it is a note about March.

Who it applies to

Any organization, by choice. CIS is a non-profit and the Controls are free to adopt, which is why they show up as the de facto baseline for teams without a regulator telling them what to do, and as the crosswalk reference for teams who have several. Insurers and customers increasingly ask about them by name for the same reason: the list is specific enough to answer honestly.

Implementation Groups, not maturity levels

The three Implementation Groups are the most commonly misread part of the framework. They are not maturity tiers you graduate through by doing the same things better — they define which safeguards apply to you, and they are cumulative. IG1 is the set CIS describes as essential cyber hygiene: the floor for every organization, including the smallest. IG2 and IG3 add safeguards as the sensitivity of what you hold and the sophistication of who wants it go up. Choosing your group is a risk decision, and it is one you should be able to justify later — which means recording why, not just what.

What it asks, in operating terms

Read as an operating requirement rather than a checklist, the Controls reduce to a handful of standing asks — each answerable from live state, not from last quarter's spreadsheet.

CIS Controls requirements · how TruSecure answers them
What CIS asksWhere it is answered
Pick an Implementation Group, and justify itRisk management · the decision and its rationale, dated
Know your assets and software before defending themAsset register · one record every framework reads
Show each safeguard is in place now, not in MarchControl library · continuously monitored
Carry the safeguards you have not met honestlyExceptions · owned, dated, re-reviewed on expiry
Reuse the same evidence for ISO 27001 and CSFShared control library · mapped once, cited by each

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a safeguard file is made of:

CIS Controls file · excerptSample data
Implementation Group
IG2 · rationale recorded
Controls covered
18/18 · safeguards scoped to IG2
Evidence freshness
continuous · provenance tracked
Open exceptions
2 · each with an owner and an expiry
Export
sealed · sha256:4f88...b1c7

Where teams usually start

With a demo walked through by TruSecure — your Implementation Group scoped against controls you already operate, a single safeguard opened to its evidence, the same evidence answering ISO 27001 and CSF without being collected twice. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

CIS Controls v8 is a set of 18 prioritized cybersecurity safeguards organized into three Implementation Groups scaled by organizational size and risk. TruSecure maps CIS safeguards into the same control library used across every other framework it supports.