Compliance · Framework & benchmarks

CIS Controls & Benchmarks — prioritized security safeguards

The most practical starting point in security — a prioritized list, in order.

The CIS Critical Security Controls are a prioritized set of safeguards, ordered so the things that stop the most attacks come first. Paired with CIS Benchmarks — hardened configuration baselines for specific technologies — they're the most actionable framework available, and they're free.

18

Controls (v8)

IG1–IG3

Implementation groups

100+

Benchmark technologies

What CIS gives you

Two distinct things that get conflated: a prioritized control framework, and hardening baselines.

The Controls (v8)

18 controls covering inventory, data protection, access, logging, and response — deliberately ordered by impact, so you can start at the top and work down.

Implementation Groups

IG1 is the basic cyber hygiene every organization should have. IG2 and IG3 add depth for organizations with more resources and more risk. It tells you what's realistic for your size.

The Benchmarks

Consensus hardening baselines for operating systems, cloud platforms, browsers, and databases — turning 'harden the server' into a specific, checkable configuration.

Who should use CIS

Anyone who needs to improve security fast and doesn't know where to start.

  • Organizations with no formal framework yet
  • Teams needing defensible hardening baselines
  • Companies whose insurer or customers reference CIS
  • Security teams that want measurable coverage, not vibes

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

IG selection

We determine the right implementation group for your size and risk so you don't over-commit or under-protect.

Control assessment

We measure current coverage safeguard by safeguard and produce a prioritized roadmap in CIS's own order.

Benchmark hardening

We apply CIS Benchmarks to your operating systems, cloud accounts, and databases — and handle the exceptions that break things.

Drift monitoring

We monitor for configuration drift so hardened stays hardened after the project ends.

Framework mapping

We map CIS coverage to SOC 2, ISO 27001, and HIPAA so one body of work serves several obligations.

Measurement

We report coverage over time, which is what turns security spend into a defensible story.

How the engagement runs

1

Choose your IG

Right-size the target to your organization.

2

Assess

Score current safeguard coverage.

3

Remediate in order

Work the prioritized list top-down.

4

Harden

Apply benchmarks and handle exceptions.

5

Monitor

Watch for drift and report coverage.

Frequently asked questions

Can you get 'CIS certified'?

Not in the way you can with ISO 27001. CIS is a framework and a set of benchmarks, not a certification scheme. You can be independently assessed against it, and CIS offers benchmark-conformance tooling, but there's no organizational CIS certificate. Its value is the prioritized roadmap.

CIS or NIST CSF?

They complement each other. NIST CSF is better for organizing and communicating a program at the executive level; CIS is better for telling engineers exactly what to do next, in order. Many organizations use CSF for structure and CIS for execution.

Are the CIS Benchmarks safe to apply as-is?

Not blindly — some settings break real applications. That's why benchmarks have profile levels and why exceptions must be documented rather than silently skipped. We test in staging, record deviations with justification, and keep the baseline defensible.

Where should we start?

IG1, top-down. Asset and software inventory first — because every later control depends on knowing what you have. Teams that jump to the interesting controls first almost always find they can't apply them consistently.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

CIS for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.