CIS Controls v8 — measured from your real estate, not a questionnaire.
CIS Controls v8 is the most operational security framework in circulation: 18 controls, 153 safeguards, and three implementation groups. Almost all of it is answerable from asset, identity, and endpoint data — which is exactly the data Lojycal already holds.
What CIS v8 actually demands
CIS is deliberately concrete. Every safeguard is a testable statement about your estate, which makes self-attestation by spreadsheet indefensible.
Controls 1 and 2 come first for a reason
Inventory of enterprise assets and inventory of software assets underpin everything else. Get them wrong and every downstream safeguard measures nothing.
An honest implementation group
IG1 (56 safeguards), IG2, or IG3. Claiming IG2 while failing IG1 safeguards is the most common self-assessment failure.
Continuous measurement
Safeguards are stated as ongoing conditions — 'maintain', 'establish and maintain' — not one-time projects.
Evidence for each safeguard
Insurers and enterprise buyers increasingly ask for the underlying data, not the self-assessed score.
The Lojycal CIS engine
The safeguards that are hardest to evidence manually are the ones Lojycal computes automatically.
Live asset and software inventory
Controls 1 and 2 answered directly from MDM, identity, network, and browser telemetry — including unmanaged and shadow assets.
Asset Lifecycle + Endpoint Governance
Safeguard scoring by IG
Each safeguard scored against live data with your declared implementation group, so the score is defensible rather than aspirational.
Policy Lab → CIS Controls v8
Configuration and access posture
Secure configuration, account management, and access-control safeguards evaluated from MDM baselines and IdP grants.
Endpoint Governance + RBAC
Attestation pack
Signed export of scores plus the underlying evidence per safeguard — the artefact cyber insurers actually want.
Trust Center → Evidence Pack
CIS v8 controls → Lojycal sources
A sampled view of the 18 controls and where the evidence originates:
| Control | Example safeguard | Lojycal source |
|---|---|---|
| 1 — Enterprise assets | Maintain a detailed asset inventory | Asset Lifecycle |
| 2 — Software assets | Maintain an authorised software inventory | Application Library |
| 3 — Data protection | Data inventory and retention | Data Retention |
| 4 — Secure configuration | Baseline configuration on assets | Endpoint Governance |
| 5 — Account management | Inventory of accounts, disable dormant | RBAC + HR Automation |
| 6 — Access control | MFA for administrative access | AAL2 Enforcement |
| 7 — Vulnerability management | Remediate detected vulnerabilities | Patch Lab |
| 8 — Audit log management | Collect and retain audit logs | WORM Audit Log |
| 12 — Network infrastructure | Maintain network documentation | Infrastructure Governance |
| 15 — Service provider management | Inventory and assess providers | Vendor Governance |
Sampled — Lojycal ships a mapped subset of the 153 safeguards covering those it can evidence from live data. Safeguards requiring physical or procedural proof stay manual, and the export says so.
A score you can defend line by line
Self-attested CIS scores fall apart the moment someone asks for the data behind them.
Every safeguard score in Lojycal is a query over live inventory, identity, and configuration data — with the contributing records attached. The signed attestation pack carries both: the score and the evidence, with a detached signature an insurer or customer can verify without access to your tenant.
IG1 to a defensible score
Because Controls 1 and 2 populate from your connectors, the first score arrives in days.
- Week 1
Inventory
Connect MDM, identity, and SaaS. Controls 1 and 2 populate automatically, including unmanaged assets.
- Week 2–3
Baseline score
Score IG1 honestly. Fix the safeguards the data shows failing rather than the ones that feel risky.
- Week 4–10
Climb
Move to IG2 where it earns its keep, using drift alerts to hold gains.
- Ongoing
Attest
Export the signed attestation pack for insurers, customers, and the board.
CIS Controls v8 questions
Which implementation group should we target?
IG1 is the defined baseline of essential cyber hygiene and applies to every enterprise. IG2 suits organisations managing sensitive data across multiple departments; IG3 suits those with dedicated security functions and regulatory exposure. Lojycal scores against your declared group and flags where you are claiming above your evidence.
Is CIS v8 a substitute for ISO 27001 or NIS2?
No, but it is excellent scaffolding for both. CIS is prescriptive about what to do technically; ISO 27001 and NIS2 care about the management system around it. Lojycal maps the shared evidence in both directions, so a CIS safeguard also feeds the ISO Annex A control it supports.
Do you cover all 153 safeguards?
No product honestly does. Lojycal maps the subset it can evidence from live operational data — inventory, identity, configuration, logging, vulnerability and provider management. Safeguards that depend on physical security or human process remain manual, and every export states how many of the 153 are automated.
Will cyber insurers accept this?
Insurers increasingly ask for evidence behind self-assessed scores. The signed attestation pack gives them the score, the safeguard-level detail, and a signature they can verify independently — which is materially stronger than a completed questionnaire.
Where do I switch it on?
Policy Lab → Available frameworks (off) → Enable on the CIS Controls v8 card. It appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.
Stop self-assessing. Start measuring.
18 controls, scored from the estate you actually run, with the evidence attached.
