Skip to content

Implementation Group (IG)

Definition

A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers essential cyber hygiene applicable to all organisations. IG2 adds controls for organisations with dedicated security staff. IG3 covers advanced controls for high-risk environments. Most compliance crosswalks target IG1 as the minimum baseline.

Framework
CIS Controls
Total safeguards
153, divided across three tiers
IG1
56 safeguards, essential cyber hygiene for all organisations
Common baseline
IG1 used as the minimum in most compliance crosswalks

Common questions

How does an organisation decide which Implementation Group applies to it?+

The choice is based on organisational size, the sensitivity of data handled, and available security staffing and budget, rather than industry alone. A small business with limited IT capacity typically targets IG1, while an organisation with a dedicated security team and higher risk exposure moves to IG2 or IG3.

Is IG3 simply IG1 and IG2 with more controls added?+

Yes, the groups are cumulative. IG2 includes every IG1 safeguard plus additional ones, and IG3 includes everything in IG1 and IG2 plus the advanced safeguards suited to high-risk environments, so higher tiers are strict supersets rather than separate control sets.

Related terms

Crosswalk
A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
CIS Benchmark
A technology-specific configuration hardening guide published by CIS for operating systems, cloud services, databases, and applications. Each Benchmark provides Level 1 (broadly...
CIS Controls Self-Assessment Tool (CSAT)
A free web-based tool provided by CIS that allows organisations to score their current implementation status for each Safeguard and generate a...
CIS Controls V8
The eighth version of the CIS Critical Security Controls, released in May 2021. It consolidates 18 Controls and 153 Safeguards, reorganised from...
Control Catalogue
A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include...
Control Family
A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU...
Gap Analysis
The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial,...
Safeguard
The individual action item within a CIS Control. Each Safeguard specifies a concrete activity (for example, 'establish and maintain an accurate inventory...
Unified Control Mapping
An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.