CIS CONTROLS v8 · 18 CONTROLS · 153 SAFEGUARDS

There are eighteen CIS Controls. Two of them decide the rest.

Eighteen controls is not what the framework contributes. The order you build them in is.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Everything downstream is scoped from this
Inventory Data protection Access control Logging Service providers

Our promise

“A checklist is an intention. Measurement is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.

Each additional tool
$1,500
Re-audit, same scope
$4,200
Renewal, every twelve months
$5,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

The Controls, in three chapters

The Order

Eighteen controls holding 153 safeguards, from the Center for Internet Security. Nobody is short of security advice, so the list is not the contribution — the sequence is. These are opinionated about which control you build first, and that opinion is what you are actually buying.

The Groups

Three Implementation Groups say how far along that sequence you need to go. IG1 is essential hygiene and the floor for every organisation; IG2 and IG3 are decisions rather than achievements, taken against the attacks you actually face and the budget you actually have to spend.

The Inventory

Controls 1 and 2 are inventory, and everything after them is scoped from what those two produce. A new AI estate fails them almost without exception, because the models and the pipelines arrived as product features rather than as assets anybody thought to catalogue at the time.

How far to go

Not how many you do, how far along you go.

IG1 is the floor for everyone. Past it, the group is a decision.

Which group you are in № 01
  • IG1 — essential hygiene, the floor for everybody
  • IG2 — where most teams with security resource belong
  • IG3 — chosen under sustained, targeted attack
  • The choice is yours to make, and to write down
CIS Controls v8 · iDharma · Presented for review
What Control 1 misses № 02
  • Models in production, and the ones behind them
  • Inference endpoints nobody registered as assets
  • Notebook environments and training pipelines
  • Training corpora, retrieval indexes and prompt logs
CIS Controls v8 · iDharma · Presented for review
Whose job is which

The list is published. The order is the work.

You

The organisation that picks the group

Nothing here is imposed on anybody, so the only person who decides how far along the sequence you go is you. IG1 is the floor rather than an ambition, and choosing to go beyond it is a judgement about the attacks you actually face and the money you actually have available to spend on any of it.

Whoever asks

The customer with the questionnaire

Most organisations meet the Controls through somebody else's due diligence rather than by choosing them for themselves. That changes the useful answer: not how many safeguards you hold, but which group you work to and why you drew the line exactly where you drew it, in writing.

The line

Nobody certifies you against these

CIS accredits no assessors and issues no certificate against the Controls, so any firm offering you one is selling something that does not exist. We review against them in their own order and write down what is missing, in the sequence it should actually be built, not the order you bought it in.

What most teams assume

“We started with the AI-specific controls.”

What the framework says

Start at Control 1. Nobody has it.

The order is the contribution. Discarding it discards the framework.

  • Who it is for
  • New AI estates
  • CSF & ISO 27001 users
  • Finite security budgets
  • Vendor questionnaires
  • First security programmes
Why this matters in 2026
A handwritten checklist on aged paper under warm light, five boxes ticked in gold and the last one still empty, with a brass desk stamp, reading glasses and a fountain pen beside it.
01 A ticked box records an intention. What a reviewer can check is whether the safeguard is still operating — and the gap between those two is where most programmes quietly live.
02

Inventories were built before the AI estate existed, so they contain none of it. Controls 1 and 2 are where that shows, immediately.

03

Safeguards get built in the order they are easiest rather than the order published. That is the framework’s one opinion, discarded.

04

A group is drifted into rather than chosen. Nobody can say which bar they are working to, so nothing can be graded against it.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Inventory -

Everything after this is scoped from it. Inventories were built when the estate was servers and applications. Models, endpoints, notebooks and pipelines arrived afterwards, as features rather than as assets.

The group -

The group is a decision, not a discovery. IG1 is the floor for every organisation. Past it, the choice is a judgement about the attacks you face and the budget you have — and the reasoning is the artefact.

Measurement -

A checklist is an intention. A safeguard ticked at implementation and never revisited says what somebody meant to do. What a reviewer can check is whether it is still operating today.

The calendar

Four moves, and the first one decides the rest.

