Compliance Guide

CIS Controls Compliance for Endpoints

A Practical Guide to CIS Controls v8.1's Endpoint Security Safeguards

The CIS Critical Security Controls are the most widely referenced prioritised action list in information security. Version 8.1's 18 controls and 153 safeguards are structured by Implementation Group so that organisations of any size can identify exactly what they need to do first. This guide maps the controls most directly enforced at the endpoint to Zecurit Endpoint Manager, giving IT and security teams an actionable compliance starting point.

Published byZecurit
CategoryCompliance & Regulation
AudienceIT Teams, Security Officers, Compliance Leads, MSPs

Why the CIS Controls Start and End at the Endpoint

At a Glance
  • What they are: The CIS Critical Security Controls are a prioritised set of 18 controls and 153 safeguards developed by the Center for Internet Security, derived from analysis of actual attack data to address the most prevalent and damaging threats first.
  • Who uses them: Organisations of every size, from small businesses working through Implementation Group 1 to enterprise security programmes aligning all three groups with frameworks such as NIST CSF, ISO 27001, and SOC 2.
  • Why endpoints dominate: Six of the first seven CIS Controls, covering asset inventory, software inventory, data protection, device configuration, account management, and vulnerability management, are primarily enforced at the endpoint device level.
  • How Zecurit helps: Hardware and software inventory, patch and vulnerability management, device control, configuration management, BitLocker encryption, and audit-ready reporting from a single agent and unified console.

The CIS Critical Security Controls, now in version 8.1, are maintained by the Center for Internet Security and are built differently from most compliance frameworks. Rather than beginning with risk assessment methodology or governance structure, they start with the most common attack patterns documented across real-world incidents and ask: what practical controls, implemented in this order, would have prevented or contained the most damage?

The result is a framework that security practitioners across government, enterprise, healthcare, and the SMB market reach for because it tells them what to do next, not just what to measure. The 2024 v8.1 revision refined safeguard language and clarified Implementation Group boundaries without restructuring the control set, making existing CIS programmes straightforward to maintain while giving new adopters the most precise guidance the framework has ever offered.

The Endpoint Concentration Problem: Analysis of the CIS Controls mapped against the MITRE ATT&CK framework consistently shows that more than 70 percent of the techniques adversaries use to achieve their objectives require access to or control of an endpoint. Inventory gaps, missing patches, unmanaged removable media, and weak local configurations are the entry points. The first seven CIS Controls exist because these are not theoretical risks — they are where actual breaches begin.

This guide maps CIS Controls v8.1's endpoint-relevant controls and safeguards to specific capabilities in Zecurit Endpoint Manager, so IT and security teams can move from the framework's language to operational, evidenced controls without rebuilding their toolkit.

Key Terminology Under CIS Controls v8.1

A handful of terms shape how the CIS Controls are structured and applied in practice:

  • CIS Control

    One of 18 high-level security domains, each addressing a category of risk. Controls are action-oriented: "Inventory and Control of Enterprise Assets", not "Asset Management Policy."

  • Safeguard

    A specific, implementable action within a control. Each control contains multiple safeguards; these are the individual testable items organisations track for compliance. CIS Controls v8.1 contains 153 safeguards in total.

  • Implementation Group (IG)

    A tiered prioritisation system. IG1 covers essential cyber hygiene for all organisations. IG2 adds controls for organisations with moderate resources and risk. IG3 covers the full set for security-mature enterprises.

  • Enterprise Asset

    v8.1's term for any device, physical or virtual, that is part of an organisation's environment. The shift from "system" to "asset" reflects the breadth of modern environments including cloud, containers, and IoT.

  • CIS Benchmarks

    Companion configuration guides produced by CIS for specific operating systems, applications, and cloud platforms. Benchmarks define the secure baseline that CIS Control 4 (Secure Configuration) references.

  • CIS RAM

    CIS Risk Assessment Method: a companion framework that helps organisations use the CIS Controls to conduct and document risk assessments, useful when aligning CIS with frameworks requiring formal risk treatment.

Who Uses CIS Controls?

