WHY COMPLY WITH CIS CSC V.8?
Center for Internet Security’s Critical Security Controls is especially relevant because they are updated by cyber experts based on actual attack data pulled from a variety of public and private threat sources. Organizations that implement CIS Controls are likely to prevent the majority of cyber-attacks. The CIS Critical Security Controls™ (CIS Controls) is a concise, prioritized set of cyber practices created to stop today's most pervasive and dangerous cyber-attacks. CIS CSC v6.1 contains important components that make-up an effective cyber defense system, allowing companies to prioritize controls that protect against the greatest threats, provide metrics for IT personnel to understand, continuously diagnose and mitigate risks, and automate defenses to ensure compliance with the controls.
Security and Compliance offers a system-based mapping of CIS Benchmark rules according to their most relevant CIS CSC 6.1 (soon to update to 8.1) risks, making failure and success in IT control continuously available to the risk management reporting process.
CIS CSC IS THE RIGHT CHOICE
- Referenced by the U.S. Federal Government in the NIST Cybersecurity Framework CSF and other guidelines, and validated by the Australian government
- Recommended by the U.S. National Governor’s Association, the UK’s Centre for the Protection of National Infrastructure (CPNI), Symantec, Zurich Insurance, and others
LEVERAGING CIS CSC RISK FINDINGS TO OPTIMIZE ENVIRONMENTS AND PASS AUDITS FASTER
Facing multiple forms of external controls assessment, organizations often fail due to improper security settings, incorrect configurations, low levels of encryption, or poor policies and procedures. Continuous testing over those controls could have prevented costs in business disruption, time-consuming client discussion, or lost business opportunities.
Audit Once Use Many - Unified Compliance
Like many standards coverings cyber risk, Critical Security Controls are broken out to Network, Application, and System. Whether the organization approaches security from a risk-centric or the matrix approach of NIST 800-53 r5, with the SDDF and NIST Privacy frameworks, the efforts to make an enterprise resilient should be the same. Explaining these efforts to the board should be results driven and simple. EnterpriseGRC Solutions security and compliance experts evaluate and map the CSC to 100% of applicable areas in NIST 800-53 r5.
We're not alone. The extended community of CIS and CSA, for example, where EnterpriseGRC Solutions currently provides CCM Working group leadership in mapping, always enforces consensus in areas of mapping.
CIS Controls v8 Mappings as provided by CIS
Download individual mappings below or visit our CIS Controls Navigator for all mappings to CIS Controls v8.
- AICPA Trust Services Criteria (SOC2)
- CMMC Cybersecurity Maturity Model Certification v1.0 (Note that EnterpriseGRC Solutions maps to NIST SP 800-171 and 172 which currently replace CMMC 1.0. We always contribute to NIST as fast as we can. The goal is to drive industry consensus.)
- CS CCM Cloud Security Alliance Cloud Control Matrix (Note EnterpriseGRC Solutions leads in supporting the CCM 4.0 update to the CIS Controls V8 - we are CCM WG participants and consult for CSA)
- HIPAA Health Insurance Portability and Accountability Act of 1996
- ISACA COBIT 19
- NIST CSF (Note: pay attention to the NIST Privacy Matrix and use of NIST SDDF framework)
- NIST Special Publication 800-53 Rev.5
- NIST Special Publication 800-171 Rev.2 - as mentioned above, use this for SPRS DFARS. CMMC 1.0 is no longer in use.
- PCI Payment Card Industry
- Azure Security Benchmark
- CIS Controls v8 Mapping to GSMA FS.31 Baseline Security Controls
Steps to associate the controls prescribed for NIST 800-53 r5 are the same throughout all areas of compliance, so the EnterpriseGRC Solutions team iterates across risk and vulnerability concepts using the best industry research and tying down themes of risk that result in a resilient compliance fabric.
These images are a few years old, but the process remains consistent as the frameworks continue to update and add attributes for mapping.







EnterpriseGRC Solutions content mapping methodology works with Cavirin's ARAP platform in some striking ways. Cavirin’s ARAP™ solution automatically checks system configuration settings across all target environments, reporting against an expected system-based CSC top 20 Critical Security Controls. Review and response to address recommended fix actions allows timely remediation to found problems, and further rewards the business by rapid completion of unnecessarily disruptive audit events.
People with compliance responsibilities have only three choices, to avoid, accept or share a risk. The burden of proving prudence and speed falls to those we entrust with positions to manage risks to the enterprise, including its people, process, and systems. Using this type approach allows for qualitative and quantitative risk analysis. The objective is always to make the right decisions faster.
POSSIBLE SOLUTIONS
EnterpriseGRC recommends using a number of products, for example, Cavirin’s Automated Risk Analysis Platform, Aaraali Network Patching for Cloud-Native Apps, Security Compass SDE. As a Chief Risk & Security, as well as IT and DevOps leader in gathering configuration data, used to address top security and compliance challenges I want assurance that our platform will identify and help us fix these common problems:
- Settings that indicate missing patches for operating systems and applications.
- Monitoring and detecting sensitive data loss (data exfiltration)
- Locating policies that enable weak passwords.
- Lack of logs and audit trails necessary to conduct forensics
- Security validation for new systems
- Missing or outdated anti-malware technology
- Settings that enable encryption of sensitive information in transit
- The information necessary to remediate deficiencies that would otherwise be impossible to manage due to the lack of trained staff maintaining security controls
COMPLIANCE IN ANY ENVIRONMENT
Any product used for Cloud Security must cover at least these seven details
- Cloud Native platform supporting 12-factor patterns (things like port binding, logs, concurrency…)
- A “hyperplane” of integrated “risk assessment” amongst segmented vulnerability domains
- Works with Private, Hybrid, and Public Clouds and Support AWS, Azure, GCP (Google Cloud Platform)
- Manages thousands of out-of-box policies, well-curated and certified (SCAP, XCCDF, OVAL)
- Supports most compliance authorities (PCI, HIPAA, NIST, SOC2, FedRamp, CIS Benchmark, DISA, CIS CSC, CSF)
- Is CIS Certified security content (Multiple OS, Docker, AWS Cloud)
- Complies with DISA standards in all aspects of delivery and reported results
ABOUT EnterpriseGRC Solutions
EnterpriseGRC Solutions is empowered to implement governance, security, risk, and compliance automation products and programs, emphasizing system-based policies specific to security settings for secure configuration management. EnterpriseGRC is a women-owned small business offering compliance readiness, Security & GRC tools, Enterprise Security Architecture, Cybersecurity Risk Assessment, and a wide variety of resources for security and GRC technology support. Founded in October of 2002 as Phoenix Business and Systems Process, and rebranded in 2011 as EnterpriseGRC Solution, the company is positioned to solve an organization's greatest cloud security and cyber challenges. True to its tagline "Simple Solutions to Complex Problems" the company offers pragmatic, remote, and on-site web-enabled compliance implementation, training, strategy, management consulting, security and risk management services.



Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics