Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

CIS Controls v8 Compliance

Center for Internet Security Controls — The Prioritized Path to Cyber Defense

lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned

WHAT ARE CIS CONTROLS?

CIS Controls v8: the most actionable cybersecurity framework for SMBs.

The CIS Controls (currently version 8) are a prioritized set of 18 cybersecurity actions developed by the Center for Internet Security — a non-profit organization that collaborates with government, industry, and academic partners to develop best practices for cyber defense. Unlike prescriptive regulatory frameworks, CIS Controls are designed to be practical, actionable, and immediately measurable, making them particularly well-suited for small and mid-sized businesses.

CIS Controls v8 is organized around the concept of Implementation Groups (IGs) — tiers of controls that scale with organizational size, resources, and risk tolerance. This tiered structure allows businesses to demonstrate meaningful progress even at the earliest stage of their security program, while providing a clear roadmap to full implementation.

18

control categories

153

individual safeguards

3

implementation group tiers

IG1

56 safeguards for all SMBs

THE 18 CIS CONTROL CATEGORIES

What the framework covers.

Control

Focus Area

01 — Inventory & Control of Enterprise Assets

Know every device on your network before attackers do

02 — Inventory & Control of Software Assets

Authorize and manage every application in your environment

03 — Data Protection

Identify, classify, and protect sensitive data throughout its lifecycle

04 — Secure Configuration

Establish and maintain secure configurations for all devices and software

05 — Account Management

Manage the creation, use, and deletion of all accounts across the enterprise

06 — Access Control Management

Limit access based on the need to know; enforce least privilege

07 — Continuous Vulnerability Management

Continuously identify, prioritize, and remediate vulnerabilities

08 — Audit Log Management

Collect, retain, and review audit logs to detect and respond to anomalies

09 — Email & Web Browser Protections

Protect against threats delivered through email and web browsing

10 — Malware Defenses

Control the installation and execution of malicious code

11 — Data Recovery

Establish and test data backup and recovery capabilities

12 — Network Infrastructure Management

Secure network infrastructure — routers, switches, firewalls, and wireless access points

13 — Network Monitoring & Defense

Operate processes and tools to detect and respond to network threats

14 — Security Awareness & Skills Training

Train all employees to recognize and report security threats

15 — Service Provider Management

Establish processes to manage third-party service providers

16 — Application Software Security

Manage the security lifecycle of internally developed or acquired software

17 — Incident Response Management

Establish an incident response capability to prepare, detect, contain, and recover

18 — Penetration Testing

Test the effectiveness of security defenses through controlled attack simulation

IMPLEMENTATION GROUPS

A tiered approach that meets your business where it is.

Group

Profile & Safeguards

IG1 — Essential Cyber Hygiene

For organizations with limited IT resources. 56 safeguards covering the most impactful controls against the most common attacks. The minimum baseline for all SMBs.

IG2 — Standard Defense

For organizations managing sensitive data or facing increased threat exposure. 74 additional safeguards covering deeper monitoring, incident response, and supply chain risk.

IG3 — Advanced Defense

For organizations in high-risk environments or regulated industries. 23 additional safeguards covering advanced threat hunting, application security, and penetration testing.

LBT Technology Group’s Business Tier clients are implemented at IG1/IG2 and Enterprise Tier clients at IG2/IG3 — with the specific safeguard selection driven by each client’s industry, data types, and risk assessment findings.

HOW LBT IMPLEMENTS CIS CONTROLS V8

From baseline hygiene to advanced defense.

✓ IG1 Baseline Implementation (All Clients)

Deploy the 56 essential safeguards across asset inventory, access control, data protection, patch management, account management, and basic incident response — the foundation of every LBT managed program.

✓ IG2 Standard Controls (Business & Enterprise Tier)

Implement advanced monitoring, email and web browser protections, service provider management, and vulnerability management continuous processes that exceed the basic hygiene baseline.

✓ IG3 Advanced Controls (Enterprise Tier)

Application security review, penetration testing coordination, and network monitoring and defense at the full IG3 safeguard level for clients in high-risk or regulated environments.

✓ CIS Controls Gap Assessment

A formal mapping of your current security controls against all 18 CIS Control categories, with documented gap findings, remediation priorities, and progress tracking.