CIS Controls adoption spans virtually every sector, precisely because the Implementation Group structure allows organisations to begin with the safeguards most critical to their size and risk profile rather than attempting a full 153-safeguard programme at once:

  • Small and mid-size businesses seeking a practical, prioritised starting point for cyber hygiene
  • Managed service providers building security baselines for client environments
  • US federal, state, and local government agencies aligning with CISA guidance
  • Healthcare organisations supplementing HIPAA with a technical controls framework
  • Financial services firms using CIS as an operational complement to NIST CSF or ISO 27001
  • SaaS and technology vendors demonstrating security posture to enterprise customers
  • Critical infrastructure operators mapping CIS Controls to sector-specific requirements
  • Organisations undergoing SOC 2 audits using CIS Controls as evidence of control implementation
Regulatory Alignment: CIS Controls v8.1 maps directly to NIST SP 800-53, NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022 Annex A, HIPAA Security Rule, and PCI DSS v4.0.1. For organisations managing compliance against multiple frameworks, CIS Controls frequently serve as the operational control layer that satisfies requirements across all of them simultaneously, reducing duplicated effort and consolidating evidence collection.

Implementation Groups: Where Your Organisation Sits

Implementation Groups are the CIS Controls framework's most practically useful feature. Rather than presenting all 153 safeguards as equally urgent, IGs sequence them by organisational risk and resource profile, letting any organisation begin with a coherent, achievable programme.

IG1 56 Safeguards

Essential Cyber Hygiene

The minimum set of controls every organisation should have in place. Designed for small teams with limited security expertise and budget. Addresses the most common, high-impact attack patterns. All IG1 safeguards are also required in IG2 and IG3.

IG2 +74 Safeguards

Moderate Risk Environments

For organisations with dedicated IT security staff managing multiple departments and handling more sensitive data. Adds detection, response, and more granular access controls on top of IG1's foundational hygiene.

IG3 +23 Safeguards

High-Risk and Enterprise

For security-mature organisations with dedicated security teams and complex environments. Adds advanced logging, incident response, penetration testing, and supply chain security controls suited to high-value targets and regulated sectors.

Endpoint Management Across All Groups: Controls 1 through 7, which cover asset inventory, software inventory, data protection, device configuration, account management, access control, and vulnerability management, contain safeguards across all three Implementation Groups. Organisations implementing even IG1 alone will touch six of these seven controls, and all of them require endpoint-level data and enforcement to satisfy.

CIS Controls v8.1: What Changed and Why It Matters

Current Version: CIS Controls v8.1 was published in 2024 as a targeted refinement of v8.0. It does not restructure the 18 controls or change the total number of safeguards. Organisations already implementing v8.0 will find the transition to v8.1 straightforward, with the revisions primarily clarifying ambiguities that practitioners had raised since v8.0's release.

The most substantive v8.1 changes affect safeguard language in Controls 1 through 4, the controls most directly associated with endpoint management. Several safeguard descriptions were sharpened to remove ambiguity about whether virtual assets, cloud-hosted workloads, and BYOD devices fall within scope; v8.1 confirms that they do, and that the same inventory, configuration, and vulnerability management expectations apply.

The v8.1 revision also clarified Implementation Group assignments for several safeguards that organisations had interpreted inconsistently in v8.0, particularly around automated patch management (CIS 7.3) and automated vulnerability scanning (CIS 7.5 and 7.6). These are now clearly IG1 requirements for automated patching and IG2 for authenticated scanning, resolving debate about how basic these expectations are meant to be. For most IT teams, this means the bar for what constitutes minimum viable vulnerability management has moved up rather than down.

CIS Controls v8.1 Mapped to Zecurit Endpoint Manager

The sections below translate each endpoint-relevant CIS Control and its key safeguards into the Zecurit Endpoint Manager capabilities that address them, with Implementation Group labels indicating the safeguards' priority tier.

CIS Control 1

Inventory and Control of Enterprise Assets

Safeguards 1.1 – 1.5  |  IG1 IG2 IG3

Actively manage, track, and correct all enterprise assets connected to the infrastructure, including end-user devices, network devices, IoT, and cloud instances. Only assets inventoried can be secured, patched, or monitored. Unmanaged devices represent the attack surface organisations cannot see.

Key safeguards require maintaining an up-to-date asset inventory (1.1), addressing unauthorised assets (1.2), and using active discovery tools to find assets not in the inventory (1.4). Safeguard 1.5 (IG2) adds DHCP logging to aid discovery, while 1.3 ensures DHCP server log data is used to update asset records.

Zecurit Endpoint Manager

Asset Discovery continuously scans the environment to surface every managed and unmanaged device, populating the Hardware Inventory with real-time data on each asset, including device type, OS, hostname, IP, and last-seen timestamps. Hardware Change Alerts in the Monitoring and Alerts module flag any new or modified device the moment it appears, giving IT teams the active inventory management Control 1 demands rather than a quarterly spreadsheet exercise.

