Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CIS Controls ISO 27001 mapping explained

CIS Controls ISO 27001 Mapping: All 18 Controls to Annex A (2026)

A CIS Controls ISO 27001 mapping answers the question most ISO-certified organisations ask when an insurer, a customer or a US state requirement points at the CIS Controls: how much of this do we already have? The honest answer is most of it in outline and less of it in detail. ISO/IEC 27001:2022 Annex A has 93 controls written as outcomes; CIS Controls v8.1 has 153 Safeguards written as actions with frequencies.

CIS publishes the mapping itself, through the CIS Controls Navigator, Safeguard by Safeguard to Annex A control, and the pattern is consistent: almost every Safeguard lands on an Annex A control, and almost every Annex A technical control is implemented more specifically by several Safeguards than the ISO wording requires. This guide sets out how the two documents relate, the mapping by Control with the Annex A controls each one implements, where ISO 27001 has content the CIS Controls do not and vice versa, and how to use the mapping in both directions — to evidence CIS from an ISMS, and to strengthen an ISMS with CIS Safeguards.

CIS Controls ISO 27001 mapping: 153 Safeguards to 93 Annex A controls
CIS v8.1 Safeguards (prescriptive, with frequencies) → ISO 27001:2022 Annex A controls (outcomes, 4 themes) · Annex A 5.x organizational and 6.x people controls mostly beyond CIS · CIS Controls 3, 4, 6, 8, 12, 13, 16 deeper than Annex A 8.x.

CIS Controls ISO 27001 mapping: how the two relate

CIS Controls v8.1 ISO/IEC 27001:2022
Unit 153 Safeguards in 18 Controls 93 Annex A controls in 4 themes: 37 organizational, 8 people, 14 physical, 34 technological
Form Actions with owners and frequencies Outcomes; ISO 27002 gives implementation guidance
Selection Implementation Group: IG1 56, IG2 130, IG3 153 Risk assessment and the Statement of Applicability under clause 6.1.3
System requirements None; governance is a security function tag Clauses 4–10: context, leadership, planning, support, operation, evaluation, improvement
Assurance Self-assessment (CSAT); no certificate Accredited certification, three-year cycle

Our guides to the CIS Controls v8.1 and to CIS Controls vs NIST CSF cover the CIS side; the mapping below uses the Annex A numbering of the 2022 edition.

The CIS Controls ISO 27001 mapping by Control

CIS Control Annex A controls it implements How the CIS Safeguards go further
1 Inventory and Control of Enterprise Assets 5.9 Inventory of information and other associated assets; 8.8 (unauthorised assets); 8.20 Networks security Named inventory fields, bi-annual review, weekly handling of unauthorised assets, active and passive discovery, DHCP logging
2 Inventory and Control of Software Assets 5.9; 8.19 Installation of software on operational systems; 8.32 Change management Supported-software rule reviewed monthly; allowlisting of software, libraries and scripts
3 Data Protection 5.12 Classification; 5.13 Labelling; 5.10 Acceptable use; 5.33 Protection of records; 8.10 Deletion; 8.11 Masking; 8.12 DLP; 8.24 Cryptography; 8.3 Access restriction Data management process, inventory, retention with minimum and maximum, encryption at rest, in transit and on removable media, DLP and access logging at IG3
4 Secure Configuration of Enterprise Assets and Software 8.9 Configuration management; 8.5 Secure authentication; 8.20; 8.22 Segregation of networks Session lock at 15 and 2 minutes, host firewalls with default deny, default account management, trusted DNS, device lockout thresholds
5 Account Management 5.16 Identity management; 5.18 Access rights; 8.2 Privileged access rights; 8.5 Account inventory, unique passwords, disabling dormant accounts after 45 days, dedicated administrator accounts, centralised account management
6 Access Control Management 5.15 Access control; 5.18; 8.2; 8.3; 8.5 Access granting and revoking processes, MFA for external applications, remote access and administrative access, role-based access
7 Continuous Vulnerability Management 8.8 Management of technical vulnerabilities Documented process, monthly OS and application patching, automated internal and external scanning, remediation process
8 Audit Log Management 8.15 Logging; 8.16 Monitoring activities; 8.17 Clock synchronisation Log management process, collection, adequate storage, time synchronisation, detailed logging, DNS and URL logging, centralisation, retention, weekly review
9 Email and Web Browser Protections 8.7 Protection against malware; 8.23 Web filtering; 8.19 Supported browsers and clients, DNS filtering, URL filtering, extension restrictions, DMARC, unnecessary file types blocked
10 Malware Defenses 8.7 Deployed and managed anti-malware, automatic signature updates, autorun disabled, behaviour-based detection
11 Data Recovery 8.13 Information backup; 5.30 ICT readiness for business continuity Documented recovery process, automated backups, protected and isolated recovery data, recovery testing
12 Network Infrastructure Management 8.20; 8.21 Security of network services; 8.22; 8.9 Current infrastructure, secure architecture, centralised AAA, secure management protocols, dedicated administration resources
13 Network Monitoring and Defense 8.16; 8.20; 8.21; 8.22 Centralised alerting, host and network IDS/IPS, traffic filtering between segments, port-level access control, application-layer filtering
14 Security Awareness and Skills Training 6.3 Information security awareness, education and training Programme with specific topics: social engineering, authentication, data handling, unintentional exposure, incident recognition, insecure networks, role-specific
15 Service Provider Management 5.19 Supplier relationships; 5.20 Addressing security within supplier agreements; 5.21 ICT supply chain; 5.22 Monitoring and review; 5.23 Cloud services Provider inventory, classification, contract requirements, assessment, monitoring, secure decommissioning
16 Application Software Security 8.25 Secure development life cycle; 8.26 Application security requirements; 8.27 Secure architecture; 8.28 Secure coding; 8.29 Security testing; 8.31 Separation of environments Vulnerability handling, root-cause analysis, third-party component inventory, severity rating, secure design and templates, code analysis, penetration testing of applications
17 Incident Response Management 5.24 Planning and preparation; 5.25 Assessment; 5.26 Response; 5.27 Learning; 5.28 Collection of evidence; 6.8 Event reporting Named personnel, contact information, reporting process, process for handling, roles, communications, thresholds, exercises, post-incident review
18 Penetration Testing 8.29 Security testing in development and acceptance; 8.8 Programme, external tests, remediation, validation, internal tests at IG3

