CIS CONTROLS
The controls are arranged by what tends to stop a real attack first, not by theme and not by what presents well. It is the most direct reference for anyone deciding where the next unit of budget goes, and it is the base that ISO 27001, SOC 2 and PCI DSS reuse when they arrive later.
The CIS Controls are a freely available technical reference maintained by the Center for Internet Security. DM11 measures your current state, implements in the order that cuts risk fastest, and files the evidence. If a certificate is the destination, that evidence is the beginning of it, and the page for the standard you choose explains the rest of the route.
Who runs the implementation
ISO/IEC 27001 Lead Auditor certified by BSI
CISA, information systems auditing
Vulnerability management with a Qualys Certified Specialist
17 years of governance, risk and compliance
WHAT IT IS
The CIS Controls are a set of security controls published by the Center for Internet Security, currently at version 8.1, released in June 2024. There are 18 controls and 153 safeguards, and the trait that separates them from everything else is the order: they are not listed by theme, they are listed by what tends to stop a real attack first.
CIS splits the safeguards into three implementation groups. IG1 holds 56 and is defined as essential cyber hygiene: the minimum any company should have against the most common attacks. IG2 adds 74 for more complex operations, and IG3 another 23 for organisations facing sophisticated attackers. Starting at IG1 holds for a company of any size.
The 2024 revision introduced the governance function and aligned the structure with NIST CSF 2.0. The change acknowledges something implementers already knew: a safeguard with no owner does not survive its third month. Before that, the framework said what to do without saying who answers for keeping it working.
Worth settling the expectation early, because it shapes the plan. What the work produces is a measured picture of your state, with coverage per control and the evidence behind it. There is a credential called CIS Controls Accreditation, and it applies to the service provider who implements or audits rather than to the company being measured. Where your customer needs a document issued by a third party, ISO 27001 or SOC 2 is what answers that, and the work done here carries into that project intact.
The CIS safeguards appear, under other names, inside ISO 27001, SOC 2 and PCI DSS. Asset inventory, access control, logging, tested backups and vulnerability management are required by all three. The evidence produced here is the same evidence an auditor will ask for later, which is why CIS is so often the first year of a certification project.
WHO USUALLY NEEDS IT
None of them involves anyone demanding a certificate. Where a certificate is being demanded, the route is different, and the page for the standard in question explains which.
The company grew, IT kept up as best it could, and nobody ever stopped to look at the whole. There is no external requirement yet, and there is the correct sense that luck is not a strategy. CIS answers the question this company is actually asking, which is where to start, not which standard to follow.
Here the priority order is the product. With limited money, the difference between spending on IG1's 56 safeguards and spending on the tool a vendor pitched last week is large, and it only becomes visible when somebody measures before buying.
A company far from the requirements should not open a certification project on day one: the audit costs the same whether you are close or far. Implementing CIS first shortens the distance, with evidence the audit will accept later.
STORIES
We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.
Manufacturing
Every department kept a list of equipment and none of them matched. There were servers running that nobody could account for, and shop-floor machines on unsupported operating systems that appeared on no list at all, because maintenance looked after them rather than IT.
We started at the beginning, which in the CIS Controls is literally control number one: an inventory of assets and software. We established what actually exists, through scanning and through conversation, and set an owner for each item. Only after that did we discuss any protection.
The inventory turned up considerably more equipment than the official list showed, and most of the difference sat outside IT. The two cheapest safeguards in the whole project were switching off what no longer served a purpose and isolating what could not be updated.
Retail and e-commerce
The copy routine had run without failing for years, with a green report every morning. Nobody had ever restored anything into a test environment, and the board's perception was that the availability risk was covered because the report said so.
We tested the restore for real, against a clock, which is what the safeguard asks for and almost nobody does. We found that a critical database was being copied with the service running, without consistency, and that a full restore would take far longer than the operation could absorb.
