CIS Controls v8.1 Assessment

The CIS Critical Security Controls v8.1 are 18 controls ordered by what actually stops attacks, not by what reads well in a table of contents. They are not a legal requirement and they are not certified: they are the answer to the question «if I can only do ten things this year, which ten».

Why start here rather than with a standard

Because the implementation groups — IG1, IG2 and IG3 — tell you what applies to you given your size and exposure, instead of demanding everything at once. IG1 is the basic hygiene any organisation should have; IG2 and IG3 scale with risk. It is the cheapest way to cut real exposure before entering a certification process.
They are measurable: every safeguard is verifiable, so progress can be tracked year on year.
They are mapped: documented mappings exist to ISO 27001, the Spanish ENS and other frameworks, so work done here is reused later.
They are prioritised: the ordering reflects which controls block the most attacks per euro spent.

What we do

Phase 1
Gap analysis
We measure the real distance between what the regulation demands and what you have today, control by control. No generic checklists: we review evidence, not statements of intent.
Phase 2
Action plan
Every gap becomes a task with an owner, an effort estimate and a priority based on risk. You decide what comes first knowing what protects you most.
Phase 3
Remediation
We work alongside you through delivery: policies, procedures, technical controls and evidence, until compliance holds up in front of an auditor.

Scope of work

Determination of the implementation group that applies to you, with the criteria justified.
Assessment of the 18 controls and their safeguards, with technical evidence rather than interviews alone.
Technical verification of everything that can genuinely be checked: asset and software inventory, vulnerability management, secure configuration, access and privilege control, logging and monitoring, backups and recovery capability.
Maturity scoring per control, with a baseline to compare against at the next review.
Mapping matrix to ISO 27001 and the ENS, so effort is not repeated if you certify later.

How we work

1
Framing
Size, sector, exposure and available resources determine whether we work to IG1, IG2 or IG3. Demanding IG3 of an organisation that cannot sustain it is an expensive way to change nothing.
2
Evidence-based assessment
We go control by control checking technical reality: what is inventoried, what is patched, who holds privileges and what is being logged.
3
Scoring and baseline
Each control gets a traceable score. That number is the reference you measure against next year.
4
Quarterly action plan
Ordered by risk reduction, not by ease. With effort estimates so it fits the budget.
5
Progress review
We measure again when due and give you the trend in the same format. That is what turns this into a programme rather than a report.

What you get

Maturity report by control and by safeguard, with evidence.
Overall score and a baseline for tracking.
Action plan prioritised by risk reduction, with effort estimates.
Mapping matrix to ISO 27001 and the ENS.
A one-page executive summary the board can read without translation.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Does this replace an ISO or ENS audit?
No, and it does not try to. The CIS Controls are not certified. They exist to cut risk quickly and sensibly, and to reach a later certification with half the technical work already done.
We are a small company. Is this for us?
It is probably the best fit for you. IG1 is the set of safeguards that stops most opportunistic attacks, and it is designed for organisations without a dedicated security team.
Do you assess by interview or do you actually check?
We check. A questionnaire filled in by the IT department measures optimism, not security. We technically verify everything that can be verified.
How often should it be repeated?
Annually as a rule, or every six months if you are in the middle of an improvement plan. The value is in the series: whether the number goes up, and why.
Start by knowing where you stand
Half an hour with an auditor to decide which implementation group applies to you and what a useful assessment would cover.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
Spain