Global · 8 controls evidenced

    Continuous evidence for CIS Controls v8

    The vendor-neutral baseline of 18 critical security controls.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    See your CIS Controls v8 readiness in 60 seconds. Free, no signup.

    Sample evidence
    acme-corp.com · CIS Controls v8
    Live
    CIS 1 — Inventory and Control of Enterprise Assets
    Third-party data flow map (subdomains & external services)
    CIS 4 — Secure Configuration of Enterprise Assets and Software
    Secure HTTP response headers
    CIS 7 — Continuous Vulnerability Management
    Reputation & threat intelligence
    CIS 12 — Network Infrastructure Management
    DNS hygiene & DNSSEC
    Updated continuously+ 4 more controls
    Why it matters

    CIS Controls v8 in 30 seconds

    Published by the Center for Internet Security, the CIS Controls are the most widely cited 'practical baseline' for cybersecurity. They map to virtually every other framework (ISO 27001, NIST CSF, PCI DSS, HIPAA) and are required or recommended in many cyber-insurance policies. Implementation Group 1 (IG1) is increasingly the floor for SMB cyber-insurance underwriting.

    Scope

    Any organisation seeking a pragmatic, prioritised baseline. Especially common in North-American mid-market and as a precursor to ISO 27001 or NIST CSF.

    Clause-by-clause mapping

    How Security Monitor evidences CIS Controls v8

    Each row links a CIS Controls v8 clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.

    CIS Controls v8 clauseWhat it requiresHow we evidence it
    SUB-1
    CIS 1 — Inventory and Control of Enterprise Assets
    Actively manage all enterprise assets connected to the infrastructure, including externally-facing services.
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    WEB-1
    CIS 4 — Secure Configuration of Enterprise Assets and Software
    Establish and maintain a secure configuration of enterprise assets, including hardened HTTP response headers.
    Secure HTTP response headers
    We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site.
    REP-1
    CIS 7 — Continuous Vulnerability Management
    Develop a plan to continuously assess and track vulnerabilities on all enterprise assets.
    Reputation & threat intelligence
    We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing.
    DNS-1
    CIS 12 — Network Infrastructure Management
    Establish, implement and actively manage network devices and services to prevent attackers from exploiting vulnerable network points.
    DNS hygiene & DNSSEC
    We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls.
    BREACH-1
    CIS 17 — Incident Response Management
    Establish a programme to develop and maintain incident-response capability — including external breach indicators.
    Credential exposure monitoring
    We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts.
    EMAIL-1
    CIS 9 — Email and Web Browser Protections
    Improve protections and detections of threats from email and web vectors, including SPF/DKIM/DMARC enforcement.
    Email authentication (SPF / DKIM / DMARC)
    We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses.
    TLS-1
    CIS 3 — Data Protection
    Develop processes and technical controls to identify, classify, securely handle, retain and dispose of data — including encryption in transit.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    EXP-1
    CIS 5 — Account Management
    Use processes and tools to manage authorisation to credentials and avoid unauthorised exposure of admin interfaces.
    Exposed files & admin panels
    We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable.
    Honest scope

    What we don’t cover for CIS Controls v8

    External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:

    • CIS 6 — Access Control Management (internal)
    • CIS 8 — Audit Log Management (internal)
    • CIS 14 — Security Awareness and Skills Training
    • CIS 16 — Application Software Security (internal SDLC)
    FAQ

    CIS Controls v8 questions

    See your CIS Controls v8 readiness now

    One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption