Skip to content
DM11AI TRUST & IT RISK PROTECTION
StandardsProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • SastAction®
  • NosConformes®
  • Cyber Antifrágil®
  • All products

Company

  • About Us
  • Case Studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000
  • Standards and certifications
  • Comparisons between standards

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. CIS CONTROLS
  3. CIS Controls implementation

CIS CONTROLS

The list that tells you where to start, in priority order

The controls are arranged by what tends to stop a real attack first, not by theme and not by what presents well. It is the most direct reference for anyone deciding where the next unit of budget goes, and it is the base that ISO 27001, SOC 2 and PCI DSS reuse when they arrive later.

Talk to a specialistSee the other standards

The CIS Controls are a freely available technical reference maintained by the Center for Internet Security. DM11 measures your current state, implements in the order that cuts risk fastest, and files the evidence. If a certificate is the destination, that evidence is the beginning of it, and the page for the standard you choose explains the rest of the route.

Who runs the implementation

  • ISO/IEC 27001 Lead Auditor certified by BSI

  • CISA, information systems auditing

  • Vulnerability management with a Qualys Certified Specialist

  • 17 years of governance, risk and compliance

WHAT IT IS

A list with an order, kept by people who respond to incidents

The CIS Controls are a set of security controls published by the Center for Internet Security, currently at version 8.1, released in June 2024. There are 18 controls and 153 safeguards, and the trait that separates them from everything else is the order: they are not listed by theme, they are listed by what tends to stop a real attack first.

The first group is 56 safeguards

CIS splits the safeguards into three implementation groups. IG1 holds 56 and is defined as essential cyber hygiene: the minimum any company should have against the most common attacks. IG2 adds 74 for more complex operations, and IG3 another 23 for organisations facing sophisticated attackers. Starting at IG1 holds for a company of any size.

Version 8.1 added governing

The 2024 revision introduced the governance function and aligned the structure with NIST CSF 2.0. The change acknowledges something implementers already knew: a safeguard with no owner does not survive its third month. Before that, the framework said what to do without saying who answers for keeping it working.

How the CIS result is presented

Worth settling the expectation early, because it shapes the plan. What the work produces is a measured picture of your state, with coverage per control and the evidence behind it. There is a credential called CIS Controls Accreditation, and it applies to the service provider who implements or audits rather than to the company being measured. Where your customer needs a document issued by a third party, ISO 27001 or SOC 2 is what answers that, and the work done here carries into that project intact.

The work is not wasted if a certification follows

The CIS safeguards appear, under other names, inside ISO 27001, SOC 2 and PCI DSS. Asset inventory, access control, logging, tested backups and vulnerability management are required by all three. The evidence produced here is the same evidence an auditor will ask for later, which is why CIS is so often the first year of a certification project.

WHO USUALLY NEEDS IT

Three situations where starting with CIS is the right call

None of them involves anyone demanding a certificate. Where a certificate is being demanded, the route is different, and the page for the standard in question explains which.

Nothing structured has ever been done

The company grew, IT kept up as best it could, and nobody ever stopped to look at the whole. There is no external requirement yet, and there is the correct sense that luck is not a strategy. CIS answers the question this company is actually asking, which is where to start, not which standard to follow.

The budget is small and the board wants to know where to spend it

Here the priority order is the product. With limited money, the difference between spending on IG1's 56 safeguards and spending on the tool a vendor pitched last week is large, and it only becomes visible when somebody measures before buying.

Certification is a year away and the distance is long

A company far from the requirements should not open a certification project on day one: the audit costs the same whether you are close or far. Implementing CIS first shortens the distance, with evidence the audit will accept later.

STORIES

Three situations we have already worked through

We change our clients' names with the same confidentiality that will protect your company later. The names change; the pattern of the problems repeats. Where a client agrees, we give named references in a conversation.

Manufacturing

The machine count never added up

Situation

Every department kept a list of equipment and none of them matched. There were servers running that nobody could account for, and shop-floor machines on unsupported operating systems that appeared on no list at all, because maintenance looked after them rather than IT.

What we did

We started at the beginning, which in the CIS Controls is literally control number one: an inventory of assets and software. We established what actually exists, through scanning and through conversation, and set an owner for each item. Only after that did we discuss any protection.

Outcome

The inventory turned up considerably more equipment than the official list showed, and most of the difference sat outside IT. The two cheapest safeguards in the whole project were switching off what no longer served a purpose and isolating what could not be updated.

Retail and e-commerce

The backup ran every day and had never been restored

Situation

The copy routine had run without failing for years, with a green report every morning. Nobody had ever restored anything into a test environment, and the board's perception was that the availability risk was covered because the report said so.

What we did

We tested the restore for real, against a clock, which is what the safeguard asks for and almost nobody does. We found that a critical database was being copied with the service running, without consistency, and that a full restore would take far longer than the operation could absorb.

