CIS ControlsSecurityGlobalAll Industries

Center for Internet Security Critical Security Controls

Prioritized set of actions to protect organizations from known cyber attack vectors. Adopted by numerous organizations as a practical security framework.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

CIS ControlsControl 3Retention and availability

Data Protection

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.

Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.

CIS ControlsControl 6Least privilege and privileged useAttribution to an individual

Access Control Management

Use processes and tools to create, assign, manage, and revoke access credentials and privileges.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

CIS ControlsControl 8Spotting the abnormalA record of access

Audit Log Management

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack.

Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.

CIS ControlsControl 13A record of access

Network Monitoring

Operate processes and tools to establish and maintain comprehensive network monitoring and defense.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

What CIS Controls covers

This instrument defines no data category of its own. A prioritised list of defensive ACTIONS. Safeguard 3.1 tells you to build a data inventory; it does not tell you what belongs in it, because that comes from the law you answer to.

How CIS Controls is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by Nobody. A prioritised control list maintained by a non-profit.

A voluntary standard. No regulator enforces it.

The CIS Critical Security Controls are a community-maintained, prioritised list of defensive actions. They are widely used as a starting point and are mapped into other frameworks, but there is no certification, no assessor, and no sanction.

Some cyber insurers and some state statutes reference the Controls as a safe harbour, which is where any practical consequence comes from.

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for CIS Controls,
not configured for it afterwards

Policy Template

Control 8 Implementation

Complete audit log management per CIS requirements

Report

CIS Controls Assessment

Control-by-control implementation evidence

Classification

Data Classification Rules

Control 3 compliant data identification and classification

Alert

Attack Pattern Detection

Alerts based on known attack signatures and behaviors

Walk into the CIS Controls audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment