Framework · International

CIS Controls v8, without the spreadsheets.

Start with the safeguards that stop the most common attacks.

What is CIS Controls v8?

The CIS Critical Security Controls are a prioritised set of safeguards against the most common attacks. Implementation Groups let smaller teams start with essential cyber hygiene (IG1) and grow into IG2 and IG3 as their risk and resources increase.

Who needs it

  • Small teams that want a practical first security baseline
  • Organisations whose cyber insurers reference CIS
  • Teams that want to prioritise before pursuing a certification

What CIS Controls v8 looks at

Inventory

Know your enterprise assets and software (Controls 1 and 2).

Data and configuration

Data protection and secure configuration of assets and software.

Accounts and access

Account management and access control management.

Vulnerabilities and malware

Continuous vulnerability management and malware defences.

How Beviso gets you there

  • Controls evaluated against device inventory from MDM and endpoint tools
  • Vulnerability evidence from scanners and code security tools
  • A path from CIS to ISO 27001 or SOC 2 using the same evidence

13 CIS Controls v8 controls, ready on day one

These controls are loaded when you enable CIS Controls v8, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

CIS.1

Inventory and Control of Enterprise Assets

Actively manage all enterprise assets connected to the infrastructure to accurately know the totality of assets.

Evidence from

  • Jamf
  • Kandji
  • Mosyle
  • SentinelOne
  • DigitalOcean
  • Hetzner
  • AWS

CIS.2

Inventory and Control of Software Assets

Actively manage all software on the network so only authorized software is installed and executed.

Evidence from

  • GitHub
  • GitLab
  • Snyk
  • Heroku
  • Render
  • Vercel

CIS.3

Data Protection

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.

Evidence from

  • HashiCorp Vault
  • Doppler
  • Bitwarden
  • 1Password
  • Notion

CIS.4

Secure Configuration of Enterprise Assets

Establish and maintain the secure configuration of enterprise assets.

Evidence from

  • Terraform Cloud
  • AWS
  • Microsoft Azure
  • Doppler
  • GitHub
  • Jamf

CIS.5

Account Management

Use processes and tools to assign and manage authorization to credentials for user accounts including admin accounts.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • JumpCloud
  • AWS
  • GitHub
  • OneLogin

CIS.6

Access Control Management

Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, admin, and service accounts.

Evidence from

  • Okta
  • AWS
  • HashiCorp Vault
  • GitHub
  • Cloudflare
  • Microsoft Azure

CIS.7

Continuous Vulnerability Management

Develop a plan to continuously assess and track vulnerabilities on all enterprise assets.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • Lacework
  • GitHub
  • SonarCloud

CIS.8

Audit Log Management

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.

Evidence from

  • Datadog
  • AWS
  • Splunk
  • Okta
  • HashiCorp Vault
  • Salesforce
  • Dynatrace

CIS.9

Email and Web Browser Protections

Improve protections and detection of threats from email and web vectors.

Evidence from

  • Cloudflare
  • CrowdStrike
  • SentinelOne

CIS.12

Network Infrastructure Management

Establish, implement, and actively manage network devices to prevent attackers from exploiting vulnerable services.

Evidence from

  • Cloudflare
  • DigitalOcean
  • Hetzner
  • AWS

CIS.13

Network Monitoring and Defense

Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats.

Evidence from

  • Datadog
  • Grafana
  • New Relic
  • Splunk
  • AWS
  • Lacework

CIS.16

Application Software Security

Manage the security life cycle of in-house developed, hosted, or acquired software to prevent, detect, and remediate security weaknesses.

Evidence from

  • Snyk
  • SonarCloud
  • Veracode
  • GitHub
  • GitLab
  • HackerOne

CIS.17

Incident Response Management

Establish a program to develop and maintain an incident response capability to prepare, detect, contain, and recover from attacks.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira
  • CrowdStrike

CIS Controls v8 questions

What is IG1?
Implementation Group 1 is the essential cyber hygiene baseline — the safeguards every organisation should have, whatever its size.

Start your CIS Controls v8 programme today.

Free while Beviso is in beta. No credit card required.

Get started free