Compliance — CIS Controls managed services
Managed services for the CIS Critical Security Controls v8.1
Continuous monitoring, evidence generation, and 24x7 response across the operational CIS Controls — delivered by ManySignal analysts and AI agents so your IG1 or IG2 baseline is real, not a spreadsheet.
18
Critical Security Controls in CIS v8.1
153
Safeguards across IG1, IG2, and IG3
10+
Controls with primary or supporting ManySignal coverage
24x7
Analyst plus AI-agent monitoring against your CIS baseline
Continuous CIS evidence, not point-in-time screenshots
The CIS Critical Security Controls are only as useful as the evidence you can produce that they are working. ManySignal's managed CIS service runs the operational Controls — logging, monitoring, malware defence, incident response — and generates the evidence as a by-product of the work, day after day.
Control 4 — Secure Configuration monitoring
ManySignal continuously watches configuration state across endpoints, servers, cloud accounts, and network devices, flagging drift from the CIS Benchmarks baseline before it becomes an audit finding or an attacker foothold.
Control 6 — Access Control Management
Every identity event — provisioning, privilege escalation, MFA bypass, dormant account activity — is correlated on an entity graph so joiner/mover/leaver evidence for CIS 6.1-6.8 is produced automatically.
Control 8 — Audit Log Management
Centralised audit log collection with retention, integrity hashing, and time synchronisation checks satisfies safeguards 8.1 through 8.12, and every log is reviewed by an AI triage agent rather than sampled.
Control 10 — Malware Defenses
EDR telemetry lands in the same graph as identity and network signals, so anti-malware coverage, signature freshness, and detonation outcomes for CIS 10.1-10.7 are visible in one place with evidence attached.
Control 13 — Network Monitoring and Defense
Behavioural baselines per asset, east-west traffic inspection, and IDS/IPS alert triage deliver the continuous network monitoring that safeguards 13.1, 13.3, 13.6, and 13.11 require without a second SIEM.
Control 17 — Incident Response Management
A documented IR process with 24x7 analyst-plus-agent response, tabletop artefacts, and post-incident reports produces the evidence CIS 17.1-17.9 asks for — with mean time to detect and respond tracked per case.
CIS Control to ManySignal managed capability
Ten of the eighteen CIS v8.1 Controls have direct operational coverage inside a ManySignal managed service. Each row below is a real capability with generated evidence, not a checkbox mapping.
| CIS v8.1 Control | ManySignal managed capability |
|---|---|
| CIS 4 — Secure Configuration of Enterprise Assets and Software | Continuous CIS Benchmark drift detection across OS, containers, and cloud accounts with owner-routed remediation tickets |
| CIS 5 — Account Management | Identity inventory reconciled against HR source of truth; dormant, shared, and orphaned accounts surfaced with evidence |
| CIS 6 — Access Control Management | MFA coverage, privilege escalation, and access review evidence generated per user, per system, per quarter |
| CIS 7 — Continuous Vulnerability Management | Authenticated scan ingestion with risk-adjusted prioritisation and closure evidence for the monthly report |
| CIS 8 — Audit Log Management | Central log collection, tamper-evident retention, and 100% AI review of security-relevant events rather than sampling |
| CIS 10 — Malware Defenses | EDR coverage monitoring, detonation triage, and signature freshness reporting across managed endpoints |
| CIS 13 — Network Monitoring and Defense | 24x7 network anomaly detection with behavioural baselines, IDS triage, and east-west visibility |
| CIS 14 — Security Awareness and Skills Training | Phishing simulation ingestion and role-based training completion tracking rolled into the compliance evidence pack |
| CIS 16 — Application Software Security | SAST/DAST/SCA finding ingestion, deduplication, and SLA tracking against the CIS 16 safeguards |
| CIS 17 — Incident Response Management | Documented IR runbooks, 24x7 analyst-and-agent response, tabletop artefacts, and post-incident reports |
Choosing an Implementation Group
CIS defines three Implementation Groups so organisations can adopt the Controls at a level that matches their risk, resources, and expertise. Most managed-service buyers target IG1 or IG2 as their contracted baseline.
-
IG1 — Essential cyber hygiene
56 Safeguards. Suitable for SMBs with limited security expertise and lower sensitivity data. This is the CIS-defined minimum for every enterprise.
