CIS CONTROLS v8.1 · Cyber Hygiene Baseline

CIS CONTROLS v8.1RUN THE WORLD'S MOST-DEPLOYED CYBER BASELINE AS A MANAGED PROGRAM

Assess, prioritize, remediate, and prove CIS CONTROLS v8.1 from one platform — with AI governance and shadow-tool visibility built into the same workflow your auditors and insurers already ask about.

CIS CONTROLS IN 60 SECONDS

18 Controls, 153 Safeguards

CIS CONTROLS v8.1 is the prioritized cybersecurity baseline maintained by the Center for Internet Security — the same one insurers, regulators, and enterprise buyers anchor their questions to.

Scoped by Implementation Group

Every Safeguard is tagged IG1 (essential hygiene), IG2 (depth for growing organizations), or IG3 (advanced) so you size the program to your risk, not someone else's checklist.

Now in cyber-insurance and AG safe-harbor laws

Cyber-insurance applications, state attorney-general safe-harbor statutes, and enterprise vendor questionnaires all reference CIS v8.1 — and the same buyers now want AI governance evidence in the same breath.

THE CIS PROBLEM NOBODY WARNED YOU ABOUT

These are the gaps that stall cyber-hygiene programs — and quietly burn budget before auditors or insurers even arrive.

Problem 1

Cyber hygiene lives in spreadsheets

Security teams track 153 CIS Safeguards across tabs and screenshots, so coverage drifts, owners disappear, and audits stall before they start.

Problem 2

Implementation Groups get misapplied

Without a structured tool, organizations over-scope to IG3 and burn budget — or under-scope to IG1 and leave real exposure open.

Problem 3

AI and shadow IT outrun the baseline

New AI tools and agentic workloads land daily, but legacy cyber-hygiene programs have no way to fold them into CIS coverage — so the most volatile assets stay invisible.

WHAT YOU GET WITH RAIC

Buyer outcomes first. Every value below ties to a Safeguard your auditor, insurer, or enterprise customer already plans to test.

Full CIS CONTROLS v8.1 catalog, pre-loaded

All 18 Controls and 153 Safeguards ship pre-loaded, with the official Implementation Group (IG1, IG2, IG3) and Asset Type metadata on every row — no spreadsheet to maintain.

One-click Implementation Group scoping

Filter your program to IG1 essential hygiene, IG2 depth, or IG3 advanced, then track coverage and gaps live by Group so leadership sees progress in their language.

POA&M register plus evidence vault

Convert any Safeguard gap into a tracked remediation item with owner, due date, and status — then attach fingerprinted, hash-chained evidence so auditors and insurers verify proof rather than accept promises.

Crosswalks to the frameworks buyers ask about

Live mapping from every Safeguard to NIST CSF 2.0, ISO 27001, SOC 2, and the EU AI Act so one piece of evidence answers multiple questionnaires.

Board-ready reports and Aslan AI (Enterprise)

Capture posture snapshots for trend reporting, and ask plain-English questions cited against your live CIS data — built for the audiences that fund and govern the program.

WHAT'S INSIDE THE CIS MODULE

Each capability covers a named CIS Control family — and produces the artifact your auditor or insurer will request.

Asset and software inventory you can trust

Covers Controls 1 and 2 with a living register of enterprise and software assets, owners, and authorization status — the foundation every other Safeguard depends on.

Data protection and classification

Covers Control 3 with sensitivity tagging, handling rules, and evidence that protected data stays where your policies say it does.

Secure configuration and change discipline

Covers Controls 4 and 7 with baseline configuration tracking and vulnerability management workflows so drift and unpatched systems surface before attackers find them.

Account and access management

Covers Controls 5 and 6 with account inventory, privileged-access oversight, and access-review evidence aligned to your joiner-mover-leaver process.

Audit log management with retention

Covers Control 8 with logging coverage, retention proof, and review cadence — the evidence both insurers and incident responders ask for first.

Email, browser, and network defenses

Covers Controls 9, 12, and 13 with hardening posture, monitoring, and shadow-tool visibility — including the AI services employees adopt without telling IT.

Incident response with corrective action

Covers Control 17 with a documented response workflow, root cause, corrective action, and effectiveness verification — the artifacts auditors and regulators expect.

Penetration testing and continuous improvement

Covers Controls 18 and the awareness-training scope of Control 14 with scheduled testing, findings tracking, and training evidence tied back to the Safeguards they support.

PRICING THAT MATCHES YOUR CIS PROGRAM STAGE

Pick the tier that matches where your program sits today. Move up as your scope and reporting needs grow.

Professional — $499/month

CIS CONTROLS v8.1 hub, IG1/IG2/IG3 scoping, POA&M register, evidence vault, and standard reports included.

Enterprise — Custom

Adds Aslan AI Copilot, scheduled posture snapshots, multi-framework crosswalks, and MSP multi-tenant rollups.

MSP Partners — included per tenant

Deliver CIS CONTROLS assessments to every client tenant from the Partner Portal with no per-client license cost.

WHY MOVE NOW

Insurers, regulators, and enterprise buyers already anchor to CIS Controls v8.1 — and the same buyers now demand AI governance evidence alongside it. RAIC delivers both from one pane of glass.

  • Cyber-insurance applications already ask for CIS v8.1 coverage by Implementation Group — vague answers cost premium dollars.
  • State attorney-general safe-harbor laws cite CIS CONTROLS as a recognized standard — adoption is now a litigation shield, not a checkbox.
  • Enterprise vendor questionnaires bundle CIS coverage with explicit AI governance attestations — losing one loses the deal.
  • Shadow AI keeps expanding your asset surface — CIS coverage that ignores AI is already out of date.
All 18 Controls, all 153 Safeguards pre-loaded
IG1, IG2, IG3 scoping in one click
Crosswalks to NIST CSF 2.0, ISO 27001, SOC 2, EU AI Act
NEW · In-platform assessment

CIS Controls v8.1 Framework Assessment

Run a scored CIS Controls v8.1 readiness assessment inside RAIC and export the results — plus the underlying evidence — as an audit-ready download. Stop rebuilding the same gap analysis in spreadsheets.

Scored assessment

Question-by-question readiness scoring with maturity bands, owner assignment, and re-assessment cadence.

Mapped to the standard

Every item maps to all 18 Controls and 153 Safeguards across IG1, IG2, and IG3 — so a single answer drives both the score and the evidence trail.

Downloadable evidence

Export a branded DOCX report plus a ZIP of the underlying evidence (RhindonCyber_CIS-Controls-Assessment_*.docx + .zip) — ready to hand to your auditor.

Framework Assessment + downloadable evidence is available on ISO 42001, NIST AI RMF, EU AI Act, SOC 2, CIS Controls v8.1, and HIPAA.

TAKE THE NEXT STEP

Three doors. One team. Pick the one that fits where your CIS program is today.