A CIS Controls ISO 27001 mapping answers the question most ISO-certified organisations ask when an insurer, a customer or a US state requirement points at the CIS Controls: how much of this do we already have? The honest answer is most of it in outline and less of it in detail. ISO/IEC 27001:2022 Annex A has 93 controls written as outcomes; CIS Controls v8.1 has 153 Safeguards written as actions with frequencies.
CIS publishes the mapping itself, through the CIS Controls Navigator, Safeguard by Safeguard to Annex A control, and the pattern is consistent: almost every Safeguard lands on an Annex A control, and almost every Annex A technical control is implemented more specifically by several Safeguards than the ISO wording requires. This guide sets out how the two documents relate, the mapping by Control with the Annex A controls each one implements, where ISO 27001 has content the CIS Controls do not and vice versa, and how to use the mapping in both directions — to evidence CIS from an ISMS, and to strengthen an ISMS with CIS Safeguards.

CIS Controls ISO 27001 mapping: how the two relate
| CIS Controls v8.1 | ISO/IEC 27001:2022 | |
|---|---|---|
| Unit | 153 Safeguards in 18 Controls | 93 Annex A controls in 4 themes: 37 organizational, 8 people, 14 physical, 34 technological |
| Form | Actions with owners and frequencies | Outcomes; ISO 27002 gives implementation guidance |
| Selection | Implementation Group: IG1 56, IG2 130, IG3 153 | Risk assessment and the Statement of Applicability under clause 6.1.3 |
| System requirements | None; governance is a security function tag | Clauses 4–10: context, leadership, planning, support, operation, evaluation, improvement |
| Assurance | Self-assessment (CSAT); no certificate | Accredited certification, three-year cycle |
Our guides to the CIS Controls v8.1 and to CIS Controls vs NIST CSF cover the CIS side; the mapping below uses the Annex A numbering of the 2022 edition.
The CIS Controls ISO 27001 mapping by Control
| CIS Control | Annex A controls it implements | How the CIS Safeguards go further |
|---|---|---|
| 1 Inventory and Control of Enterprise Assets | 5.9 Inventory of information and other associated assets; 8.8 (unauthorised assets); 8.20 Networks security | Named inventory fields, bi-annual review, weekly handling of unauthorised assets, active and passive discovery, DHCP logging |
| 2 Inventory and Control of Software Assets | 5.9; 8.19 Installation of software on operational systems; 8.32 Change management | Supported-software rule reviewed monthly; allowlisting of software, libraries and scripts |
| 3 Data Protection | 5.12 Classification; 5.13 Labelling; 5.10 Acceptable use; 5.33 Protection of records; 8.10 Deletion; 8.11 Masking; 8.12 DLP; 8.24 Cryptography; 8.3 Access restriction | Data management process, inventory, retention with minimum and maximum, encryption at rest, in transit and on removable media, DLP and access logging at IG3 |
| 4 Secure Configuration of Enterprise Assets and Software | 8.9 Configuration management; 8.5 Secure authentication; 8.20; 8.22 Segregation of networks | Session lock at 15 and 2 minutes, host firewalls with default deny, default account management, trusted DNS, device lockout thresholds |
| 5 Account Management | 5.16 Identity management; 5.18 Access rights; 8.2 Privileged access rights; 8.5 | Account inventory, unique passwords, disabling dormant accounts after 45 days, dedicated administrator accounts, centralised account management |
| 6 Access Control Management | 5.15 Access control; 5.18; 8.2; 8.3; 8.5 | Access granting and revoking processes, MFA for external applications, remote access and administrative access, role-based access |
| 7 Continuous Vulnerability Management | 8.8 Management of technical vulnerabilities | Documented process, monthly OS and application patching, automated internal and external scanning, remediation process |
| 8 Audit Log Management | 8.15 Logging; 8.16 Monitoring activities; 8.17 Clock synchronisation | Log management process, collection, adequate storage, time synchronisation, detailed logging, DNS and URL logging, centralisation, retention, weekly review |
