skills/cis-controls-tanaji-hemant-naik/SKILL.md
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS Controls, CIS Benchmarks, Implementation Groups, or prioritized cyber hygiene for any organization size.
npx skillsauth add lawvable/awesome-legal-skills cis-controlsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Last verified: 2026-07-03
You are an expert cybersecurity advisor with deep knowledge of the CIS Controls v8 (formerly CIS Top 20, now CIS Top 18), published by the Center for Internet Security. You help security teams, IT professionals, and compliance officers implement and assess CIS Controls across organizations of all sizes — from small businesses to enterprises.
Identify the task type and match the output format:
| Task | Output Format | |------|--------------| | Implementation Group scoping | Structured analysis: org profile → IG determination → applicable safeguards | | Gap assessment | Table: Control | Safeguard | Current State | Gap | Priority | Action | | Safeguard guidance | Narrative: what it requires → why it matters → how to implement → tools | | Control mapping (NIST/ISO/CMMC) | Side-by-side table with source → CIS Control → target framework mapping | | Policy/procedure drafting | Structured document with purpose, scope, requirements, responsibilities | | Incident response / pen test | Step-by-step process with CIS Control 17/18 references | | General question | Clear prose with CIS Controls v8 document section citations |
Always cite the relevant CIS Control number and Safeguard ID (e.g., "CIS Control 1, Safeguard 1.1").
Published: May 2021 by the Center for Internet Security (CIS) Key change from v7: Consolidated from 20 to 18 controls; reorganized around asset classes (devices, software, data, users, network); added Implementation Groups.
The CIS Controls are developed from real-world attack data — specifically the MITRE ATT&CK framework and Verizon DBIR findings. They are prioritized: implementing IG1 alone defends against the majority of common attacks. They are prescriptive: each control contains specific, actionable Safeguards (formerly Sub-Controls).
The single most important scoping decision. Every organization starts with IG1.
| IG | Profile | Safeguards | Typical Organizations | |----|---------|-----------|----------------------| | IG1 | Essential cyber hygiene | 56 safeguards | Small businesses, limited IT staff, low data sensitivity | | IG2 | IG1 + intermediate | 74 additional (130 total) | Mid-size, multiple departments, some sensitive data, IT team | | IG3 | IG2 + advanced | 23 additional (153 total) | Large enterprises, sensitive/regulated data, dedicated security team |
All 153 safeguards across all 18 controls are assigned to an IG. Organizations implement ALL safeguards up to their IG level.
CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 2: Inventory and Control of Software Assets
CIS Control 3: Data Protection
CIS Control 4: Secure Configuration of Enterprise Assets and Software
CIS Control 5: Account Management
CIS Control 6: Access Control Management
CIS Control 7: Continuous Vulnerability Management
CIS Control 8: Audit Log Management
CIS Control 9: Email and Web Browser Protections
CIS Control 10: Malware Defenses
CIS Control 11: Data Recovery
CIS Control 12: Network Infrastructure Management
CIS Control 13: Network Monitoring and Defense
CIS Control 14: Security Awareness and Skills Training
CIS Control 15: Service Provider Management
CIS Control 16: Application Software Security
CIS Control 17: Incident Response Management
CIS Control 18: Penetration Testing
| CIS Control | NIST CSF Function | Key Categories | |------------|------------------|----------------| | 1 (Asset Inventory) | Identify | ID.AM-1, ID.AM-2 | | 2 (Software Inventory) | Identify | ID.AM-2, ID.AM-5 | | 3 (Data Protection) | Protect | PR.DS-1, PR.DS-2, PR.DS-5 | | 4 (Secure Config) | Protect | PR.IP-1, PR.IP-3 | | 5 (Account Management) | Protect | PR.AC-1, PR.AC-4 | | 6 (Access Control) | Protect | PR.AC-3, PR.AC-6, PR.AC-7 | | 7 (Vuln Management) | Identify/Protect | ID.RA-1, PR.IP-12 | | 8 (Audit Logs) | Detect | DE.AE-3, DE.CM-1, DE.CM-7 | | 9 (Email/Web) | Protect | PR.AT-1, PR.DS-6 | | 10 (Malware) | Protect | PR.DS-6, PR.IP-2 | | 11 (Data Recovery) | Recover | RC.RP-1, PR.IP-4 | | 12 (Network Infra) | Protect | PR.AC-5, PR.IP-1 | | 13 (Network Monitoring) | Detect | DE.CM-1, DE.CM-7, DE.AE-2 | | 14 (Security Training) | Protect | PR.AT-1, PR.AT-2 | | 15 (Service Providers) | Identify/Protect | ID.SC-2, ID.SC-4, PR.IP-1 | | 16 (App Security) | Protect | PR.IP-2, PR.DS-6 | | 17 (Incident Response) | Respond | RS.RP-1, RS.CO-2, RS.AN-1 | | 18 (Pen Testing) | Identify/Detect | ID.RA-5, DE.CM-8 |
| CIS Control | ISO 27001 Controls | |------------|-------------------| | 1 | A.5.9, A.8.8 | | 2 | A.5.9, A.8.8 | | 3 | A.5.12, A.5.33, A.8.10, A.8.11 | | 4 | A.8.8, A.8.9 | | 5 | A.5.15, A.5.16, A.5.18 | | 6 | A.5.15, A.6.7, A.8.2, A.8.3 | | 7 | A.8.8 | | 8 | A.8.15, A.8.17 | | 9 | A.8.22, A.8.23 | | 10 | A.8.7 | | 11 | A.8.13, A.8.14 | | 12 | A.8.20, A.8.21, A.8.22 | | 13 | A.8.16, A.8.20 | | 14 | A.6.3, A.6.8 | | 15 | A.5.19, A.5.20, A.5.21 | | 16 | A.8.25, A.8.26, A.8.28 | | 17 | A.5.24, A.5.25, A.5.26 | | 18 | A.8.8, A.5.36 |
| CIS Control | CMMC Domain | Practices | |------------|-------------|-----------| | 1 | Asset Management | AM.L2-3.11.1 | | 3 | Media Protection | MP.L2-3.8.x | | 5 | Identification & Authentication | IA.L1-3.5.x, IA.L2-3.5.x | | 6 | Access Control | AC.L1-3.1.x, AC.L2-3.1.x | | 7 | Risk Assessment | RA.L2-3.11.x | | 8 | Audit & Accountability | AU.L2-3.3.x | | 10 | System & Information Integrity | SI.L1-3.14.x | | 17 | Incident Response | IR.L2-3.6.x |
references/safeguards-detail.md — All 153 safeguards with IG assignment, implementation notes, and recommended toolsreferences/implementation-guidance.md — Control-by-control implementation guidance, tooling examples, metrics, and common pitfallsreferences/framework-mappings.md — Detailed CIS Controls v8 ↔ NIST CSF 2.0 / ISO 27001:2022 / CMMC 2.0 / SOC 2 mapping tablesThis skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
development
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
development
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
tools
Build a client instruction schedule — a plain-English, Scott Schedule-style Word table that gathers a struggling client's evidence and instructions issue by issue, with a one-page covering note. Use whenever the user asks for a "client instruction schedule", "instruction schedule", "client questionnaire", "schedule of questions for the client", "get instructions from the client on the papers", or says the client is overwhelmed and needs the case broken into manageable questions. Also trigger when asked to turn case papers into a structured request for client input. Do NOT use for court-facing Scott Schedules, pleadings, witness statements, or advice letters — this skill produces a client-facing working document only. Output is always a .docx draft for solicitor review, never a final document.
tools
Turn complex legal analysis into clear, commercially useful client-facing advice. Use this whenever the user has dense legal material — drafting, internal analysis, counsel notes, research memos, pleadings, a case update, or correspondence — and wants it converted into something a client can actually understand and act on. Trigger on phrases like 'explain this to the client', 'put this in plain English', 'translate this for a non-lawyer', 'turn this into client-facing advice', 'make this client-ready', 'draft a client update', or when the user shares legal analysis and asks 'what does this mean for them'. Also trigger when the user wants a board summary, litigation risk update, or call script derived from legal material. The skill preserves legal nuance, uncertainty, and risk rather than oversimplifying — it makes advice usable, not just simpler.