Organizations that want concrete, prioritized security actions rather than a broad risk-management framework to interpret, and companies building a security program from a low baseline who need to know what to do first.
Implementation of safeguards appropriate to your assigned Implementation Group, starting with foundational controls (asset inventory, access control, vulnerability management) before advancing to more sophisticated safeguards.
Because the Controls are ranked by priority, gaps in the earliest controls (asset and software inventory, access control) undermine the effectiveness of every control built on top of them.
Implementation Group determination based on organization size and risk profile, safeguard-by-safeguard gap assessment, and a prioritized implementation roadmap starting from IG1.
Determine your Implementation Group and assess current safeguard coverage.
Prioritized rollout starting from foundational IG1 safeguards.
Advance toward IG2/IG3 safeguards as your risk profile requires.
Asset and software inventories, access control records, vulnerability management logs, and a documented safeguard implementation status mapped to your Implementation Group.
Jumping to advanced IG3 safeguards while foundational IG1 controls like asset inventory remain incomplete; treating the Controls as a static checklist instead of a prioritized, continuously maintained baseline.
Find out your Implementation Group and where your current safeguards stand.
Request a Gap Assessment →