CIS Controls, by implementation group.
The CIS Controls tell you what to do first. TruOps tells you how far you have gotten, safeguard by safeguard.
Mappings are typed exact, partial, or inferred, each with a citation.
The CIS Critical Security Controls, maintained by the Center for Internet Security, are a prioritized set of 18 controls containing 153 safeguards in version 8.1. Safeguards are divided into three Implementation Groups: IG1 is essential cyber hygiene for every organization, and IG2 and IG3 add safeguards for organizations with more complex environments and higher risk.
- You picked CIS as the practical list and still cannot say which IG you actually meet
- Safeguards that are technical are still attested in a spreadsheet
- Leadership wants a prioritized roadmap, not 153 greens and reds
- Maintained by
- Center for Internet Security
- Current version
- v8.1
- Structure
- 18 controls, 153 safeguards
- Implementation groups
- IG1 · IG2 · IG3
Implementation groups
| Group | Who it is for |
|---|---|
| IG1 | Essential cyber hygiene; the minimum for every organization |
| IG2 | Organizations with more IT staff, sensitive data, and multiple departments |
| IG3 | Organizations facing sophisticated attacks or with sensitive data and regulatory oversight |
The actual challenge
CIS is a priority order. Programs that treat all 18 controls as a flat audit lose the point: IG1 first, then the rest, with technical safeguards checked from tools you already own.
- IG1 was never scored separately from IG2/IG3.
- Asset inventory, MFA, and vuln management are in tools; the CIS assessment does not read them.
- The same safeguards map to CSF and ISO and are evidenced again.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts CIS Controls from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
How TruOps helps with the CIS Controls
Pick the CIS Controls as your anchor, or map it to the framework you already run. TruOps keeps the CIS Controls' own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your CIS Controls assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
Many CIS safeguards, such as asset inventory, MFA, and vulnerability management, can be checked directly from connected tools.
If this is your situation
Bring a CIS self-assessment. TruOps scores by implementation group and checks the technical safeguards from connected tools.
How TruOps helps
- Anchor or map
- Run CIS Controls as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your CIS Controls assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
How many CIS Controls are there?
Eighteen controls with 153 safeguards in version 8.1.
What is CIS IG1?
Implementation Group 1, the set of safeguards CIS describes as essential cyber hygiene for every organization.
Does TruOps include a CIS assessment?
Yes. CIS assessments are available as starting points and can be scored by implementation group.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
Related
Govern, Identify, Protect, Detect, Respond, Recover, with maturity scoring.
→LearnMaturity assessmentScoring how capable a program is, not just whether it passes.
→IndustriesManufacturingDefense supply chains, plant networks, and supplier risk.
→IndustriesHigher educationResearch data, student records, and decentralized IT.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.