Frameworks
CIS Critical Security Controls v8.1
The prioritized to-do list of security — start where attacks actually happen.
Book a demoThe CIS Controls answer the practitioner's question every framework dodges: what should we do first? Eighteen controls, ordered by attack relevance, split into implementation groups so a ten-person startup and a bank both know their next move.
Implementation groups keep it honest
IG1 is essential cyber hygiene — 56 safeguards every organization needs, from asset inventory to MFA. IG2 layers on controls for teams managing sensitive data at scale; IG3 completes the set for mature, targeted enterprises. You adopt the group that matches your reality, then grow.
The perfect companion framework
CIS Controls are prescriptive where CSF is descriptive and audits are retrospective. Teams commonly run CIS as the engineering checklist while presenting posture through CSF and attesting through SOC 2 or ISO 27001 — three views of the same underlying work.
How Compriska helps
Compriska tracks safeguard implementation by group, evidences each one, and cross-maps CIS safeguards to every other framework you run — so hardening work done by engineering shows up instantly in audit readiness.
Frequently asked questions
Where should a small company start with CIS Controls?
IG1, without hesitation — its 56 safeguards are explicitly designed as the minimum standard of hygiene and block the commodity attacks that cause most breaches.
Other frameworks
Automate CIS Controls with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo