cis-controls

Guides CIS Controls v8 implementation, gap assessments, and framework mapping for security teams.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill cis-controls-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cis-controls
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/cis-controls
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill cis-controls-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security teams and compliance officers struggle to scope, implement, and assess the 153 safeguards of CIS Controls v8 across organizations of different sizes, and to map those controls to frameworks like NIST CSF, ISO 27001, SOC 2, and CMMC. ## Core Features & Use Cases - Implementation Group Scoping: Determines whether an organization should target IG1, IG2, or IG3 based on size, data sensitivity, and IT capability. - Gap Assessments: Produces structured tables of control, safeguard, current state, gap, priority, and remediation action across all 18 controls. - Framework Mapping: Provides side-by-side mappings from CIS Controls v8 to NIST CSF 2.0, ISO 27001:2022, CMMC 2.0, SOC 2, and PCI DSS v4.0. - Use Case: A mid-size company preparing for a SOC 2 audit asks which CIS safeguards apply at IG2 and how they map to SOC 2 Trust Services Criteria, receiving a prioritized remediation roadmap. ## Quick Start Ask the assistant to determine the right CIS Implementation Group for your organization and list the applicable safeguards with a gap assessment table.

Frequently Asked Questions about cis-controls

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I determine which CIS Implementation Group my organization belongs to?

Implementation Group determination depends on IT staffing, data sensitivity, and risk tolerance. IG1 fits small organizations with limited IT resources, IG2 fits mid-size organizations with dedicated IT staff and sensitive data, and IG3 fits enterprises with security teams and regulated data.

How do I perform a CIS Controls gap assessment?

A CIS gap assessment starts by determining your Implementation Group, then scoring each applicable safeguard as implemented, partial, or not implemented. Gaps are prioritized IG1 first, mapped to business risk using MITRE ATT&CK, and organized into a remediation roadmap.

How do CIS Controls v8 map to NIST CSF and ISO 27001?

Each of the 18 CIS Controls maps to NIST CSF 2.0 functions and ISO 27001:2022 Annex A controls. For example, Control 8 (Audit Logs) maps to NIST Detect categories DE.AE and DE.CM, and to ISO controls 8.15 and 8.16.

What changed between CIS Controls v7.1 and v8?

CIS Controls v8 consolidated 20 controls into 18, reduced sub-controls from 171 to 153 safeguards, and reorganized around asset types instead of technology types. It also added explicit cloud and mobile coverage and enhanced Implementation Group assignments.

Is IG1 enough for compliance with frameworks like HIPAA or PCI DSS?

IG1 covers essential cyber hygiene but is generally insufficient for regulated industries. Healthcare organizations under HIPAA and financial institutions under PCI DSS typically need IG2 as a minimum, with IG3 elements for large or high-risk environments.