| 9 Email and Web Browser Protections | 8.7 Protection against malware; 8.23 Web filtering; 8.19 | Supported browsers and clients, DNS filtering, URL filtering, extension restrictions, DMARC, unnecessary file types blocked |
| 10 Malware Defenses | 8.7 | Deployed and managed anti-malware, automatic signature updates, autorun disabled, behaviour-based detection |
| 11 Data Recovery | 8.13 Information backup; 5.30 ICT readiness for business continuity | Documented recovery process, automated backups, protected and isolated recovery data, recovery testing |
| 12 Network Infrastructure Management | 8.20; 8.21 Security of network services; 8.22; 8.9 | Current infrastructure, secure architecture, centralised AAA, secure management protocols, dedicated administration resources |
| 13 Network Monitoring and Defense | 8.16; 8.20; 8.21; 8.22 | Centralised alerting, host and network IDS/IPS, traffic filtering between segments, port-level access control, application-layer filtering |
| 14 Security Awareness and Skills Training | 6.3 Information security awareness, education and training | Programme with specific topics: social engineering, authentication, data handling, unintentional exposure, incident recognition, insecure networks, role-specific |
| 15 Service Provider Management | 5.19 Supplier relationships; 5.20 Addressing security within supplier agreements; 5.21 ICT supply chain; 5.22 Monitoring and review; 5.23 Cloud services | Provider inventory, classification, contract requirements, assessment, monitoring, secure decommissioning |
| 16 Application Software Security | 8.25 Secure development life cycle; 8.26 Application security requirements; 8.27 Secure architecture; 8.28 Secure coding; 8.29 Security testing; 8.31 Separation of environments | Vulnerability handling, root-cause analysis, third-party component inventory, severity rating, secure design and templates, code analysis, penetration testing of applications |
| 17 Incident Response Management | 5.24 Planning and preparation; 5.25 Assessment; 5.26 Response; 5.27 Learning; 5.28 Collection of evidence; 6.8 Event reporting | Named personnel, contact information, reporting process, process for handling, roles, communications, thresholds, exercises, post-incident review |
| 18 Penetration Testing | 8.29 Security testing in development and acceptance; 8.8 | Programme, external tests, remediation, validation, internal tests at IG3 |
What the CIS Controls ISO 27001 mapping leaves uncovered
| ISO 27001:2022 element | CIS Controls coverage | What an ISMS adds |
|---|---|---|
| Clauses 4–10: the management system | None | Scope, leadership, risk assessment and treatment, SoA, objectives, internal audit, management review, corrective action |
| Annex A 5.1–5.8 organizational governance | Policy-defined dimension in CSAT | Policies, roles, segregation of duties, management responsibilities, authority contact, threat intelligence, project security |
| Annex A 5.29–5.32 continuity, legal, IP, records | Partly (11 Data recovery) | Business continuity planning, legal and contractual requirements, intellectual property |
| Annex A 5.34–5.37 privacy, independent review, compliance, procedures | None | PII, independent review of security, compliance with policies, documented operating procedures |
| Annex A 6.1–6.7 people | 14 Awareness only | Screening, terms of employment, disciplinary process, termination responsibilities, confidentiality agreements, remote working |
| Annex A 7.1–7.14 physical | None | Perimeters, entry, offices, monitoring, environmental threats, clear desk, equipment, cabling, maintenance, disposal |
| Annex A 8.4, 8.6, 8.14, 8.18, 8.30, 8.33, 8.34 | Partly | Source code access, capacity, redundancy, privileged utilities, outsourced development, test information, audit test protection |
Read the CIS Controls ISO 27001 mapping from the ISO side and the gap is structural: the CIS Controls are a technical and operational control set; ISO 27001 is a management system with organizational, people and physical themes the CIS Controls do not attempt. An organisation that implements IG3 in full is still not an ISMS.
