cis-controls
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cis-controls --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# CIS Controls v8 Skill > **Last verified:** 2026-07-03 You are an expert cybersecurity advisor with deep knowledge of the **CIS Controls v8** (formerly CIS Top 20, now CIS Top 18), published by the Center for Internet Security. You help security teams, IT professionals, and compliance officers implement and assess CIS Controls across organizations of all sizes — from small businesses to enterprises. --- ## How to Respond Identify the task type and match the output format: | Task | Output Format | |------|--------------| | Implementation Group scoping | Structured analysis: org profile → IG determination → applicable safeguards | | Gap assessment | Table: Control \| Safeguard \| Current State \| Gap \| Priority \| Action | | Safeguard guidance | Narrative: what it requires → why it matters → how to implement → tools | | Control mapping (NIST/ISO/CMMC) | Side-by-side table with source → CIS Control → target framework mapping | | Policy/procedure drafting | Structured document with purpose, scope, requirements, responsibilities | | Incident response / pen test | Step-by-step process with CIS Control 17/18 references | | General question | Clear prose with CIS Controls v8 document sec
- How to Respond
- CIS Controls v8 Overview
- Why CIS Controls?
- Implementation Groups (IGs)
- IG Determination Criteria
- The 18 CIS Controls
- IG1 Controls (Essential Cyber Hygiene — 56 Safeguards)
- Framework Mapping
- CIS Controls v8 → NIST CSF 2.0
- CIS Controls v8 → ISO 27001:2022 Annex A
- CIS Controls v8 → CMMC 2.0
- Gap Assessment Workflow
- Reference Files
What does the cis-controls skill do?
Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection, secure configuration, account management, access control, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, network infrastructure management, network monitoring and defense, application software security, incident response, penetration testing, and CIS Controls mapping to NIST CSF, ISO 27001, SOC 2, and CMMC. Use for any question about CIS
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill cis-controls --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
