All resources
CIS v8IG1–IG3Checklist

CIS Controls v8 checklist: 18 controls, 153 safeguards, mapped to IGs

CIS v8 isn’t a one-time certification — it’s evidence your controls operate continuously. This checklist walks every control an auditor examines, and flags which a platform can automate.

What CIS v8 requires

CIS v8 is assessed against 153 controls across 5 families: Basic (IG1), Foundational (IG2), Organizational (IG3), Asset control, Implementation Groups. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

All 18 CIS Controls v8 (153 safeguards across IG1–IG3). Use the table below as your working checklist — 18 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
CIS Controls v8 — all 18 controls
CIS 1Inventory & control of enterprise assetsAuto
CIS 2Inventory & control of software assetsAuto
CIS 3Data protectionAuto
CIS 4Secure configuration of assets & softwareAuto
CIS 5Account managementAuto
CIS 6Access control managementAuto
CIS 7Continuous vulnerability managementAuto
CIS 8Audit log managementAuto
CIS 9Email & web browser protectionsAuto
CIS 10Malware defensesAuto
CIS 11Data recoveryManual
CIS 12Network infrastructure managementAuto
CIS 13Network monitoring & defenseAuto
CIS 14Security awareness & skills trainingManual
CIS 15Service provider managementManual
CIS 16Application software securityManual
CIS 17Incident response managementManual
CIS 18Penetration testingManual

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of CIS v8 controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Turn this checklist into a live dashboard

SBCMSP tracks every CIS v8 control continuously across all your clients.