skip to content

A 40-person company with no security team adopts CIS Controls v8.1 — what are Implementation Groups, and why start with IG1?

level: middleimportance: must knowfreq 46%

answer

  1. three nested groups
  2. risk profile and resources
  3. essential cyber hygiene
  4. IG3 is everything

basics

~20 s

CIS Implementation Groups IG1-IG3 sort the 153 Safeguards by an organization's risk profile and resources. IG1 is essential cyber hygiene, the foundational set every enterprise should apply first; IG2 builds on it and IG3 is all Safeguards.

solid answer

~40 s

In **CIS Controls v8.1**, **Implementation Groups (IGs)** are CIS's recommended guidance for prioritizing which **Safeguards** to implement. There are three, based on the **risk profile and resources** an enterprise has. **IG1** is defined as **essential cyber hygiene**: the foundational Safeguards every enterprise should apply to guard against the most common attacks. **IG2** builds on IG1, and **IG3** comprises all the Controls and Safeguards. The groups are cumulative, not alternatives. For a 40-person company with no security team, IG1 is the right start because CIS says every enterprise should start there, and because its Safeguards - inventory, secure configuration, account and access management, backups and the like - are the ones that blunt common attacks. It would move toward IG2 only if its data or risk exposure grew.

go deeper

for a junior

Recall that there are three Implementation Groups, that IG1 is essential cyber hygiene, and that IG3 includes every Safeguard.

for a middle

Explain that the groups are cumulative and chosen by risk profile and resources, and why a small company begins with IG1.

for a senior

Show how you would plan the IG1 rollout for a company without security staff, and what evidence would justify moving to IG2.

for a principal

Weigh when data sensitivity should push a small organization past IG1 despite limited resources, and how to fund that step.

## The problem Implementation Groups solve The **CIS Critical Security Controls v8.1** contain **153 Safeguards** across 18 Controls. A small company cannot implement all of them at once, and a list of 153 items gives no hint which matter most. **Implementation Groups (IGs)** are CIS's answer: its recommended guidance for prioritizing implementation. CIS divides them into three groups based on the **risk profile** and the **resources** an enterprise has available. ## The three groups | Group | What CIS says | Relationship | |---|---|---| | **IG1** | Essential cyber hygiene: the foundational set of cyber defense Safeguards every enterprise should apply to guard against the most common attacks | Starting point for everyone | | **IG2** | Builds upon IG1 | IG1 plus additional Safeguards | | **IG3** | Comprises all the Controls and Safeguards | The complete set | Three properties follow from those definitions: - The groups are **cumulative**. An organization at IG2 has done IG1; IG3 includes everything. - The groups are **not tied to company size alone**. Risk profile matters: a small firm holding very sensitive data may need more than IG1. - Controls do **not** contribute equally to every group. Each IG identifies the Safeguards it needs, and CIS tabulates how many Safeguards of each Control apply to each IG. ## Applying it to a 40-person company The company has no security team, a handful of laptops, some cloud services and perhaps a few servers. The reasoning for IG1: 1. **CIS's own instruction** - every enterprise should start with IG1. 2. **Threat fit** - IG1 targets the most common attacks, which is what a small company actually faces. 3. **Resource fit** - IG1 is the foundational set CIS expects every enterprise to apply, whatever its resources. 4. **Foundation for later work** - IG2 and IG3 build on IG1, so nothing done now is wasted. A practical IG1 programme for this company would focus on: - an inventory of devices and software, so unmanaged assets are found (Controls 1 and 2); - a secure configuration standard for laptops and servers (Control 4); - account and access management, including removing unused accounts (Controls 5 and 6); - patching known vulnerabilities (Control 7); - backups that can actually restore data (Control 11); - basic security awareness training (Control 14). ## When to move up Moving to **IG2** is a risk decision, not a calendar milestone. Signals include: - the company starts handling more sensitive data, or customers demand stronger assurance; - it hires IT or security staff who can operate more technical Safeguards; - its environment grows in complexity (more networks, more custom software). **IG3** is for organizations whose risk profile calls for the complete set of Controls and Safeguards. ## Tracking progress Implementation Groups also give the company a simple way to report progress. For each IG1 Safeguard it records an owner, a status (implemented, partial, not started) and the evidence that shows it working, such as an inventory export or a restore test. Leadership then sees a single, honest measure - how much of essential cyber hygiene is actually in place - instead of a list of tools bought. When the IG1 list is substantially complete, the same format extends naturally to the additional Safeguards IG2 brings. Because the groups are cumulative, the IG1 records stay valid and are simply kept current as the company moves up. ## Common mistakes - **Treating IG1 as "basic, therefore optional".** CIS positions it as the minimum every enterprise should apply. - **Skipping to IG3 items** such as advanced testing before IG1 is complete, leaving common attack paths open. - **Treating IGs as maturity levels to be certified.** They are prioritization guidance; CIS does not certify an organization as "IG2". - **Choosing an IG by headcount alone**, ignoring the sensitivity of the data held. A strong answer defines IGs as cumulative prioritization groups based on risk and resources, quotes IG1 as essential cyber hygiene, and justifies IG1 for the small company by both CIS's instruction and the threat and resource fit.

  • Is IG2 a different set from IG1, or a superset?
    A superset. CIS says IG2 builds upon IG1, and IG3 comprises all the Controls and Safeguards, so each group includes the one before it.
  • Could a very small company need more than IG1?
    Yes. CIS bases the groups on risk profile as well as resources, so a small company holding highly sensitive data may need Safeguards beyond IG1 even without a large team.

Implementation Groups work like a staged fitness plan: everyone starts with the basics that prevent the most common injuries, and harder stages add to the basics rather than replacing them. An athlete in stage three still does the stage-one routine.

saying these in an interview costs you the question

  • Treats IG1 as optional basics a small company can skip
  • Thinks IG2 replaces IG1 rather than building on it
  • Chooses the Implementation Group purely by employee count
  • Says CIS certifies organizations at an Implementation Group
  • Starts with IG3 activities before IG1 is in place