CIS Controls v8 Compliance
Center for Internet Security Controls — The Prioritized Path to Cyber Defense
lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned
WHAT ARE CIS CONTROLS?
CIS Controls v8: the most actionable cybersecurity framework for SMBs.
The CIS Controls (currently version 8) are a prioritized set of 18 cybersecurity actions developed by the Center for Internet Security — a non-profit organization that collaborates with government, industry, and academic partners to develop best practices for cyber defense. Unlike prescriptive regulatory frameworks, CIS Controls are designed to be practical, actionable, and immediately measurable, making them particularly well-suited for small and mid-sized businesses.
CIS Controls v8 is organized around the concept of Implementation Groups (IGs) — tiers of controls that scale with organizational size, resources, and risk tolerance. This tiered structure allows businesses to demonstrate meaningful progress even at the earliest stage of their security program, while providing a clear roadmap to full implementation.
18
control categories
153
individual safeguards
3
implementation group tiers
IG1
56 safeguards for all SMBs
THE 18 CIS CONTROL CATEGORIES
What the framework covers.
Control
Focus Area
01 — Inventory & Control of Enterprise Assets
Know every device on your network before attackers do
02 — Inventory & Control of Software Assets
Authorize and manage every application in your environment
03 — Data Protection
Identify, classify, and protect sensitive data throughout its lifecycle
04 — Secure Configuration
Establish and maintain secure configurations for all devices and software
05 — Account Management
Manage the creation, use, and deletion of all accounts across the enterprise
06 — Access Control Management
Limit access based on the need to know; enforce least privilege
07 — Continuous Vulnerability Management
Continuously identify, prioritize, and remediate vulnerabilities
08 — Audit Log Management
Collect, retain, and review audit logs to detect and respond to anomalies
09 — Email & Web Browser Protections
Protect against threats delivered through email and web browsing
10 — Malware Defenses
Control the installation and execution of malicious code
11 — Data Recovery
Establish and test data backup and recovery capabilities
12 — Network Infrastructure Management
Secure network infrastructure — routers, switches, firewalls, and wireless access points
13 — Network Monitoring & Defense
Operate processes and tools to detect and respond to network threats
14 — Security Awareness & Skills Training
Train all employees to recognize and report security threats
15 — Service Provider Management
Establish processes to manage third-party service providers
16 — Application Software Security
Manage the security lifecycle of internally developed or acquired software
17 — Incident Response Management
Establish an incident response capability to prepare, detect, contain, and recover
18 — Penetration Testing
Test the effectiveness of security defenses through controlled attack simulation
IMPLEMENTATION GROUPS
A tiered approach that meets your business where it is.
Group
Profile & Safeguards
IG1 — Essential Cyber Hygiene
For organizations with limited IT resources. 56 safeguards covering the most impactful controls against the most common attacks. The minimum baseline for all SMBs.
IG2 — Standard Defense
For organizations managing sensitive data or facing increased threat exposure. 74 additional safeguards covering deeper monitoring, incident response, and supply chain risk.
IG3 — Advanced Defense
For organizations in high-risk environments or regulated industries. 23 additional safeguards covering advanced threat hunting, application security, and penetration testing.
LBT Technology Group’s Business Tier clients are implemented at IG1/IG2 and Enterprise Tier clients at IG2/IG3 — with the specific safeguard selection driven by each client’s industry, data types, and risk assessment findings.
HOW LBT IMPLEMENTS CIS CONTROLS V8
From baseline hygiene to advanced defense.
✓ IG1 Baseline Implementation (All Clients)
Deploy the 56 essential safeguards across asset inventory, access control, data protection, patch management, account management, and basic incident response — the foundation of every LBT managed program.
✓ IG2 Standard Controls (Business & Enterprise Tier)
Implement advanced monitoring, email and web browser protections, service provider management, and vulnerability management continuous processes that exceed the basic hygiene baseline.
✓ IG3 Advanced Controls (Enterprise Tier)
Application security review, penetration testing coordination, and network monitoring and defense at the full IG3 safeguard level for clients in high-risk or regulated environments.
✓ CIS Controls Gap Assessment
A formal mapping of your current security controls against all 18 CIS Control categories, with documented gap findings, remediation priorities, and progress tracking.
✓ Quarterly Drift Review
Quarterly evaluation of control implementation against the IG baseline — identifying new gaps introduced by environmental changes, new assets, or vendor changes, with a documented remediation log.
✓ Cyber Insurance Documentation
CIS Controls implementation evidence — asset inventories, access control logs, patch records, and training completion records — packaged in a format that directly satisfies cyber insurance underwriter requirements.
Is Your Business CIS Controls Ready?
Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.
BOOK YOUR FREE CIS CONTROLS ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California
© 2026 LBT Technology Group, LLC · CIS Controls v8 Compliance Services · Sacramento, CA · Confidential