✓ Quarterly Drift Review

Quarterly evaluation of control implementation against the IG baseline — identifying new gaps introduced by environmental changes, new assets, or vendor changes, with a documented remediation log.

✓ Cyber Insurance Documentation

CIS Controls implementation evidence — asset inventories, access control logs, patch records, and training completion records — packaged in a format that directly satisfies cyber insurance underwriter requirements.

Is Your Business CIS Controls Ready?

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

BOOK YOUR FREE CIS CONTROLS ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California

© 2026 LBT Technology Group, LLC · CIS Controls v8 Compliance Services · Sacramento, CA · Confidential

Center for Internet Security Controls

CIS Controls v8 Alignment & Implementation

Build a prioritized cybersecurity program around practical safeguards that scale with your organization, resources, data, and risk.

18Control categories

A prioritized foundation for practical cyber defense.

153Individual safeguards

Specific actions organized across the controls.

03Implementation Groups

A tiered path that scales with resources and risk.

Prioritized cyber defense

Start with the safeguards that matter most.

CIS Controls v8 organizes 18 cybersecurity control categories into a practical sequence. Its safeguards help organizations move from essential cyber hygiene toward deeper monitoring, incident response, application security, and testing.

Implementation Groups make that progression manageable for small and midsize businesses. The appropriate group and safeguard scope depend on the organization’s data, threat exposure, resources, and regulatory environment.

Where to begin

Match the starting point to the organization—not a generic checklist.

01

Small and midsize businesses

Establish essential safeguards when IT resources are limited.

02

Organizations handling sensitive data

Add deeper monitoring, response, and service-provider oversight as exposure increases.

03

Regulated or high-risk environments

Extend the program with advanced defense, testing, and stronger evidence.

Explore the operating cycle

Six stages turn individual safeguards into a continuous defense program.

Select a stage to see how related CIS Controls work together in practice.

Stage 01 · Know the environment

Identify the devices and software the business depends on.

Reliable inventories establish scope, ownership, and the context needed to make the remaining safeguards effective.

Related CIS Controls
  • 01 — Enterprise Assets
  • 02 — Software Assets
  • 15 — Service Providers
Implementation focus
  • Asset discovery and ownership
  • Authorized software standards
  • Third-party visibility

Implementation Groups

Three tiers create a realistic path forward.

Safeguards accumulate as risk, resources, and operational complexity grow.

IG1

Essential Cyber Hygiene

56 safeguards

A baseline for organizations with limited IT resources, focused on the most impactful defenses against common attacks.

IG2

Standard Defense

74 additional safeguards

Deeper monitoring, incident response, vulnerability management, and supply-chain risk practices.

IG3

Advanced Defense

23 additional safeguards

Advanced threat, application-security, and penetration-testing practices for high-risk or regulated environments.

The 18 CIS Controls

One framework covering the full security environment.

Each control addresses a distinct part of cyber defense while supporting the others as a coordinated program.

01Enterprise Assets
02Software Assets
03Data Protection
04Secure Configuration
05Account Management
06Access Control
07Vulnerability Management
08Audit Log Management
09Email & Web Protection
10Malware Defenses
11Data Recovery
12Network Infrastructure
13Network Monitoring
14Security Awareness
15Service Providers
16Application Security
17Incident Response
18Penetration Testing

How LBT implements CIS Controls v8

Move from a gap list to maintained safeguards and evidence.

The scope follows the selected Implementation Group and the organization’s industry, data types, and risk-assessment findings.

Discuss your CIS Controls scope
01

IG1 baseline implementation

02

IG2 standard controls

03

IG3 advanced controls

04

CIS Controls gap assessment

05

Quarterly drift review

06

Cyber-insurance documentation

Managed improvement

Controls stay useful when the review continues.

01

Assess

Map current safeguards against the appropriate group.

02

Prioritize

Sequence gaps around risk, resources, and business impact.

03

Implement

Deploy safeguards and organize operating evidence.

04

Review

Identify drift and the next remediation priorities.

Next step

Build a CIS Controls roadmap your business can maintain.

Talk with LBT about the appropriate Implementation Group, current coverage, priority gaps, and a realistic path forward.