📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

CIS Controls v8 8.1

SecurityGlobal

Center for Internet Security Critical Security Controls Version 8.

1. Community-developed set of 18 prioritized safeguards to mitigate the most prevalent cyber-attacks.

Three Implementation Groups (IGs): IG1 (essential cyber hygiene for small/medium orgs), IG2 (for enterprises with IT staff managing moderate complexity), IG3 (for organizations with dedicated security experts). Widely referenced by insurance underwriters, MSPs, and as a practical implementation guide for NIST CSF.

Official reference: https://www.cisecurity.org/controls

Assessment tiers & levels Lavawall supports

Lavawall assesses CIS Controls v8 at every level below, so you can start where you are and step up as your program matures.

Tier / levelWhat it coversBuilds on lower
Implementation Group 1Basic cyber hygiene - essential controls for all organizations. Focus on preventing wide-spread attacks and common exploits.
Implementation Group 2Foundational controls for organizations with more resources and elevated risk profiles. Includes all IG1 controls plus additional defenses.Yes
Implementation Group 3Advanced controls for organizations with significant resources and high-value assets requiring protection against sophisticated attacks.Yes

How Lavawall® helps you get to CIS Controls v8 compliance

Most of CIS Controls v8 comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CIS Controls v8, and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against CIS Controls v8 in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Ready to tackle CIS Controls v8?

Assess, remediate, and stay audit-ready for CIS Controls v8 — and every other framework you carry — from one Lavawall® console.

Lavawall® supports CIS Controls v8 as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.