About
Services
24/7 SOC & MXDR Zero Trust Security Microsoft 365 Backup & DR Email Security Compliance Virtual CISO VoIP Services Managed Print Website Design All Services →
Areas We Serve
Laurel Hattiesburg Meridian Waynesboro
Home Services
Computer Repair & Upgrades Virus & Malware Removal Hardware Repairs & Upgrades Data Recovery & Transfer
Blog Pricing Free Security Assessment
CIS Controls · Cybersecurity Framework · Implementation Groups

CIS Controls v8.1
The Security Baseline Every Business Needs

CIS Controls v8.1 is the most widely adopted cybersecurity framework for small and mid-sized businesses — 18 control families, 153 safeguards, organized by priority. West Computers implements, documents, and maintains CIS Controls so your security program has a defensible, evidence-based foundation.

// Implementation Groups
IG1 — Essential Cyber Hygiene (56 safeguards)
IG2 — Moderate Risk (74 additional safeguards)
IG3 — Advanced / Sensitive Data (23 additional)
153 total safeguards across 18 control families
Maps to HIPAA, FTC Safeguards, NIST CSF
Cyber insurance alignment
Evidence collection & gap tracking
Quarterly control reviews
Why CIS Controls

A framework that works for every business, not just enterprises.

Most compliance frameworks were written for large organizations with dedicated security teams. CIS Controls v8.1 was built differently. Its Implementation Group model lets any business — from a 10-person law firm to a 500-employee manufacturer — adopt controls that match their size, risk, and resources.

IG1 alone covers the foundational safeguards that stop the vast majority of common attacks: inventory management, secure configuration, access control, malware defense, data recovery, and security awareness training. For many small businesses, IG1 is the right starting point — and it's often all that's needed to satisfy cyber insurance requirements and client security questionnaires.

For businesses with regulatory obligations or sensitive data, IG2 and IG3 add the controls needed for deeper protection — vulnerability management, audit logging, incident response, penetration testing, and application security.

// The 18 Control Families
01 — Enterprise Asset InventoryIG1
02 — Software Asset InventoryIG1
03 — Data ProtectionIG1
04 — Secure ConfigurationIG1
05 — Account ManagementIG1
06 — Access ControlIG1
07 — Vulnerability ManagementIG2
08 — Audit Log ManagementIG2
09 — Email & Browser ProtectionIG1
10 — Malware DefensesIG1
11 — Data RecoveryIG1
12 — Network InfrastructureIG2
13 — Network MonitoringIG2
14 — Security Awareness TrainingIG1
15 — Service Provider ManagementIG2
16 — Application SecurityIG2
17 — Incident ResponseIG2
18 — Penetration TestingIG3
Implementation Groups

Start where you are. Build from there.

CIS Controls are organized into three Implementation Groups so every business has a clear, prioritized path forward.

IG1

Essential Cyber Hygiene

56 safeguards that every organization should implement regardless of size or industry. IG1 covers the fundamentals — asset inventory, secure configuration, access controls, malware defense, data backup, and security awareness. This is the baseline that stops most common attacks and satisfies most cyber insurance applications.

IG2

Moderate Risk

74 additional safeguards for organizations with increased risk exposure, regulatory obligations, or sensitive data. IG2 adds vulnerability management, audit logging, network monitoring, incident response planning, service provider management, and application security controls.

IG3

Advanced / Sensitive Data

23 additional safeguards for organizations handling highly sensitive data or facing sophisticated threat actors. IG3 adds penetration testing, advanced network defense, and controls designed to detect and respond to targeted attacks.

📋

Control Mapping

Every CIS Control maps to corresponding requirements in HIPAA, FTC Safeguards Rule, NIST CSF, and Cyber Essentials. One set of implemented controls can satisfy multiple compliance obligations simultaneously — reducing overhead and eliminating redundant work.

📊

Evidence Collection

Each safeguard is tracked with documented evidence: configuration screenshots, policy records, audit logs, training completion records, and test results. When an auditor, insurer, or client asks for proof, it exists.

🛡

Cyber Insurance Alignment

Cyber insurance applications are essentially asking whether you've implemented CIS Controls IG1. West Computers documents your controls in the format insurers expect — giving you stronger coverage terms and more defensible renewal conversations.

How West Computers Implements CIS Controls

Our process.

01

Scoping & IG Selection

We assess your business size, industry, data sensitivity, and regulatory obligations to determine the right Implementation Group. Most small businesses start at IG1; businesses with compliance requirements like HIPAA or FTC Safeguards typically need IG2.

02

Gap Assessment

A structured review of your current environment against every safeguard in your target Implementation Group. Each control is scored as implemented, partially implemented, or missing — producing a documented gap report with risk ratings and remediation priorities.

03

Remediation & Implementation

We close gaps in priority order: asset inventory, secure configurations, access controls, endpoint protection, backup verification, email security, and security training. Every remediation is documented with before/after evidence and mapped to its CIS safeguard number.

04

Policy & Documentation

Written policies aligned to CIS Controls — acceptable use, access management, incident response, data protection, vendor management, and change control. Policies are written for your business, not copied from a template.

05

Ongoing Monitoring & Review

Quarterly control reviews, continuous monitoring through our 24/7 SOC, annual gap reassessments, and evidence library maintenance. CIS Controls are a living program — not a one-time project.

Cross-Framework Mapping

One set of controls. Multiple compliance frameworks.

The biggest advantage of CIS Controls is that they map directly to other compliance frameworks your business may need. Instead of implementing separate sets of controls for HIPAA, FTC Safeguards, and cyber insurance, you implement CIS Controls once and map the evidence to each framework.

West Computers maintains these cross-framework mappings for every client. When you need to prove HIPAA compliance, we pull the relevant CIS Controls evidence. When a cyber insurer asks about endpoint protection, we reference the same documented controls. One source of truth, multiple outputs.

This approach eliminates the compliance overhead that comes from treating each framework as a separate project — and it means every new compliance requirement you face is partially addressed before you start.

// Framework Alignment
HIPAA Security RuleMAPPED
FTC Safeguards RuleMAPPED
NIST CSF 2.0MAPPED
Cyber EssentialsMAPPED
Cyber Insurance ApplicationsALIGNED
Client Security QuestionnairesSUPPORTED
FAQ

Common questions about CIS Controls.

What are the CIS Controls?
The CIS Controls (formerly the CIS Critical Security Controls) are a prioritized set of 18 cybersecurity actions developed by the Center for Internet Security. Version 8.1 organizes 153 safeguards into three Implementation Groups (IG1, IG2, IG3) based on organizational size, risk, and resources. They are widely recognized as the baseline standard for cybersecurity hygiene across all industries.
What are Implementation Groups?
Implementation Groups (IGs) are a prioritization system within CIS Controls. IG1 contains 56 essential safeguards that every organization should implement — often called "essential cyber hygiene." IG2 adds 74 more safeguards for organizations with moderate risk or compliance obligations. IG3 covers the full 153 safeguards and is appropriate for organizations handling sensitive data or facing advanced threats.
Which Implementation Group does my business need?
Most small businesses with 10 to 100 employees should start with IG1. Businesses with regulatory obligations (HIPAA, FTC Safeguards), sensitive data, or client security requirements typically need IG2. IG3 is appropriate for organizations with advanced threat exposure or highly sensitive data. West Computers helps you determine the right level during the initial assessment.
How do CIS Controls help with cyber insurance?
Cyber insurance applications are essentially a CIS Controls IG1 checklist. Insurers ask about MFA, endpoint protection, backup, access controls, vulnerability management, and security training — all of which are IG1 safeguards. Documented CIS Controls implementation gives you stronger answers, better coverage terms, and more favorable premiums.
Do CIS Controls satisfy HIPAA requirements?
CIS Controls map directly to HIPAA Security Rule requirements. CIS provides an official crosswalk document. Implementing CIS Controls IG2 addresses the majority of HIPAA technical safeguards — access controls, audit logging, encryption, malware defense, and incident response. West Computers maintains the HIPAA-to-CIS mapping for every healthcare client. Learn more about HIPAA-Compliant IT →
How long does implementation take?
IG1 implementation typically takes 30 to 60 days for a small business with an existing managed IT environment. IG2 adds another 60 to 90 days depending on complexity. The controls are then maintained as an ongoing program with continuous monitoring, periodic assessments, and evidence collection.
Are CIS Controls required by law?
CIS Controls themselves are not a legal mandate. However, they are recognized as a reasonable security standard by regulators, courts, and insurers. Multiple state data breach laws reference "reasonable security measures" — and CIS Controls are widely accepted as meeting that standard. Implementing them demonstrates due diligence in the event of a breach or regulatory inquiry.
How do CIS Controls relate to NIST CSF?
CIS Controls and NIST CSF are complementary. NIST CSF provides a high-level risk management framework (Identify, Protect, Detect, Respond, Recover), while CIS Controls provide specific, actionable safeguards that fulfill NIST CSF outcomes. West Computers uses CIS Controls as the implementation layer and NIST CSF as the strategic overlay when clients need both.
Related Services

Complete the stack.