-
IG2 — Growing organisation
130 Safeguards total (74 additional). Multiple departments with differing risk, some regulated data, and a security function that needs to demonstrate maturity to customers.
-
IG3 — Mature enterprise
153 Safeguards total (23 additional). Large organisations with regulated data, dedicated security staff, and adversary-aware programs. Typically layered on top of an IG2 baseline for high-value systems.
What ends up in the quarterly CIS evidence pack
- Asset and software inventory reconciliation (Controls 1 and 2)
- Secure configuration drift against CIS Benchmarks (Control 4)
- Account management and privileged access review evidence (Controls 5 and 6)
- Vulnerability scan coverage and closure metrics (Control 7)
- Audit log completeness, retention, and review coverage (Control 8)
- Malware defence coverage and detonation outcomes (Control 10)
- Network monitoring anomaly counts and dispositions (Control 13)
- Incident response cases with MTTD, MTTR, and lessons learned (Control 17)
CIS Controls managed services — buyer questions
What are the CIS Critical Security Controls?
The CIS Critical Security Controls are a prioritised set of cybersecurity best practices published by the Center for Internet Security. Version 8, released in 2021 and updated to v8.1 in 2024, consolidates the previous 20 controls into 18 Controls containing 153 Safeguards. They are informed by real-world attack data and are widely used as a reference for organisations that need a defensible baseline without adopting a heavier framework like NIST 800-53. Managed CIS Controls services from ManySignal cover the operational safeguards — logging, monitoring, malware defence, incident response, and access control — that most organisations struggle to run in-house.
How are CIS v7, v8, and v8.1 different?
CIS v7 had 20 Controls and organised sub-controls into three Implementation Groups. CIS v8 (2021) restructured this to 18 Controls and 153 Safeguards, merging Boundary Defense and Data Protection into activity-based controls that reflect modern cloud and remote-work environments. CIS v8.1 (2024) added governance mapping, aligned language with NIST CSF 2.0, and clarified safeguard descriptions without changing the numbering. ManySignal's managed services map to v8.1 by default and support v7 evidence generation for organisations mid-transition or audited against v7-era contracts. There is no CIS 2.0 — that phrasing usually refers to either CSF 2.0 or the CIS v8 major revision.
What are the three CIS Implementation Groups?
Implementation Group 1 (IG1) is the essential cyber hygiene baseline — 56 Safeguards suitable for small and mid-sized organisations with limited security expertise. IG2 (74 additional safeguards, 130 total) covers organisations with multiple departments and moderate risk. IG3 (23 additional safeguards, 153 total) is aimed at large enterprises with mature security programs and regulated data. Buyers of managed CIS services usually target IG1 or IG2 coverage as their contracted baseline, with selective IG3 safeguards for regulated systems.
Why buy managed services for CIS Controls rather than run them in-house?
Three practical reasons. First, the skills gap — Controls 8, 10, 13, and 17 require continuous analyst attention that most organisations cannot staff 24x7. Second, evidence generation — auditors want continuous evidence, not point-in-time screenshots, and generating that manually consumes disproportionate engineering time. Third, tooling economics — buying a SIEM, EDR, vulnerability scanner, and GRC platform separately costs more than a managed service that consolidates them. ManySignal delivers all three: analyst plus AI-agent coverage 24x7, evidence generated as a by-product of the work, and a consolidated platform rather than a stack of point tools.
Which CIS Controls does ManySignal primarily cover?
Primary operational coverage for Controls 4 (Secure Configuration), 6 (Access Control), 7 (Vulnerability Management), 8 (Audit Log Management), 10 (Malware Defenses), 13 (Network Monitoring and Defense), and 17 (Incident Response). Supporting coverage for Controls 1 and 2 (Asset and Software Inventory), 5 (Account Management), 14 (Security Awareness — tracking and evidence, not content delivery), and 16 (Application Software Security). Controls 3 (Data Protection), 9 (Email/Browser Protection), 11 (Data Recovery), 12 (Network Infrastructure Management), 15 (Service Provider Management), and 18 (Penetration Testing) are typically outside the managed-service scope and remain a customer or partner responsibility.
Get the CIS v8.1 coverage matrix
Request the full ManySignal to CIS v8.1 Safeguard mapping, sample quarterly evidence pack, and a scoping call for IG1 or IG2 adoption.