CIS Controls List for Small Organizations: Turn 18 Controls into a Workable Security Plan — Datapath managed IT, cybersecurity, and compliance
Back to Blog
GENERAL Insights Published September 11, 2026 Updated September 11, 2026 9 min read

CIS Controls List for Small Organizations: Turn 18 Controls into a Workable Security Plan

For a small organization, the CIS Controls list is not an 18-item shopping spree. Start with CIS Controls v8.1 Implementation Group 1: inventory what exists.

David Darmstandler, Co-CEO & Co-Founder at Datapath

By

David Darmstandler

Co-CEO & Co-Founder

backup and recoveryCentral Valleyco-managed IT

Quick summary

  • For a small organization, the CIS Controls list is not an 18-item shopping spree. Start with CIS Controls v8.1 Implementation Group 1: inventory what exists, control accounts, secure configurations, protect email and data, recover deliberately, and assign owners who can prove the work.
  • What is the CIS Controls list for small organizations?
  • How should a small organization prioritize the 56 IG1 safeguards?

For a small organization, the CIS Controls list is not an 18-item shopping spree. Start with CIS Controls v8.1 Implementation Group 1: inventory what exists, control accounts, secure configurations, protect email and data, recover deliberately, and assign owners who can prove the work.

At 7:08 a.m. in a Ceres K-12 district, the technology coordinator is trying to get a substitute teacher online before the first bell. A Chromebook appears on the wireless network with an old asset tag, an unapproved browser extension, and no clear owner. Blocking it could interrupt the morning schedule. Allowing it could create an unmanaged path into staff accounts and student systems.

That is the practical moment when the CIS Controls list becomes useful. It gives the coordinator a sequence of decisions: Do we know this device? Is its software authorized? Is the user account appropriate? Is the device configured securely? Can we detect suspicious activity and recover if something goes wrong?

This is a better starting point for a small organization than buying another security product and hoping it closes the gap. We use the list to create accountable work: an owner, a due date, a technical change, and evidence that the change actually happened.

What is the CIS Controls list for small organizations?

The CIS Critical Security Controls are a prioritized set of cybersecurity practices. The current list covered here is CIS Controls v8.1, which contains 18 controls and incorporates revised safeguard descriptions and a governance function.1

The important distinction is between a control and a safeguard. A control is the broad outcome, such as Inventory and Control of Enterprise Assets. Safeguards are the specific actions underneath it, such as maintaining an asset inventory or removing unauthorized devices.

For a smaller organization, the practical entry point is Implementation Group 1, or IG1. CIS describes IG1 as essential cyber hygiene and a foundational set of 56 safeguards intended for organizations with limited cybersecurity expertise and limited tolerance for downtime.2

That does not mean every small organization has the same risk. A 40-person accounting firm, a rural clinic, a school district, and a public-safety dispatch center may all begin with IG1, but they will prioritize different systems and recovery requirements.

The complete CIS Controls list, translated into decisions

Use the table below as a working backlog rather than a compliance checklist. The Wave column is our recommended order for a small organization that needs to reduce uncertainty quickly.

