CIS Critical Security Controls
A prioritised, prescriptive control set that tells a small team what to do first, which is what most other frameworks deliberately avoid doing.
NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.
How it is organised
Eighteen controls, deliberately ordered
Version 8 defines eighteen controls, and the order is the product. Asset and software inventory come first because every later control depends on knowing what you have. A programme that starts at the interesting end and never completes the inventory is the most common way this framework is misused.
Implementation Groups make it affordable
The safeguards are split into three Implementation Groups. IG1 is described as basic cyber hygiene and is the realistic target for a small organisation; IG2 and IG3 add depth for larger or more exposed ones. Choosing your group honestly is what keeps the programme finishable.
It is prescriptive on purpose
Unlike outcome frameworks, CIS tells you the specific safeguard. That makes it excellent for execution and weaker as a governance narrative, which is why it is often paired with NIST CSF rather than chosen instead of it.
What an assessor will ask to see
- An asset inventory that is current and reconciled, not a spreadsheet from last year
- Software inventory including what is unauthorised and what was removed
- Configuration baselines and evidence of drift detection
- Vulnerability management records showing remediation, not just scanning
- Log collection coverage mapped against the assets that matter
Where it usually goes wrong
- Inventory treated as a one-off exercise rather than a maintained control
- Scanning in place but no closure loop, so findings accumulate
- Backups configured and never restore-tested
- IG3 safeguards attempted while IG1 is incomplete