Asset Discovery Hardware Inventory Hardware Change Alerts Real-Time Monitoring
CIS Control 2

Inventory and Control of Software Assets

Safeguards 2.1 – 2.7  |  IG1 IG2 IG3

Actively manage all software on enterprise assets so that only authorised software is installed and can execute. Unauthorised and unmanaged software is one of the primary vectors for malware delivery and data exfiltration. Safeguard 2.1 requires maintaining an authorised software inventory; 2.3 requires addressing unauthorised software; 2.5 and 2.6 add application allow-listing for higher-risk environments.

Zecurit Endpoint Manager

Software Inventory discovers and tracks every installed application across all managed endpoints in real time, including version numbers and installation dates. Software Change Alerts immediately notify IT teams when any unauthorised application is installed on a managed device, supporting both the inventory requirement and the unauthorised software response safeguard without requiring a manual audit cycle.

Software Inventory Software Alerts Software Licence Management Real-Time Monitoring
CIS Control 3

Data Protection

Safeguards 3.1 – 3.14  |  IG1 IG2 IG3

Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data. Safeguard 3.6 requires encryption of data on end-user devices. Safeguard 3.10 (IG1) requires that removable media be encrypted. Safeguard 3.11 (IG2) requires data classification and handling procedures. Safeguard 3.14 (IG2) adds logging for sensitive data access. These protections extend to data at rest on every managed endpoint.

Zecurit Endpoint Manager

BitLocker Management enforces full-disk encryption across every managed Windows endpoint from a central console, with TPM-only, TPM+PIN, and passphrase authentication modes, and automatic recovery key backup. BitLocker Compliance Reports surface any unencrypted device instantly. Device Control governs removable media connections with allow, block, or trusted-device-only policies, preventing unencrypted data movement through USB and external storage, supporting both 3.6 and 3.10 from a single platform.

BitLocker Management TPM Policy Management BitLocker Compliance Reports Device Control USB/Removable Storage Policies
CIS Control 4

Secure Configuration of Enterprise Assets and Software

Safeguards 4.1 – 4.12  |  IG1 IG2 IG3

Establish and maintain the secure configuration of enterprise assets and software. Safeguard 4.1 (IG1) requires establishing and maintaining a secure configuration process. Safeguard 4.2 (IG1) requires establishing and maintaining a secure configuration for end-user devices. Safeguard 4.5 (IG1) requires implementing and managing a firewall on end-user devices. Safeguard 4.8 (IG2) adds uninstallation or disabling of unnecessary services. Configuration drift between audit cycles is one of the most common causes of compliance failure and breach exposure.

Zecurit Endpoint Manager

Configuration Management enables IT teams to build named profiles that bundle firewall rules, Windows Update policies, power management settings, and security hardening parameters, then deploy and enforce them consistently across device groups. Hardware and Software Change Alerts detect the moment any endpoint deviates from its approved configuration baseline, giving CIS Control 4's monitoring requirement a continuous, automated implementation rather than a periodic manual review.

Configuration Management Centralised Profile Management Firewall Policy Management Hardware/Software Change Alerts
CIS Control 5

Account Management

Safeguards 5.1 – 5.6  |  IG1 IG2

Use processes and tools to assign and manage authorisation to credentials for user accounts, including administrator accounts, ensuring only authorised users can access enterprise assets. Safeguard 5.2 (IG1) requires using unique passwords and disabling default credentials. Safeguard 5.3 (IG1) requires disabling dormant accounts after a defined inactive period. Safeguard 5.4 (IG2) requires restricting administrator privileges to dedicated administrator accounts and not using them for day-to-day activities.

Zecurit Endpoint Manager

Configuration Management's User and Group Management module lets IT teams create, modify, disable, and remove local user accounts remotely across the entire fleet, enforcing password complexity and expiry policies consistently without requiring manual intervention on each device. Role-based access controls within the Zecurit console enforce the principle of least privilege for IT staff managing endpoints, and User Logon Reports provide the access history record that account governance safeguards require as evidence.

User and Group Management Password Policy Enforcement Role-Based Access User Logon Reports
CIS Control 6

Access Control Management

Safeguards 6.1 – 6.8  |  IG1 IG2 IG3

Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software. Safeguard 6.3 (IG1) requires requiring MFA for externally exposed applications. Safeguard 6.4 (IG2) extends MFA to all administrative access. Safeguard 6.5 (IG2) requires requiring MFA for remote network access. Safeguard 6.8 (IG3) adds centralised access control management for all assets.

