Skip to main content
The CIS Controls (Center for Internet Security Controls) are a prioritized set of cybersecurity best practices designed to help organizations defend against the most common cyber threats. Version 8.1 includes 18 control groups organized by implementation priority.

Who needs CIS Controls?

Any organization looking for a practical, prioritized approach to cybersecurity — especially those without the resources for comprehensive frameworks like ISO 27001. CIS Controls are widely used in government, healthcare, and education.

18 CIS Control groups

Implementation Groups

IG1 — Essential

Basic cyber hygiene. Minimum standard for all organizations regardless of size.

IG2 — Foundational

For organizations with moderate IT complexity managing sensitive data.

IG3 — Organizational

For mature organizations facing sophisticated threats and regulatory requirements.

How DSALTA helps

  • All 18 CIS control groups mapped to actionable controls
  • Implementation Group tracking to prioritize by your organization’s maturity
  • Automated evidence from connected integrations
  • Cross-framework mapping — CIS Controls overlap heavily with SOC 2, ISO 27001, and NIST

Frequently asked questions

No, they are voluntary best practices. However, many regulatory frameworks reference CIS Controls, and some industries require them (e.g., CMMC references CIS).
Most small and medium businesses should start with IG1 (essential hygiene). Move to IG2 as your security program matures.

How DSALTA automates this

85 of DSALTA’s automated checks contribute evidence to this framework, drawn from 11 integrations. Browse them in the Compliance Tests catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.