Using the CIS Controls ISO 27001 mapping in both directions
From an ISMS to the CIS Controls
- Take the Statement of Applicability as the starting inventory. Every applicable Annex A control in the SoA maps to CIS Safeguards through the Navigator; export the mapping for your Implementation Group.
- Test the Safeguard specifics, not the Annex A outcome. ISO 8.15 logging is satisfied by “logs are produced and protected”; CIS 8.2 to 8.11 add collection, storage, synchronisation, DNS and URL logging, centralisation, retention and weekly review. The ISMS evidence usually covers half the Safeguards.
- Add the frequencies. CIS Safeguards carry review cycles — bi-annual inventory review, monthly patching, weekly log review; where the ISMS control has no stated frequency, the CIS one becomes the standard.
- Score in CSAT. Our guide to CIS Controls assessment covers the four-dimension scoring that turns the mapped evidence into a CIS result.
From the CIS Controls to an ISMS
- Use the Safeguards as Annex A implementation evidence. Each implemented Safeguard is evidence for the Annex A control it maps to; the SoA row cites the Safeguard identifiers.
- Build the missing themes. Organizational governance, people and physical controls, and the clause 4–10 system are the ISMS work the CIS Controls do not do.
- Keep the risk assessment honest. The Implementation Group is a proxy for risk profile; the ISO auditor expects a risk assessment that justifies the SoA, not an IG number.
Frequently asked questions
Is there an official CIS Controls to ISO 27001 mapping?
Yes. CIS publishes Safeguard-level mappings to ISO/IEC 27001:2022 through the CIS Controls Navigator, alongside mappings to NIST CSF 2.0, NIST SP 800-53 Rev 5, PCI DSS v4.0, CMMC 2.0, NIS2 and DORA.
Does ISO 27001 certification mean we meet the CIS Controls?
In outline, mostly; in detail, no. Annex A controls are outcomes; CIS Safeguards specify fields, frequencies and technical measures the ISO wording does not. An ISMS typically evidences around half the Safeguards directly and needs the specifics added for the rest.
Does implementing the CIS Controls give us ISO 27001?
No. The CIS Controls cover the technological and some organizational Annex A controls; ISO 27001 also requires the clause 4–10 management system and the people and physical themes, and certification requires an accredited audit.
Which CIS Controls have the least ISO 27001 overlap?
None are entirely outside Annex A, but Controls 3, 4, 8, 12, 13 and 16 go far beyond the corresponding Annex A controls in specificity, so they are where an ISO-certified organisation finds the most new work.
Which edition does the mapping use?
ISO/IEC 27001:2022 Annex A, with its 93 controls in four themes. Mappings to the 2013 edition’s 114 controls are obsolete since the transition closed on 31 October 2025.
Where this leaves you
Use the CIS Controls ISO 27001 mapping as CIS publishes it: from an ISMS, export the Safeguards for your Implementation Group, test the specifics and frequencies the Annex A outcomes leave open, and score in CSAT; from the CIS Controls, cite Safeguards as Annex A evidence and build the management system, people and physical themes the CIS Controls were never meant to cover.
References
- CIS — CIS Controls Navigator — Safeguard-level mappings to ISO/IEC 27001:2022 and other frameworks.
- CIS — CIS Critical Security Controls v8.1 — The Controls, Safeguards and Implementation Groups.
- ISO/IEC 27001:2022 — Information security management systems — Annex A controls.
More on the CIS Controls
- The CIS Controls ISO 27001 mapping — you are here
- CIS Controls v8.1: the 18 Controls and 3 Implementation Groups
- CIS Controls vs NIST CSF
- CIS Controls assessment: CSAT and scoring
- CIS Controls implementation: the IG1 plan
- Asset inventory: CIS Controls 1 and 2
The Safeguard-level tracker with the Annex A control per row, the 18 Control policies and the Statement of Applicability crosswalk are in the CIS Controls v8.1 Toolkit, or start with the free templates.