Outcome

The green report was accurate and useless: the copy existed and would not come back. Once the method was fixed and the restore timed, the company knew how long it would be down, which was the figure the board needed in order to decide how much to invest.

Professional services

Everyone was an administrator

Situation

For convenience, almost every user held administrative rights on their own machine, and three people in IT shared the same domain administrator account. There was no record of who did what with it, so any incident investigation would end in a draw.

What we did

We split day-to-day accounts from administrative ones, made privileged access individual and turned on logging. We removed local administrative rights in waves, starting where friction was lowest, with a defined process for the legitimate exceptions rather than informal ones.

Outcome

The expected resistance never came: the genuine exceptions were few and were granted. The bigger gain was the logging, because from then on there was an answer to who did what, a question that previously had no answer available.

HOW WE RUN IT

Measure, prioritise, implement, then measure again

The measurement is worth what it costs in honesty. Scoring a safeguard here is binary, met or not met, with evidence attached, because a subjective score drifts upward on its own and turns the report into a document that pleases and decides nothing.

  1. 01

    Inventory: what exists, before protecting it

    The first two controls are inventories of assets and of software, and the order is not accidental: you cannot protect what you do not know exists. We map equipment, systems, cloud services and third-party access, with a defined owner for each item.

    • An inventory of assets and software, with an owner per item

    • Cloud services and third-party access mapped

    • A list of what is unsupported or has no owner

    • The target implementation group agreed with the board

    Delivery milestoneInventory closed and reconciled against what IT had on record.

  2. 02

    Measurement against the safeguards

    We score safeguard by safeguard, starting with IG1's 56, with evidence required for every positive answer. The result is a number, and the number exists to be moved later, not to decorate a presentation.

    • A score per safeguard, with evidence attached

    • Coverage by control and by implementation group

    • Gaps ordered by risk and by effort

    • An estimate of what is quick and cheap, kept separate from what needs investment

    Delivery milestoneCurrent state measured and approved by the board, with no positive answer lacking evidence.

  3. 03

    Implementation in the order that cuts risk fastest

    We implement alongside your team, following the order the measurement produced rather than the order of the numbering. Each safeguard gets an owner, a date, and a definition of what will serve as proof that it works, which is what separates it from a task marked done.

    • A plan with an owner and a date per safeguard

    • Implementation alongside your team or your IT provider

    • Evidence defined and filed for every safeguard closed

    • Adjustments to the IT contract where operations are outsourced

    Delivery milestoneThe highest-risk safeguards closed, with the evidence filed.

  4. 04

    Re-measurement and the route to certification

    We measure again using the same method, so the number is comparable. Where there is an intention to certify later, we organise the evidence in the form the chosen standard will ask for, so the work done here carries into the next project instead of being redone.

    • A second measurement, comparable to the first

    • A progress report for the board, free of jargon

    • Evidence organised in the form the intended standard expects

    • A maintenance routine defined, with who reviews and when

    Delivery milestoneProgress demonstrated using the same method as the initial measurement.

HOW LONG IT TAKES

It depends on the size of the estate and on who runs IT

We do not publish a standard timeline, because a published timeline turns into a promise. The initial measurement is usually the short part; implementation is the part that varies. These are the three factors that move the clock most, and the first conversation already shows which one your company is in.

How many assets, and whether anyone knows how many

A company with a current inventory starts measuring in the first week. A company without one spends much of the start discovering what it has, and that discovery almost always turns up more equipment than the official list showed.

Which implementation group you are aiming at

Closing IG1 is a project with a visible end. Moving on to IG2 adds 74 safeguards aimed at more complex operations, and IG3 is for organisations facing targeted attacks. Most companies gain more by closing IG1 entirely than by opening fronts across all three.

Who runs IT day to day

With an internal team, implementation moves at the pace of their calendar. With IT outsourced, a good share of the safeguards depends on the provider, and some require the contract to change. That conversation starts early in the project, because it tends to be the slowest one.

FREQUENTLY ASKED

What people ask before deciding

The questions that come up in almost every first meeting, answered straight.

Not for your company. The Center for Internet Security maintains a credential called CIS Controls Accreditation, but it applies to the service provider who implements or audits the controls, not to the company being measured. If what you need is a document to send a customer, CIS alone does not solve it, and ISO 27001 or SOC 2 are worth looking at. What CIS delivers is your real state, measured, which is usually what is missing in order to decide the rest.

Want to know where your company actually stands?

A measurement against the first group's safeguards gives you a picture of the current state and the order of what to do first. It is the cheapest possible start, and it serves both the company that simply wants to stop being an easy target and the one that will certify later.

Talk to a specialist

Comparisons on this subject

  • CIS Controls vs ISO 27001
  • ISO 27001 vs NIST CSF
See all 13 comparisons