The green report was accurate and useless: the copy existed and would not come back. Once the method was fixed and the restore timed, the company knew how long it would be down, which was the figure the board needed in order to decide how much to invest.
Professional services
For convenience, almost every user held administrative rights on their own machine, and three people in IT shared the same domain administrator account. There was no record of who did what with it, so any incident investigation would end in a draw.
We split day-to-day accounts from administrative ones, made privileged access individual and turned on logging. We removed local administrative rights in waves, starting where friction was lowest, with a defined process for the legitimate exceptions rather than informal ones.
The expected resistance never came: the genuine exceptions were few and were granted. The bigger gain was the logging, because from then on there was an answer to who did what, a question that previously had no answer available.
HOW WE RUN IT
The measurement is worth what it costs in honesty. Scoring a safeguard here is binary, met or not met, with evidence attached, because a subjective score drifts upward on its own and turns the report into a document that pleases and decides nothing.
The first two controls are inventories of assets and of software, and the order is not accidental: you cannot protect what you do not know exists. We map equipment, systems, cloud services and third-party access, with a defined owner for each item.
An inventory of assets and software, with an owner per item
Cloud services and third-party access mapped
A list of what is unsupported or has no owner
The target implementation group agreed with the board
Delivery milestoneInventory closed and reconciled against what IT had on record.
We score safeguard by safeguard, starting with IG1's 56, with evidence required for every positive answer. The result is a number, and the number exists to be moved later, not to decorate a presentation.
A score per safeguard, with evidence attached
Coverage by control and by implementation group
Gaps ordered by risk and by effort
An estimate of what is quick and cheap, kept separate from what needs investment
Delivery milestoneCurrent state measured and approved by the board, with no positive answer lacking evidence.
We implement alongside your team, following the order the measurement produced rather than the order of the numbering. Each safeguard gets an owner, a date, and a definition of what will serve as proof that it works, which is what separates it from a task marked done.
A plan with an owner and a date per safeguard
Implementation alongside your team or your IT provider
Evidence defined and filed for every safeguard closed
Adjustments to the IT contract where operations are outsourced
Delivery milestoneThe highest-risk safeguards closed, with the evidence filed.
We measure again using the same method, so the number is comparable. Where there is an intention to certify later, we organise the evidence in the form the chosen standard will ask for, so the work done here carries into the next project instead of being redone.
A second measurement, comparable to the first
A progress report for the board, free of jargon
Evidence organised in the form the intended standard expects
A maintenance routine defined, with who reviews and when
Delivery milestoneProgress demonstrated using the same method as the initial measurement.
HOW LONG IT TAKES
We do not publish a standard timeline, because a published timeline turns into a promise. The initial measurement is usually the short part; implementation is the part that varies. These are the three factors that move the clock most, and the first conversation already shows which one your company is in.
A company with a current inventory starts measuring in the first week. A company without one spends much of the start discovering what it has, and that discovery almost always turns up more equipment than the official list showed.
Closing IG1 is a project with a visible end. Moving on to IG2 adds 74 safeguards aimed at more complex operations, and IG3 is for organisations facing targeted attacks. Most companies gain more by closing IG1 entirely than by opening fronts across all three.
With an internal team, implementation moves at the pace of their calendar. With IT outsourced, a good share of the safeguards depends on the provider, and some require the contract to change. That conversation starts early in the project, because it tends to be the slowest one.
FREQUENTLY ASKED
The questions that come up in almost every first meeting, answered straight.
Not for your company. The Center for Internet Security maintains a credential called CIS Controls Accreditation, but it applies to the service provider who implements or audits the controls, not to the company being measured. If what you need is a document to send a customer, CIS alone does not solve it, and ISO 27001 or SOC 2 are worth looking at. What CIS delivers is your real state, measured, which is usually what is missing in order to decide the rest.
A measurement against the first group's safeguards gives you a picture of the current state and the order of what to do first. It is the cheapest possible start, and it serves both the company that simply wants to stop being an easy target and the one that will certify later.