Security baselines · GlobalCIS Controls
CIS Critical Security Controls v8
A prioritised set of eighteen controls and their safeguards, ordered by the attacks they stop, with Implementation Groups for phasing.
18
controls
153
safeguards
IG1-3
phasing
CIS v8
Asset inventory
Data protection
Secure configuration
Account management
Access control
Vulnerability mgmt
Audit logging
Key controls
Why it matters
The fastest way to a defensible baseline, and a common bridge that maps into ISO 27001, NIST CSF and PCI DSS.
Who it's for
Any organisation that wants a prioritised, prescriptive starting point for cyber defence.
The journey
How you get to CIS Controls
- 1InventoryAssets and software
- 2Pick an IGImplementation group
- 3Gap assessmentAgainst the safeguards
- 4ImplementBy priority
- 5MeasureSafeguard coverage
- 6ImproveMove up the IGs
On Compliverse
CIS Controls, worked in the platform
Get the evidence you need
The AI recommends which evidence answers each CIS Controls control, ready to confirm.
See what's missing
Gaps and missing artifacts surface on their own, not the week of the audit.
Create from templates
Spin up policies, assessments and charters from standard templates, then tailor them to your scope.
Collected once, reused
One artifact satisfies this framework and every other it maps to.
Get CIS Controls-ready on your own stack.
Demos are scoped to your frameworks. Pick a slot and we'll run CIS Controls live.