Frameworks

CIS Controls, by implementation group.

The CIS Controls tell you what to do first. TruOps tells you how far you have gotten, safeguard by safeguard.

CIS Controls · readinessevidence current
CIS Controls · coverage by implementation group
IG1 · essential hygienesatisfied · 87%
IG2partial · 66%
IG3open · 15%
The same work also counts toward
NIST CSF69% · partials shown
ISO 2700155% · partials shown
SOC 257% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The CIS Critical Security Controls, maintained by the Center for Internet Security, are a prioritized set of 18 controls containing 153 safeguards in version 8.1. Safeguards are divided into three Implementation Groups: IG1 is essential cyber hygiene for every organization, and IG2 and IG3 add safeguards for organizations with more complex environments and higher risk.

This page is for you if
  • You picked CIS as the practical list and still cannot say which IG you actually meet
  • Safeguards that are technical are still attested in a spreadsheet
  • Leadership wants a prioritized roadmap, not 153 greens and reds
Maintained by
Center for Internet Security
Current version
v8.1
Structure
18 controls, 153 safeguards
Implementation groups
IG1 · IG2 · IG3

Implementation groups

GroupWho it is for
IG1Essential cyber hygiene; the minimum for every organization
IG2Organizations with more IT staff, sensitive data, and multiple departments
IG3Organizations facing sophisticated attacks or with sensitive data and regulatory oversight

The actual challenge

CIS is a priority order. Programs that treat all 18 controls as a flat audit lose the point: IG1 first, then the rest, with technical safeguards checked from tools you already own.

  • IG1 was never scored separately from IG2/IG3.
  • Asset inventory, MFA, and vuln management are in tools; the CIS assessment does not read them.
  • The same safeguards map to CSF and ISO and are evidenced again.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts CIS Controls from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

How TruOps helps with the CIS Controls

Pick the CIS Controls as your anchor, or map it to the framework you already run. TruOps keeps the CIS Controls' own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your CIS Controls assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

Many CIS safeguards, such as asset inventory, MFA, and vulnerability management, can be checked directly from connected tools.

If this is your situation

Bring a CIS self-assessment. TruOps scores by implementation group and checks the technical safeguards from connected tools.

How TruOps helps

Anchor or map
Run CIS Controls as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your CIS Controls assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

How many CIS Controls are there?

Eighteen controls with 153 safeguards in version 8.1.

What is CIS IG1?

Implementation Group 1, the set of safeguards CIS describes as essential cyber hygiene for every organization.

Does TruOps include a CIS assessment?

Yes. CIS assessments are available as starting points and can be scored by implementation group.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.