Center for Internet Security

CIS v8 is a leading cybersecurity framework consisting of 18 Controls and multiple Safeguards within each Control. These Controls and Safeguards are applied to three different Implementation Groups. 

Policy Source TM has mapped each CIS Control and Safeguard by Implementation Group to the appropriate policies, enabling your organization to choose the right path for your cybersecurity requirements.

CIS v8 (19)

Access Management Policy

Asset Management Policy

Configuration Management Policy

Data Backup and Recovery Policy

Data Handling Policy

Data Management Policy

Data Retention Policy

Incident Management Policy

Internet Use Policy

Logging and Monitoring Policy

Malware Defense Policy

Network Management Policy

Password Policy

Patch Management Policy

Remote Access Policy

Security Training Policy

Software Management Policy

Third-Party Management Policy

Vulnerability Management Policy


CIS v8 (19)
Access Management Policy

Application Software Security Policy

Asset Management Policy

Configuration Management Policy

Data Backup and Recovery Policy

Data Classification Policy

Data Handling Policy

Data Management Policy

Data Retention Policy

Encryption Policy

Incident Management Policy

Internet Use Policy

Logging and Monitoring Policy

Malware Defense Policy

Network Management Policy

Password Policy

Patch Management Policy

Remote Access Policy

Security Training Policy

Software Management Policy

Third-Party Management Policy

Vulnerability Management Policy


CIS v8 (24)

Access Management Policy

Application Software Security Policy

Asset Management Policy

Configuration Management Policy

Data Backup and Recovery Policy

Data Classification Policy

Data Handling Policy

Data Management Policy

Data Retention Policy

Encryption Policy

End-User Computing Policy

Incident Management Policy

Internet Use Policy

Logging and Monitoring Policy

Malware Defense Policy

Mobile Device Management Policy

Network Management Policy

Password Policy

Patch Management Policy

Remote Access Policy

Security Training Policy

Software Management Policy

Third-Party Management Policy

Vulnerability Management Policy