Skip to content

/cis-expert

CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cis-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cis-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.

SKILL.md

cis-expert.SKILL.md
name: cis-expert
description: CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.
allowed-tools: Read, Glob, Grep, Write

CIS Controls Expert

Deep expertise in CIS Controls v8, the baseline cybersecurity framework developed by the Center for Internet Security.

> **License notice.** This skill incorporates content derived from **CIS Controls v8**, © Center for Internet Security, Inc., used under the [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/) license. This file and other CIS-derived content in `plugins/frameworks/cis-controls/` are licensed under CC BY-SA 4.0 (the rest of the repository is MIT). See [LICENSE-CIS.md](../../LICENSE-CIS.md).

Expertise Areas

CIS Controls Overview

**Purpose**: Prioritized set of actions to defend against the most pervasive cyber threats **Authority**: Center for Internet Security (CIS) - global non-profit **Current Version**: CIS Controls v8 (May 2021) **Adoption**: Cross-industry standard, used globally by organizations of all sizes

**Key Principles**:

  • Offense informs defense (based on real-world attack data)
  • Prioritization (most impactful controls first)
  • Measurements and metrics
  • Continuous diagnostics and mitigation
  • Automation where possible

**Evolution from v7 to v8**:

  • Consolidated from 20 to 18 controls
  • Better alignment with Implementation Groups
  • Enhanced cloud and mobile coverage
  • Stronger integration with NIST CSF
  • More actionable safeguards (171 to 153 refined)

Implementation Groups (IG1, IG2, IG3)

The core innovation of CIS Controls: tailored security based on organizational maturity and risk.

IG1 - Essential Cyber Hygiene

**Target Audience**:

  • Small to medium businesses (typically <100 employees)
  • Limited IT security resources (1-2 generalist IT staff)
  • Organizations with low attack surface
  • Standard business risk profile
  • Minimal regulatory requirements

**Characteristics**:

  • **Safeguards**: 56 essential controls
  • **Resource Model**: Part-time security focus, leveraging generalist IT
  • **Budget**: $10,000 - $50,000 annually
  • **Expertise**: Basic IT competency, limited specialized security knowledge
  • **Tools**: Commercial off-the-shelf, small business focused

**Attack Profile IG1 Defends Against**:

  • Opportunistic attacks (phishing, commodity ransomware)
  • Automated vulnerability scanning and exploitation
  • Drive-by malware downloads
  • Script kiddies and unsophisticated actors
  • Social engineering targeting general workforce

**Example Organizations**:

  • Local retail stores
  • Small healthcare practices (1-3 doctors)
  • Professional services (law firms, accounting)
  • Regional nonprofits
  • K-12 schools (individual schools, not districts)
  • Small manufacturers

**Critical IG1 Safeguards**:

1. Asset and software inventory (1.1, 2.1) 2. Secure configurations (4.1, 4.2) 3. Account management (5.1, 5.3, 5.4) 4. Automated patching (7.3, 7.4) 5. Anti-malware (10.1, 10.2) 6. Backups (11.2, 11.3) 7. Security awareness (14.1)

IG2 - Enterprise Security

**Target Audience**:

  • Medium to large organizations (100-1,000 employees)
  • Dedicated IT team with security responsibilities
  • Moderate risk environment
  • Customer or patient data handling (PII, PHI)
  • Regulatory compliance needs (HIPAA, PCI-DSS)

**Characteristics**:

  • **Safeguards**: 128 total (56 from IG1 + 72 additional)
  • **Resource Model**: 1-3 dedicated security FTEs, larger IT team
  • **Budget**: $100,000 - $500,000 annually
  • **Expertise**: Security specialists, some advanced training
  • **Tools**: Enterprise-grade (SIEM, EDR, vulnerability management)

**Attack Profile IG2 Defends Against**:

  • Targeted phishing and spear-phishing campaigns
  • Ransomware-as-a-Service (RaaS) operators
  • Financially motivated cybercriminal groups
  • Business email compromise (BEC)
  • Credential stuffing and password spraying
  • Industrial espionage (mid-tier)
  • Supply chain attacks (lower sophistication)

**Example Organizations**:

  • Mid-sized healthcare systems (regional hospitals)
  • Community banks and credit unions
  • Manufacturing companies (100-500 employees)
  • SaaS startups (Series B/C)
  • School districts and community colleges
  • MSPs and IT service providers

**Critical IG2 Safeguards** (beyond IG1):

1. Multi-factor authentication (5.5) 2. Encryption (3.6, 3.10, 3.11) 3. Centralized logging and SIEM (8.9, 8.11) 4. Vulnerability scanning (7.5, 7.6) 5. Network segmentation (12.2) 6. IDS/IPS (13.2, 13.3) 7. Secure SDLC (16.1, 16.2) 8. Penetration testing (18.1, 18.2)

IG3 - Advanced Security

**Target Audience**:

  • Large enterprises (1,000+ employees)
  • Critical infrastructure organizations
  • High-value intellectual property
  • Known targets of nation-state actors
  • Stringent regulatory environments (CMMC Level 3, NERC CIP)

**Characteristics**:

  • **Safeguards**: 153 total (128 from IG2 + 25 additional)
  • **Resource Model**: Security Operations Center (SOC), 5+ security FTEs
  • **Budget**: $1,000,000+ annually
  • **Expertise**: Highly specialized (threat hunters, forensics, IR specialists)
  • **Tools**: Advanced threat detection, threat intelligence, SOAR platforms

**Attack Profile IG3 Defends Against**:

  • Advanced Persistent Threats (APTs)
  • Nation-state sponsored cyber espionage
  • Sophisticated ransomware groups (Conti, REvil successors)
  • Zero-day exploit campaigns
  • Insider threats (malicious and negligent)
  • Supply chain compromise (SolarWinds-level)
  • Living-off-the-land (LOTL) techniques
  • Multi-stage attacks with custom malware

**Example Organizations**:

  • Fortune 500 companies
  • Defense industrial base contractors
  • Major healthcare systems (multi-state)
  • Large financial institutions (national/global banks)
  • Energy sector (utilities, pipelines)
  • Telecommunications providers
  • Federal/state government agencies
  • Univers
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked