What problem does it solve? Security teams struggle to demonstrate how their firewall estate supports CIS Controls v8/v8.1 safeguards during audits, often overclaiming that a firewall is "CIS compliant" without evidence. This Skill maps firewall controls, configurations, and operational evidence to specific CIS safeguards and Implementation Groups, producing defensible gap assessments. ## Core Features & Use Cases - Control Mapping: Maps NGFW features and firewall rules to CIS Controls 1-18 with a control-by-control matrix covering inventory, secure configuration, access control, logging, and incident response. - Assessment Workflow: Guides an eight-step assessment from scope and Implementation Group selection through rulebase review, evidence markers, and vulnerability/incident-response validation. - Evidence Markers: Recommends concise CIS:/CTRL: description and tag markers for policies, NAT rules, zones, and VPNs so exports carry auditable control references. - Use Case: Given a Palo Alto or Fortinet policy export, produce a firewall-to-CIS matrix identifying that a broad server egress rule maps to Controls 3, 4, 6, 8, 12, and 13, with risk explanation and remediation steps tailored to IG2. ## Quick Start Use the cis-controls-ngfw-compliance skill to assess this firewall configuration export against CIS Controls v8.1 at IG2 and produce a gap matrix with remediation priorities.