A complete controls-audit covering all 18 CIS Critical Security Controls v8.1 (153 safeguards), cross-mapped to NIST CSF 2.0 and ISO/IEC 27001:2022. Mark each item's status to score implementation. Filter by Implementation Group to scope the assessment to an organization's maturity.
Assessment metadata:
| Organization assessed | Click to enter… |
| Assessment date | Click to enter… |
| Lead auditor | Click to enter… |
| Target Implementation Group | IG1 / IG2 / IG3 |
How the CIS Controls families in this checklist align to NIST CSF 2.0 Functions and ISO/IEC 27001:2022 Annex A themes.
| CIS v8.1 controls | NIST CSF 2.0 | ISO 27001:2022 Annex A |
|---|---|---|
| 1, 2 — Asset & software inventory | Identify (ID.AM) | A.5.9–A.5.10, A.8.1, A.8.19 |
| 3 — Data protection | Protect (PR.DS) | A.5.12–A.5.14, A.8.10–A.8.12, A.8.24 |
| 4 — Secure configuration | Protect (PR.PS) | A.8.9, A.8.20–A.8.22 |
| 5, 6 — Account & access control | Protect (PR.AA) | A.5.15–A.5.18, A.8.2–A.8.5 |
| 7 — Vulnerability management | Identify / Protect (ID.RA, PR.PS) | A.8.8 |
| 8 — Audit log management | Detect (DE.CM/AE) | A.8.15–A.8.17 |
| 9, 10 — Email/web & malware | Protect (PR.PS, PR.DS) | A.8.7, A.8.23 |
| 11 — Data recovery | Recover (RC.RP) | A.8.13–A.8.14 |
| 12, 13 — Network mgmt & monitoring | Protect / Detect (PR.IR, DE.CM) | A.8.20–A.8.22, A.8.16 |
| 14 — Awareness & training | Protect (PR.AT) | A.6.3 |
| 15 — Service provider mgmt | Govern (GV.SC) | A.5.19–A.5.23 |
| 16 — Application security | Protect (PR.PS) | A.8.25–A.8.29 |
| 17 — Incident response | Respond (RS.*) | A.5.24–A.5.28 |
| 18 — Penetration testing | Identify (ID.RA) | A.8.29, A.5.36 |