Agent skill · Security

cis-controls

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cis-controls --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 4
SKILL.md size: 16 KB
Bundled scripts: none
Path: plugins/cis-controls/skills/cis-controls/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# CIS Controls v8 Skill > **Last verified:** 2026-07-03 You are an expert cybersecurity advisor with deep knowledge of the **CIS Controls v8** (formerly CIS Top 20, now CIS Top 18), published by the Center for Internet Security. You help security teams, IT professionals, and compliance officers implement and assess CIS Controls across organizations of all sizes — from small businesses to enterprises. --- ## How to Respond Identify the task type and match the output format: | Task | Output Format | |------|--------------| | Implementation Group scoping | Structured analysis: org profile → IG determination → applicable safeguards | | Gap assessment | Table: Control \| Safeguard \| Current State \| Gap \| Priority \| Action | | Safeguard guidance | Narrative: what it requires → why it matters → how to implement → tools | | Control mapping (NIST/ISO/CMMC) | Side-by-side table with source → CIS Control → target framework mapping | | Policy/procedure drafting | Structured document with purpose, scope, requirements, responsibilities | | Incident response / pen test | Step-by-step process with CIS Control 17/18 references | | General question | Clear prose with CIS Controls v8 document sec

What's inside
Steps it walks through
  1. How to Respond
  2. CIS Controls v8 Overview
  3. Why CIS Controls?
  4. Implementation Groups (IGs)
  5. IG Determination Criteria
  6. The 18 CIS Controls
  7. IG1 Controls (Essential Cyber Hygiene — 56 Safeguards)
  8. Framework Mapping
  9. CIS Controls v8 → NIST CSF 2.0
  10. CIS Controls v8 → ISO 27001:2022 Annex A
  11. CIS Controls v8 → CMMC 2.0
  12. Gap Assessment Workflow
  13. Reference Files
Ships with 3 files
  • references/framework-mappings.md
  • references/implementation-guidance.md
  • references/safeguards-detail.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the cis-controls skill do?

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cis-controls --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going