Zecurit Endpoint Manager

Remote Access requires the end user on the managed device to explicitly confirm any incoming session before the IT administrator is granted access, adding a mandatory user-side verification layer to every remote session. Session logs record the initiating account, the accessed device, session duration, and timestamp, building the access history record Control 6's safeguards expect to see during a review or investigation. Role-based access within the Zecurit console ensures that only authorised staff can initiate remote sessions into specific device groups.

Remote Access Session Confirmation and Audit Role-Based Access User Logon Reports
CIS Control 7

Continuous Vulnerability Management

Safeguards 7.1 – 7.7  |  IG1 IG2 IG3

Develop a plan to continuously assess and track vulnerabilities in enterprise assets within the infrastructure, and remediate them based on risk. Safeguard 7.1 (IG1) requires establishing and maintaining a vulnerability management process. Safeguard 7.2 (IG1) requires establishing and maintaining a remediation process. Safeguard 7.3 (IG1) requires performing automated operating system patch management. Safeguard 7.4 (IG1) requires performing automated application patch management. Safeguards 7.5 and 7.6 (IG2) add internal and external authenticated vulnerability scanning. CIS Controls v8.1 clarified that automated patching is an IG1 baseline requirement, not an IG2 enhancement.

Zecurit Endpoint Manager

Patch Management continuously scans every managed endpoint for missing OS and third-party application patches, ranking them by CVSS score and active exploit intelligence so critical vulnerabilities surface first and can be deployed during defined maintenance windows. Vulnerability Management maps installed software against a live CVE database fleet-wide, giving security teams the continuous, prioritised vulnerability data that safeguards 7.1 through 7.6 require. Patch Compliance Reports document remediation timelines, providing the evidence that both the process and its execution are functioning as required.

Patch Management Vulnerability Management CVSS Prioritisation Patch Compliance Reports Automated Patch Deployment
CIS Control 9

Email and Web Browser Protections / Removable Media

CIS Control 10 — Safeguards 10.3 – 10.4  |  IG1 IG2

CIS Control 10 covers data recovery, but safeguards 10.3 and 10.4 apply directly to the endpoint: organisations must test the integrity of backups (10.3) and protect sensitive data by disabling the use of removable media on assets unless a documented business need exists (10.4, IG2). The removable media safeguard is among the most consistently overlooked IG2 requirements in endpoint hardening assessments.

Zecurit Endpoint Manager

Device Control enforces allow, block, or trusted-device-only policies for removable storage devices, Bluetooth peripherals, and wireless adapters across the entire managed fleet. BadUSB keystroke injection prevention protects against malicious USB device attacks, and policies remain in force even when an endpoint is offline, closing the gap that remote and travelling users create. Every connection attempt and policy enforcement event is logged with a timestamp, device ID, and user account for audit purposes.

Device Control USB/Removable Storage Policies BadUSB Protection Offline Policy Enforcement Audit Device Logs
CIS Control 8

Audit Log Management

Safeguards 8.1 – 8.12  |  IG1 IG2 IG3

Collect, alert, review, and retain audit logs of events that could help detect, understand, or recover from an attack. Safeguard 8.2 (IG1) requires collecting audit logs. Safeguard 8.3 (IG2) requires ensuring that audit logs are protected. Safeguard 8.5 (IG1) requires collecting detailed audit logs. Safeguard 8.9 (IG2) requires centralising, where possible, the collection of audit logs. Endpoints generate the most operationally relevant log data in most environments, and gaps in endpoint log coverage mean gaps in detection and forensics capability.

Zecurit Endpoint Manager

The Monitoring and Alerts module logs security, hardware, software, and user access events in real time across every managed endpoint, surfacing them in a unified console alongside configurable alert thresholds. User Logon Reports record access patterns by account and device, and Device Control logs every connection event with full metadata, building the comprehensive activity record that Control 8's safeguards define as a minimum baseline across all three Implementation Groups.

Real-Time Monitoring and Alerts Security Event Logging User Logon Reports Audit Device Logs
CIS Control 10 / 12

Malware Defences

CIS Control 10 (v8.1) — Safeguards 10.1 – 10.7  |  IG1 IG2 IG3

Prevent or control the installation, spread, and execution of malicious applications, code, and scripts on enterprise assets. Safeguard 10.1 (IG1) requires deploying and maintaining anti-malware software on all enterprise assets that support it. Safeguard 10.2 (IG1) requires configuring anti-malware software to scan automatically. Safeguard 10.6 (IG2) requires centrally managing anti-malware software. Disabled or out-of-date anti-malware on even a single unmonitored endpoint is consistently one of the first gaps an attacker locates and exploits.

Zecurit Endpoint Manager

Security Alerts in the Monitoring and Alerts module notify IT teams immediately when antivirus or antimalware protection is disabled, out of date, or has produced a threat detection on any managed endpoint. This closes the gap between a policy requiring anti-malware deployment and verified, continuous enforcement of it across the entire fleet, supporting both the deployment safeguard (10.1) and the centralised management safeguard (10.6) from a single console.

Security Alerts Antivirus Status Monitoring Real-Time Monitoring and Alerts Centralised Security Dashboard
Cross-Control

Compliance Reporting and Evidence for CIS Assessments

Supports CIS Controls 1, 2, 3, 4, 7, 8, 10 across all Implementation Groups

CIS Controls compliance is increasingly assessed through formal evaluations, whether internal security reviews, customer security questionnaires, regulatory alignment audits, or third-party CIS certification assessments. Producing evidence that the controls are operationally in place, not just documented in policy, requires data from the endpoint environment that is current, accurate, and exportable on demand.

Zecurit Endpoint Manager

Compliance and Reporting provides 100+ built-in report templates including pre-mapped templates for CIS Controls, ISO 27001, PCI-DSS, HIPAA, GDPR, and NIST. Security Reports surface BitLocker gaps, firewall status, antivirus health, patch compliance, and software inventory data across all managed endpoints in a single view. Scheduled Report Delivery automates evidence generation on a recurring basis, so the data is ready well ahead of any assessment rather than assembled reactively under deadline pressure.

100+ Compliance Reports CIS Controls Report Templates Scheduled Report Delivery Security Dashboard

CIS Controls v8.1 and Zecurit Endpoint Manager Capabilities

A consolidated reference mapping each endpoint-relevant CIS Control to the relevant Zecurit features and the Implementation Group that requires each safeguard.

CIS Control IG Zecurit Endpoint Manager Capability
Control 1: Asset Inventory IG1+ Asset DiscoveryHardware InventoryHardware Change Alerts
Control 2: Software Inventory IG1+ Software InventorySoftware AlertsSoftware Licence Management
Control 3: Data Protection (3.6, 3.10) IG1+ BitLocker ManagementDevice ControlBitLocker Compliance Reports
Control 4: Secure Configuration (4.2, 4.5) IG1+ Configuration ManagementCentralised Profile ManagementChange Alerts
Control 5: Account Management IG1+ User and Group ManagementPassword Policy EnforcementRole-Based Access
Control 6: Access Control (6.3 – 6.5) IG1+ Remote AccessSession Confirmation and AuditUser Logon Reports
Control 7: Vulnerability Management (7.1 – 7.6) IG1+ Patch ManagementVulnerability ManagementCVSS PrioritisationPatch Compliance Reports
Control 8: Audit Log Management IG1+ Real-Time Monitoring and AlertsUser Logon ReportsAudit Device Logs
Control 10: Malware Defences (10.1, 10.6) IG1+ Security AlertsAntivirus Status MonitoringCentralised Security Dashboard
Control 10: Removable Media (10.4) IG2+ Device ControlUSB/Removable Storage PoliciesBadUSB Protection
Cross-Control Compliance Evidence IG1+ 100+ Compliance ReportsCIS Controls TemplatesScheduled Report Delivery

CIS Controls Work When They Are Enforced at the Device

The CIS Critical Security Controls are built on a simple premise: the attacks most organisations face most often exploit the same small set of gaps. Unmanaged assets, out-of-date software, missing patches, weak configurations, uncontrolled removable media, and inactive antimalware are the recurring entry points, and six of the first seven CIS Controls exist specifically to close them.

What distinguishes successful CIS programmes from compliance paper exercises is not documentation: it is continuous enforcement at the endpoint, where these controls actually need to operate. Policy statements about asset inventory or patch management carry no weight in a security assessment or an incident investigation without the real-time data and evidence to back them up, device by device.

Zecurit Endpoint Manager addresses CIS Controls v8.1's core endpoint-relevant safeguards from IG1 upwards, from a single lightweight agent and unified console, giving IT and security teams the continuous asset visibility, automated patch management, configuration enforcement, device control, and audit-ready reporting that the CIS Controls framework was designed to produce as operational outcomes, not documentation artefacts.

About Zecurit

Zecurit develops cloud-based IT management solutions designed for modern IT teams. The Zecurit platform helps organisations manage endpoints, track assets, enforce security policies, and securely support distributed workforces through centralised, easy-to-use tools.

To learn more about Zecurit Endpoint Manager and how it supports your CIS Controls programme, start a free 14-day trial or contact the Zecurit team.

Contact Zecurit
Secret Link