Terminology Index

Glossary

1801 terms

Open concept maps

Showing 865-896 of 1801 terms

I
32

Implementation Groups

The tiered sets within the CIS Controls (IG1, IG2, IG3) that group safeguards by an organization's size, resources, and risk, so smaller or less-resourced organizations can adopt a sensible subset first and scale up.

CIS Implementation Groups divide the controls' safeguards into three tiers: IG1 is essential cyber hygiene for all organizations, IG2 adds safeguards for those handling more sensitive data, and IG3 covers mature, high-risk environments. They make the CIS Controls practical by giving each organization a risk-and-resource-appropriate starting point and a path to grow, rather than facing the full control set at once. They are central to applying the CIS Controls.

Introduced in: Security Frameworks and Control Mapping

Examples

  • A small business adopting IG1 as essential baseline hygiene.
  • Scaling up to IG2 safeguards as the organization handles sensitive data.
  • Reserving IG3 safeguards for a mature, high-risk environment.

No related terms linked yet.