Cybersecurity GRC 16 items
CIS Controls v8 Implementation Group 1 (IG1) Checklist
Assesses implementation of the CIS Controls v8 Implementation Group 1 safeguards that define essential cyber hygiene for all organizations.
CIS v8CIS IG1
Free PDF · enter your email to download.
Inventory & Data (CIS 1-3)
- Is an inventory of enterprise assets maintained and updated? *
- Is unauthorized hardware addressed when detected? *
- Is an inventory of authorized software maintained? *
- Is a data management process established and sensitive data inventoried? *
Configuration & Access (CIS 4-6)
- Is a secure configuration process applied to assets and software? *
- Is an account inventory maintained and dormant accounts disabled? *
- Is MFA enabled for externally exposed and administrative access? *
- Is a documented access-granting and revoking process in place? *
Vulnerabilities, Logs & Malware (CIS 7-10)
- Is automated patch management deployed for OS and applications? *
- Are audit logs enabled and retained across enterprise assets? *
- Is anti-malware software deployed and kept current? *
- Are DNS filtering and network protections used to block malicious sites?
Recovery, Training & Response (CIS 11, 14, 17)
- Are automated backups performed and recovery tested? *
- Is a security awareness training program delivered to all staff? *
- Is incident response contact and reporting information documented? *
- Are service provider security requirements maintained?
Download the full CIS Controls v8 Implementation Group 1 (IG1) Checklist checklist
Get it as a clean, printable PDF — free.