WaveCIS ControlThe decision it should forceUseful evidence
11. Inventory and Control of Enterprise AssetsDo we know every workstation, server, mobile device, network device, and cloud asset connected to the environment?Current asset inventory with owner and location
12. Inventory and Control of Software AssetsIs every installed application authorized and supportable?Software inventory and exception list
13. Data ProtectionWhat sensitive data do we hold, where does it live, and who needs it?Data locations, retention rules, access list
14. Secure Configuration of Enterprise Assets and SoftwareAre devices built from a known secure baseline?Configuration standard and scan results
15. Account ManagementWhich accounts exist, who owns them, and which accounts are stale?Joiner-mover-leaver records and account review
16. Access Control ManagementDoes each person have only the access required for the job?Role-based access matrix and approvals
27. Continuous Vulnerability ManagementWhich weaknesses require action first, and who tracks them to closure?Vulnerability register with priority and due date
28. Audit Log ManagementWhich events would help us understand an account takeover or system failure?Central log sources, alert rules, retention record
19. Email and Web Browser ProtectionsCan we reduce phishing, malicious links, spoofing, and unsafe browsing?Email security settings and phishing-report workflow
110. Malware DefensesHow do we prevent, detect, and contain malicious code?Endpoint protection coverage and response records
111. Data RecoveryCan we restore the systems needed for the next business day?Backup inventory, restore results, recovery priorities
212. Network Infrastructure ManagementAre firewalls, switches, wireless networks, and remote access devices managed and hardened?Network diagram, device inventory, configuration backups
213. Network Monitoring and DefenseWho notices unusual traffic, and what happens after the alert?Monitoring coverage, alert triage, escalation record
214. Security Awareness and Skills TrainingDo employees know how to report phishing, suspicious behavior, or lost equipment?Training completion and simulated-report results
215. Service Provider ManagementWhich vendors can access systems or sensitive information, and what do contracts require?Vendor register, access review, security terms
316. Application Software SecurityIf we develop, host, or customize software, how are weaknesses found before release?Development review, change record, remediation log
217. Incident Response ManagementWho makes decisions during an incident, and how will operations continue?Incident plan, contact list, exercise notes
318. Penetration TestingHow will we test whether important controls withstand an attacker?Scope, findings, remediation and retest report

The list and descriptions above follow CIS’s published v8.1 control enumeration.1 The order is not a claim that Wave 3 is unimportant. It reflects a common small-organization reality: penetration testing and application security are difficult to manage well when the organization cannot yet answer basic questions about assets, accounts, configurations, backups, and ownership.

How should a small organization prioritize the 56 IG1 safeguards?

Start with the systems that support a real operating workflow. Do not begin by assigning every safeguard to an abstract security program. Ask what must work at a specific moment:

  • A school needs identity, wireless access, classroom devices, student information systems, and the bell schedule to function.
  • A clinic needs staff access to its EHR and a documented downtime process if the system is unavailable.
  • A finance team needs email protection, approval controls, and a reliable wire-approval workflow.
  • A public-safety agency needs dispatch, radio-support systems, evidence retention, and a clear escalation path.
  • A 100-plus-employee business needs dependable identity, endpoint, Microsoft 365, file, and vendor-access controls.

Then assign each high-impact system four owners: a business owner, a technical owner, an approval owner, and an incident contact. CISA guidance similarly emphasizes identifying a named role accountable for cybersecurity and maintaining a recurring asset inventory; its guidance calls for an inventory updated at least monthly.3

That accountability is where many small-organization programs fail. A spreadsheet can say that multifactor authentication is planned. It cannot tell you who will enable it, which legacy system cannot support it, what compensating control applies, or when the exception expires.

Treat identity as an operating control

Account Management and Access Control Management are not merely password topics. They govern onboarding, job changes, departures, administrator accounts, service accounts, vendors, and emergency access.

For example, a small medical practice might have 28 employees but more than 28 identities once billing vendors, EHR integrations, former staff, shared mailboxes, and administrator accounts are counted. The useful question is not how many employees the organization has. It is how many paths can reach an important system.

CISA guidance recommends password policies of at least 15 characters where technically feasible and recommends multifactor authentication for organizational accounts, with priority given to higher-risk and administrative access.3 In practice, we would document exceptions for devices or applications that cannot support the standard rather than quietly excluding them from the program.

Turn configuration into a repeatable baseline

Control 4 becomes useful when it produces a standard that someone can compare against. A baseline might cover:

  • Supported operating-system versions and patch status
  • Local administrator rights
  • Screen-lock and encryption settings
  • Endpoint protection status
  • Microsoft 365 security settings
  • Firewall, wireless, and remote-access configuration
  • Approved browser extensions and installed applications

A baseline also needs an exception process. A laboratory instrument, dispatch workstation, or older student-information-system component may not support the preferred configuration. The control is not pretending that the exception does not exist. The control is documenting the risk, limiting exposure, assigning an owner, and setting a replacement or review date.

What should a 30-day CIS Controls rollout look like?

A small organization can create useful momentum without claiming that the entire program is finished in one month. We recommend four short stages.

