CIS Controls v8

CIS Controls v8 — measured from your real estate, not a questionnaire.

CIS Controls v8 is the most operational security framework in circulation: 18 controls, 153 safeguards, and three implementation groups. Almost all of it is answerable from asset, identity, and endpoint data — which is exactly the data Lojycal already holds.

What CIS v8 actually demands

CIS is deliberately concrete. Every safeguard is a testable statement about your estate, which makes self-attestation by spreadsheet indefensible.

  • Controls 1 and 2 come first for a reason

    Inventory of enterprise assets and inventory of software assets underpin everything else. Get them wrong and every downstream safeguard measures nothing.

  • An honest implementation group

    IG1 (56 safeguards), IG2, or IG3. Claiming IG2 while failing IG1 safeguards is the most common self-assessment failure.

  • Continuous measurement

    Safeguards are stated as ongoing conditions — 'maintain', 'establish and maintain' — not one-time projects.

  • Evidence for each safeguard

    Insurers and enterprise buyers increasingly ask for the underlying data, not the self-assessed score.

The Lojycal CIS engine

The safeguards that are hardest to evidence manually are the ones Lojycal computes automatically.

Live asset and software inventory

Controls 1 and 2 answered directly from MDM, identity, network, and browser telemetry — including unmanaged and shadow assets.

Asset Lifecycle + Endpoint Governance

Safeguard scoring by IG

Each safeguard scored against live data with your declared implementation group, so the score is defensible rather than aspirational.

Policy Lab → CIS Controls v8

Configuration and access posture

Secure configuration, account management, and access-control safeguards evaluated from MDM baselines and IdP grants.

Endpoint Governance + RBAC

Attestation pack

Signed export of scores plus the underlying evidence per safeguard — the artefact cyber insurers actually want.

Trust Center → Evidence Pack

CIS v8 controls → Lojycal sources

A sampled view of the 18 controls and where the evidence originates:

ControlExample safeguardLojycal source
1 — Enterprise assetsMaintain a detailed asset inventoryAsset Lifecycle
2 — Software assetsMaintain an authorised software inventoryApplication Library
3 — Data protectionData inventory and retentionData Retention
4 — Secure configurationBaseline configuration on assetsEndpoint Governance
5 — Account managementInventory of accounts, disable dormantRBAC + HR Automation
6 — Access controlMFA for administrative accessAAL2 Enforcement
7 — Vulnerability managementRemediate detected vulnerabilitiesPatch Lab
8 — Audit log managementCollect and retain audit logsWORM Audit Log
12 — Network infrastructureMaintain network documentationInfrastructure Governance
15 — Service provider managementInventory and assess providersVendor Governance

Sampled — Lojycal ships a mapped subset of the 153 safeguards covering those it can evidence from live data. Safeguards requiring physical or procedural proof stay manual, and the export says so.

A score you can defend line by line

Self-attested CIS scores fall apart the moment someone asks for the data behind them.

Every safeguard score in Lojycal is a query over live inventory, identity, and configuration data — with the contributing records attached. The signed attestation pack carries both: the score and the evidence, with a detached signature an insurer or customer can verify without access to your tenant.

IG1 to a defensible score

Because Controls 1 and 2 populate from your connectors, the first score arrives in days.

  1. Week 1

    Inventory

    Connect MDM, identity, and SaaS. Controls 1 and 2 populate automatically, including unmanaged assets.

  2. Week 2–3

    Baseline score

    Score IG1 honestly. Fix the safeguards the data shows failing rather than the ones that feel risky.

  3. Week 4–10

    Climb

    Move to IG2 where it earns its keep, using drift alerts to hold gains.

  4. Ongoing

    Attest

    Export the signed attestation pack for insurers, customers, and the board.

CIS Controls v8 questions

Which implementation group should we target?

IG1 is the defined baseline of essential cyber hygiene and applies to every enterprise. IG2 suits organisations managing sensitive data across multiple departments; IG3 suits those with dedicated security functions and regulatory exposure. Lojycal scores against your declared group and flags where you are claiming above your evidence.

Is CIS v8 a substitute for ISO 27001 or NIS2?

No, but it is excellent scaffolding for both. CIS is prescriptive about what to do technically; ISO 27001 and NIS2 care about the management system around it. Lojycal maps the shared evidence in both directions, so a CIS safeguard also feeds the ISO Annex A control it supports.

Do you cover all 153 safeguards?

No product honestly does. Lojycal maps the subset it can evidence from live operational data — inventory, identity, configuration, logging, vulnerability and provider management. Safeguards that depend on physical security or human process remain manual, and every export states how many of the 153 are automated.

Will cyber insurers accept this?

Insurers increasingly ask for evidence behind self-assessed scores. The signed attestation pack gives them the score, the safeguard-level detail, and a signature they can verify independently — which is materially stronger than a completed questionnaire.

Where do I switch it on?

Policy Lab → Available frameworks (off) → Enable on the CIS Controls v8 card. It appears in Policy Lab, Endpoint Governance, and Shadow IT Lab immediately.

Stop self-assessing. Start measuring.

18 controls, scored from the estate you actually run, with the evidence attached.