Dr. Vianney C.Cybersecurity Advisory
CIS Controls v8.1 — all 18 NIST CSF 2.0 ISO 27001:2022

Cybersecurity Audit Checklist

A complete controls-audit covering all 18 CIS Critical Security Controls v8.1 (153 safeguards), cross-mapped to NIST CSF 2.0 and ISO/IEC 27001:2022. Mark each item's status to score implementation. Filter by Implementation Group to scope the assessment to an organization's maturity.

Scope:
0%
0Implemented
0In progress
0Not started
0N/A
0Applicable
Implemented In progress Not started N/A

AScoring & assessment notes

Score = Implemented ÷ Applicable (excludes items marked N/A). Aim for 100% of the selected Implementation Group before advancing to the next.
IG1 is essential cyber hygiene for every organization. IG2 adds controls for those handling sensitive data. IG3 is for mature organizations facing targeted threats. Each group includes the ones below it.
Evidence. For a defensible audit, attach evidence (config export, policy doc, screenshot, ticket) to each "Implemented" item in your workpapers.

Assessment metadata:

Organization assessedClick to enter…
Assessment dateClick to enter…
Lead auditorClick to enter…
Target Implementation GroupIG1 / IG2 / IG3

BFramework crosswalk

How the CIS Controls families in this checklist align to NIST CSF 2.0 Functions and ISO/IEC 27001:2022 Annex A themes.

CIS v8.1 controlsNIST CSF 2.0ISO 27001:2022 Annex A
1, 2 — Asset & software inventoryIdentify (ID.AM)A.5.9–A.5.10, A.8.1, A.8.19
3 — Data protectionProtect (PR.DS)A.5.12–A.5.14, A.8.10–A.8.12, A.8.24
4 — Secure configurationProtect (PR.PS)A.8.9, A.8.20–A.8.22
5, 6 — Account & access controlProtect (PR.AA)A.5.15–A.5.18, A.8.2–A.8.5
7 — Vulnerability managementIdentify / Protect (ID.RA, PR.PS)A.8.8
8 — Audit log managementDetect (DE.CM/AE)A.8.15–A.8.17
9, 10 — Email/web & malwareProtect (PR.PS, PR.DS)A.8.7, A.8.23
11 — Data recoveryRecover (RC.RP)A.8.13–A.8.14
12, 13 — Network mgmt & monitoringProtect / Detect (PR.IR, DE.CM)A.8.20–A.8.22, A.8.16
14 — Awareness & trainingProtect (PR.AT)A.6.3
15 — Service provider mgmtGovern (GV.SC)A.5.19–A.5.23
16 — Application securityProtect (PR.PS)A.8.25–A.8.29
17 — Incident responseRespond (RS.*)A.5.24–A.5.28
18 — Penetration testingIdentify (ID.RA)A.8.29, A.5.36
Checklist items are authored to reflect the intent of the CIS v8.1 safeguards for audit use; consult the official CIS Controls v8.1 for verbatim safeguard text and IG assignments.