Days 1–5: establish the truth

Export endpoint, network, cloud, and user inventories. Remove duplicates. Identify unknown devices and stale accounts. Mark the systems that support revenue, patient care, instruction, dispatch, evidence, or financial approval.

The deliverable is not a polished dashboard. It is a short list of assets and accounts that someone can explain.

Days 6–10: close the obvious access gaps

Disable departed users, separate administrator accounts from ordinary user accounts, require stronger authentication for privileged access, and review vendor access. Confirm that the organization can identify who approved each exception.

Days 11–20: make recovery real

Map the systems that must be restored first. Confirm backup coverage, separation from production systems, access protection, and recovery ownership. CISA guidance recommends regular backups, separate storage, recurring testing, and incident-response plans that are practiced and updated.

For a school, that may mean testing restoration of a critical file share and documenting how staff operate during a student-information-system outage. For a clinic, it may mean walking through EHR downtime documentation and communications. For a finance team, it may mean confirming that payment approvals do not depend on one person’s mailbox.

Days 21–30: rehearse the decision path

Run a short tabletop exercise. Give the team a scenario such as a compromised administrator account, ransomware on a file server, or an unknown device on the internal network. Record who isolates the device, who contacts leadership, who communicates with staff, and who decides when a system can return to service.

The output should be a prioritized remediation list, not a dramatic score. A useful list says: fix, owner, deadline, business impact, and proof required.

When should a small organization connect CIS Controls to a regulated framework?

CIS Controls can organize the work, but they do not automatically satisfy every sector-specific obligation. The mapping must follow the organization’s actual systems, contracts, data, and applicable rules.

For a Central Valley public-safety or local-government team, this distinction matters. The FBI’s CJIS Security Policy v54.9.5 includes requirements and implementation guidance covering access control, incident response, contingency planning, alternate storage, and backups for systems handling criminal justice information. A team should therefore map its CIS work to the applicable CJIS requirements rather than describe a generic CIS score as proof of CJIS compliance.

Datapath can help a public-safety organization build that crosswalk through our CJIS compliance services, while a school district can use the same operational method through our K-12 IT team. The framework changes; the discipline does not: identify the system, assign the owner, implement the safeguard, test it, and retain evidence.

What should you expect from an IT or security partner?

A commodity support provider can close tickets. A security-minded partner should help you operate the controls after the initial project. Ask for:

  • A named technical and security team, not an anonymous queue
  • An asset and account inventory with visible ownership
  • A prioritized remediation register tied to business systems
  • Configuration and identity standards with documented exceptions
  • Backup and recovery testing that produces results, not just a backup-success notification
  • Incident-response exercises with decision-makers in the room
  • Vendor-access and service-provider reviews
  • Monthly reporting that explains risk, progress, overdue work, and next decisions

For an internal IT department that needs additional capacity, co-managed IT can supply operating depth without taking control away from the team. For an organization without security leadership, vCISO services can turn the control list into a roadmap, governance rhythm, and evidence program. Our managed cybersecurity services can provide ongoing monitoring and response, while a tested disaster recovery plan addresses the point where prevention has failed.

The practical starting point

Do not begin by asking whether your organization has completed all 18 CIS Controls. Begin with three questions:

  1. What system must work during the next critical operating moment?
  2. Which unknown asset, account, configuration, or vendor connection could disrupt it?
  3. What evidence would prove that the risk is controlled and recoverable?

For the Ceres school district in our opening scenario, the first decision is straightforward: identify the Chromebook, verify its owner and software, apply the approved configuration, and document the exception if it cannot meet the baseline. That one decision exercises multiple CIS Controls at once.

The goal is not to collect a framework badge. The goal is to make uptime, accountability, recovery, and security visible in the way your organization actually works. If you want a control list connected to your systems and operating priorities, contact Datapath to discuss the first 30 days.


Footnotes

  1. The 18 CIS Critical Security Controls 2

  2. CIS Critical Security Controls Implementation Group 1

  3. Cybersecurity Performance Goals (CPGs) | CISA 2

  4. Criminal Justice Information Services (CJIS) Security Policy

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation