CIS Controls v8, without the spreadsheets.
Start with the safeguards that stop the most common attacks.
What is CIS Controls v8?
The CIS Critical Security Controls are a prioritised set of safeguards against the most common attacks. Implementation Groups let smaller teams start with essential cyber hygiene (IG1) and grow into IG2 and IG3 as their risk and resources increase.
Who needs it
- Small teams that want a practical first security baseline
- Organisations whose cyber insurers reference CIS
- Teams that want to prioritise before pursuing a certification
What CIS Controls v8 looks at
Inventory
Know your enterprise assets and software (Controls 1 and 2).
Data and configuration
Data protection and secure configuration of assets and software.
Accounts and access
Account management and access control management.
Vulnerabilities and malware
Continuous vulnerability management and malware defences.
How Beviso gets you there
- Controls evaluated against device inventory from MDM and endpoint tools
- Vulnerability evidence from scanners and code security tools
- A path from CIS to ISO 27001 or SOC 2 using the same evidence
13 CIS Controls v8 controls, ready on day one
These controls are loaded when you enable CIS Controls v8, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
CIS.1
Inventory and Control of Enterprise Assets
Actively manage all enterprise assets connected to the infrastructure to accurately know the totality of assets.
Evidence from
- Jamf
- Kandji
- Mosyle
- SentinelOne
- DigitalOcean
- Hetzner
- AWS
CIS.2
Inventory and Control of Software Assets
Actively manage all software on the network so only authorized software is installed and executed.
Evidence from
- GitHub
- GitLab
- Snyk
- Heroku
- Render
- Vercel
CIS.3
Data Protection
Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.
Evidence from
- HashiCorp Vault
- Doppler
- Bitwarden
- 1Password
- Notion
CIS.4
Secure Configuration of Enterprise Assets
Establish and maintain the secure configuration of enterprise assets.
Evidence from
- Terraform Cloud
- AWS
- Microsoft Azure
- Doppler
- GitHub
- Jamf
CIS.5
Account Management
Use processes and tools to assign and manage authorization to credentials for user accounts including admin accounts.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- JumpCloud
- AWS
- GitHub
- OneLogin
CIS.6
Access Control Management
Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, admin, and service accounts.
Evidence from
- Okta
- AWS
- HashiCorp Vault
- GitHub
- Cloudflare
- Microsoft Azure
CIS.7
Continuous Vulnerability Management
Develop a plan to continuously assess and track vulnerabilities on all enterprise assets.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- Lacework
- GitHub
- SonarCloud
CIS.8
Audit Log Management
Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.
Evidence from
- Datadog
- AWS
- Splunk
- Okta
- HashiCorp Vault
- Salesforce
- Dynatrace
CIS.9
Email and Web Browser Protections
Improve protections and detection of threats from email and web vectors.
Evidence from
- Cloudflare
- CrowdStrike
- SentinelOne
CIS.12
Network Infrastructure Management
Establish, implement, and actively manage network devices to prevent attackers from exploiting vulnerable services.
Evidence from
- Cloudflare
- DigitalOcean
- Hetzner
- AWS
CIS.13
Network Monitoring and Defense
Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats.
Evidence from
- Datadog
- Grafana
- New Relic
- Splunk
- AWS
- Lacework
CIS.16
Application Software Security
Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses.
Evidence from
- Snyk
- SonarCloud
- Veracode
- GitHub
- GitLab
- HackerOne
CIS.17
Incident Response Management
Establish a program to develop and maintain an incident response capability to prepare, detect, contain, and recover from attacks.
Evidence from
- PagerDuty
- ServiceNow
- Jira
- CrowdStrike
CIS Controls v8 questions
- What is IG1?
- Implementation Group 1 is the essential cyber hygiene baseline — the safeguards every organisation should have, whatever its size.
Often run alongside CIS Controls v8
NIST CSF 2.0
Measure and improve your security programme against a common language.
ISO 27001
Build an information security management system an auditor will certify.
SOC 2
Give US customers the SOC 2 report their procurement team asks for.
NIST 800-53
Work from the control catalogue behind US federal security.
Start your CIS Controls v8 programme today.
Free while Beviso is in beta. No credit card required.
Get started free