CIS-FRAMEWORK

Prioritised security according to proven standards.

Prioritised security according to proven standards.

Prioritised security according to proven standards.

The CIS Framework translates cyber risks into concrete, prioritised security measures. This creates a roadmap that does not demand everything at once, but rather starts where impact and risk align.

CIS Framework overview in German

ORIENTATION

From controls to decisions.

From controls to decisions.

The number of security measures (153) that a company is expected to implement depends on which group the company belongs to.

The number of security measures (153) that a company is expected to implement depends on which group the company belongs to.

01

IG1 is the definition of essential cyber hygiene and represents a minimum standard of information security for all enterprises. IG1 assists enterprises with limited cybersecurity expertise thwart general, non-targeted attacks.

IG1 is the epitome of basic cyber hygiene and represents a minimum standard for information security in all organisations. IG1 supports companies with limited expertise in the field of cybersecurity in warding off general, non-targeted attacks.

56 basic safeguards

02

IG2

IG2 supports companies in managing the IT infrastructure of multiple departments with different risk profiles. IG2 wants to help companies cope with increasing operational complexity.

additional safeguards for increased requirements

03

IG3

IG3 supports companies with IT security experts in protecting sensitive and confidential data. IG3 has set itself the goal of preventing sophisticated attacks and/or mitigating their impact.

additional safeguards for particularly exposed organisations

APPLICATION

Not as a checklist. As a basis for decisions.

Not as a checklist. As a basis for decisions.

We combine the CIS Controls with the facts of your hybrid infrastructure, management interviews and technical vulnerabilities. This results in a roadmap that clarifies responsibilities and prioritises measures.

01 Basic cyber hygiene: Essential protective measures for small and medium-sized organisations with limited resources, with a focus on defending against common attacks.

02 Builds on IG1 and includes additional protective measures for organisations with medium resources and medium risk.

03 Includes all protective measures from IG1 and IG2 as well as enhanced measures for organisations with extensive resources, sensitive data or critical infrastructure.

03 Includes all protective measures from IG1 and IG2 as well as enhanced measures for organisations with extensive resources, sensitive data or critical infrastructure.

IMPLEMENTATION GROUPS

Three stages for different starting situations.

Three stages for different starting situations.

IG1

Basic protection

For smaller or less complex environments: essential controls that first establish stability and basic protection.

IG2

Scaled operation

For organisations with multiple systems, teams and responsibilities: controls become more operationalised.

IG3

Increased requirements

For more mature or highly exposed organisations: in-depth controls, monitoring and robust evidence.

Let's check which CIS priorities matter for your environment.

Let's check which CIS priorities matter for your environment.

An assessment does not have to start with a large project. Often, a clear look at infrastructure, responsibilities and the key controls is enough.

© 2026 sec4it by AGfB, Rotbuchstrasse 60, CH-8037 Zurich

© 2026 sec4it by AGfB, Rotbuchstrasse 60, CH-8037 Zurich