The framework’s own sequence, which is the part worth keeping. Built in a different order, these stop being the CIS Controls.

  1. Inventory

    Before anything

    Controls 1 and 2, with models and pipelines included. Everything after this is scoped from it.

  2. Pick the group

    Then choose

    IG1, IG2 or IG3, decided against the attacks you actually face, and written down with its reasoning.

  3. Build

    In order

    The safeguards in the sequence the framework sets them, not in the order they happen to be easiest.

  4. Measure

    Every quarter

    A ticked box records an intention. What counts is whether the safeguard is still operating today.

The trap

Teams reach for the interesting safeguards first, because inventory is nobody’s favourite week. Built on an estate nobody has listed, every control after the second one is applied to a system somebody assumed rather than found.

Control & artefact

What the control asks, what we ship

All eighteen controls, in the order the framework sets them. Paired, so every claim can be checked against the ask.

Asset and software inventory Controls 1-2 - Where every AI estate fails
Every model, inference endpoint, notebook environment and pipeline listed with an owner - the artefact every control after this one is scoped from, and the one almost nobody has.
Data protection and configuration Controls 3-4 - Classify, then harden
Training corpora, retrieval indexes, evaluation sets and prompt logs classified before they are controlled, and model serving hardened against a baseline rather than a default.
Account and access management Controls 5-6 - Who can reach what
Who can read training data, launch a fine-tune and change production inference, reviewed against the team you have now rather than the one that set the estate up.
Vulnerability and audit logs Controls 7-8 - Find it, then see it
The ML stack inside the vulnerability programme, which it usually is not, and logs that are useful, retained, and actually read by somebody.
Malware, email and recovery Controls 9-11 - Defences and the way back
The conventional defences assessed as they stand, and recovery tested rather than documented - including what restoring a model artefact actually means.
Network infrastructure and defence Controls 12-13 - The layer nobody owns
The segmentation and monitoring around inference infrastructure, which tends to sit between two teams and therefore belong to neither of them.
Training and service providers Controls 14-15 - People, and who you buy from
Awareness that reaches the people building models, and model and cloud providers managed as the service providers they are, with terms and review to match.
Applications, response and testing Controls 16-18 - Build, react, prove
Secure development covering ML code, an incident plan that has been exercised on an AI-specific scenario, and testing that reaches the inference path.
The engagement

The estate, independently counted

From one production model to the whole estate.

  1. Inventory

    Controls 1 and 2 first: what the estate holds, models included.

  2. Review in order

    All eighteen in the framework's own sequence, scoped to your group.

  3. Rank and hand over

    You see the draft first. Then the gaps in build order - dated.

Request an assessment
An auditor in a royal-blue suit and open-collared white shirt, with a trimmed beard, standing against a warm pale wall and pointing into the open space alongside.
The inventory, settled before anything is graded against it.
Struck in your favour

Why teams choose iDharma to run the review

Independent by design

We sell none of the tooling, platforms or controls we assess. Nothing we find is convenient for us.

The order is kept

Reviewed in the framework's own sequence, so the gap list arrives as a build order already.

The AI estate counted

Models, pipelines and prompt logs treated as the assets they are, which is where Control 1 breaks.

Scoped to your group

IG1, IG2 or IG3 agreed before we start, so nothing gets graded against a bar you never chose.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

CIS Controls v8 review

The full review: where the estate stands against all eighteen controls in the framework's own order, scoped to the Implementation Group you chose, with each gap placed in the sequence it should be closed rather than ranked by how easy it is. Where a safeguard is genuinely arguable at your scale - and at the IG boundaries several always are - it says so instead of grading you against the wrong bar.

Controls 1-2

Asset and software inventory

Models, endpoints, notebooks and pipelines listed with owners, in the form the two controls expect rather than as a spreadsheet.

Recorded

Implementation Group memo

Which group you work to and why, written down before a customer asks - because the reasoning is the part their questionnaire cannot supply.

In build order

Safeguard gap list

What is missing, placed in the framework's own sequence, so the list arrives as a plan rather than as eighteen simultaneous priorities.

Control 3

Data classification map

Training corpora, retrieval indexes, evaluation sets and prompt logs classified, because a control cannot protect data nobody has categorised.

Per platform

Benchmark baseline note

Where the per-technology Benchmarks apply across your serving stack, and where a default is quietly doing the job of a hardened configuration.

Repository

Policy and procedure set

The documents the controls expect, under version control and written to your operations rather than lifted from a template library.

Format & fee

Real numbers, upfront.

Scope
All 18, at your group
Output
A build order, not a score
Re-review
As the estate grows - $5,500 against your recorded inventory

Eighteen controls is eighteen controls, so the fee is flat - and nothing is charged until you approve the scope.

Request this assessment
CIS Controls v8 · Review $6,500 flat
  • Asset & software inventory, AI included
  • All 18 controls at your chosen group
  • 29 policy and procedure documents
  • Gap list, in the framework’s build order
Show your hand

Four things a questionnaire will ask you to produce

A checklist is not evidence. Each of these is either in your hand on the day somebody asks, or it is not.

The inventory,
whole

Assets and software, models and pipelines included, each with an owner. Every control after the second is scoped from this, so a partial list shortens the review.

The group,
chosen

Which Implementation Group you work to, and the reasoning behind it. A group picked deliberately and written down beats a higher one claimed and unevidenced.

The order,
kept

Safeguards built in the sequence the framework sets, not the order they were easiest. The ordering is the contribution; discarding it discards the framework itself.

The proof,
current

Evidence that a safeguard is still operating, not a box ticked once at implementation. A checklist records an intention; measurement is what a reviewer can actually check.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Mandatory, frameworks, groups, inventory, cost. Answered straight.

Request this assessment
Are the CIS Controls mandatory?

No. They are voluntary, and there is no certification, no accredited assessor and no seal. They become an obligation the way most voluntary frameworks do - through somebody else's contract or questionnaire.

Are they a replacement for ISO 27001 or NIST CSF?

No - they sit under a framework rather than beside one. Use CSF or ISO 27001 to decide which outcomes matter, and the CIS Controls to decide what to build first.

Which Implementation Group should we target?

IG1 is the floor for everybody. Beyond that it is a judgement about the attacks you actually face and the budget you actually have - and a group chosen deliberately, with the reasoning written down, beats a higher one claimed.

Why does inventory matter so much for an AI estate?

Because Controls 1 and 2 scope every control after them, and an inventory built before the AI estate existed contains none of it. Models, endpoints, notebooks, pipelines and prompt logs are assets and data, and almost none of them are on the list.

What does an iDharma CIS Controls review cover, and what comes with it?

A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the asset and software inventory, the group memo, the gap list in build order, the data classification map and the policy suite the review writes against.

Get started

Request your CIS Controls review

Tell us what the estate runs and we come back with a scoping call inside a day.

What we need from you

Nothing you do not already have. Most of it comes out of your asset inventory and the last review, in an afternoon, and we tell you which extracts before you commit.

  1. The asset and software inventory as it stands today
  2. Which Implementation Group you believe you are in
  3. What the AI estate runs, models and pipelines included
  4. Any existing CIS assessment, however partial
  5. Who asked you for this, if anybody did

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request an assessment
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The CIS Critical Security Controls v8, published by CIS
  • The CIS Benchmarks, its per-technology companion
Version
CIS Controls v8
Enforced by
Contract only

What it means

  • General information about what the Controls describe — not legal advice, and not a determination about your programme.
  • Where a safeguard is genuinely arguable at your scale, and at the Implementation Group boundaries several always are, our reports say so rather than grade you against a bar you never chose.

Scope & limitation

  • The framework’s totals are printed; the per-group splits are not. Eighteen controls, 153 safeguards and three Implementation Groups are CIS’s own figures. How many safeguards fall inside each group is not checked here, and an unchecked count on an indexed page is a published claim — read those from CIS, along with the v7.1 change list.
  • There is no certificate, from iDharma or anyone. CIS accredits no assessors. We review in the framework’s order and write down what is missing.

Something on this page out of date?

Tell us