What the CIS Controls ISO 27001 mapping leaves uncovered

ISO 27001:2022 element CIS Controls coverage What an ISMS adds
Clauses 4–10: the management system None Scope, leadership, risk assessment and treatment, SoA, objectives, internal audit, management review, corrective action
Annex A 5.1–5.8 organizational governance Policy-defined dimension in CSAT Policies, roles, segregation of duties, management responsibilities, authority contact, threat intelligence, project security
Annex A 5.29–5.32 continuity, legal, IP, records Partly (11 Data recovery) Business continuity planning, legal and contractual requirements, intellectual property
Annex A 5.34–5.37 privacy, independent review, compliance, procedures None PII, independent review of security, compliance with policies, documented operating procedures
Annex A 6.1–6.7 people 14 Awareness only Screening, terms of employment, disciplinary process, termination responsibilities, confidentiality agreements, remote working
Annex A 7.1–7.14 physical None Perimeters, entry, offices, monitoring, environmental threats, clear desk, equipment, cabling, maintenance, disposal
Annex A 8.4, 8.6, 8.14, 8.18, 8.30, 8.33, 8.34 Partly Source code access, capacity, redundancy, privileged utilities, outsourced development, test information, audit test protection

Read the CIS Controls ISO 27001 mapping from the ISO side and the gap is structural: the CIS Controls are a technical and operational control set; ISO 27001 is a management system with organizational, people and physical themes the CIS Controls do not attempt. An organisation that implements IG3 in full is still not an ISMS.

Using the CIS Controls ISO 27001 mapping in both directions

From an ISMS to the CIS Controls

  1. Take the Statement of Applicability as the starting inventory. Every applicable Annex A control in the SoA maps to CIS Safeguards through the Navigator; export the mapping for your Implementation Group.
  2. Test the Safeguard specifics, not the Annex A outcome. ISO 8.15 logging is satisfied by “logs are produced and protected”; CIS 8.2 to 8.11 add collection, storage, synchronisation, DNS and URL logging, centralisation, retention and weekly review. The ISMS evidence usually covers half the Safeguards.
  3. Add the frequencies. CIS Safeguards carry review cycles — bi-annual inventory review, monthly patching, weekly log review; where the ISMS control has no stated frequency, the CIS one becomes the standard.
  4. Score in CSAT. Our guide to CIS Controls assessment covers the four-dimension scoring that turns the mapped evidence into a CIS result.

From the CIS Controls to an ISMS

  1. Use the Safeguards as Annex A implementation evidence. Each implemented Safeguard is evidence for the Annex A control it maps to; the SoA row cites the Safeguard identifiers.
  2. Build the missing themes. Organizational governance, people and physical controls, and the clause 4–10 system are the ISMS work the CIS Controls do not do.
  3. Keep the risk assessment honest. The Implementation Group is a proxy for risk profile; the ISO auditor expects a risk assessment that justifies the SoA, not an IG number.

Frequently asked questions

Is there an official CIS Controls to ISO 27001 mapping?
Yes. CIS publishes Safeguard-level mappings to ISO/IEC 27001:2022 through the CIS Controls Navigator, alongside mappings to NIST CSF 2.0, NIST SP 800-53 Rev 5, PCI DSS v4.0, CMMC 2.0, NIS2 and DORA.

Does ISO 27001 certification mean we meet the CIS Controls?
In outline, mostly; in detail, no. Annex A controls are outcomes; CIS Safeguards specify fields, frequencies and technical measures the ISO wording does not. An ISMS typically evidences around half the Safeguards directly and needs the specifics added for the rest.

Does implementing the CIS Controls give us ISO 27001?
No. The CIS Controls cover the technological and some organizational Annex A controls; ISO 27001 also requires the clause 4–10 management system and the people and physical themes, and certification requires an accredited audit.

Which CIS Controls have the least ISO 27001 overlap?
None are entirely outside Annex A, but Controls 3, 4, 8, 12, 13 and 16 go far beyond the corresponding Annex A controls in specificity, so they are where an ISO-certified organisation finds the most new work.

Which edition does the mapping use?
ISO/IEC 27001:2022 Annex A, with its 93 controls in four themes. Mappings to the 2013 edition’s 114 controls are obsolete since the transition closed on 31 October 2025.

Where this leaves you

Use the CIS Controls ISO 27001 mapping as CIS publishes it: from an ISMS, export the Safeguards for your Implementation Group, test the specifics and frequencies the Annex A outcomes leave open, and score in CSAT; from the CIS Controls, cite Safeguards as Annex A evidence and build the management system, people and physical themes the CIS Controls were never meant to cover.

References

More on the CIS Controls

The Safeguard-level tracker with the Annex A control per row, the 18 Control policies and the Statement of Applicability crosswalk are in the CIS Controls v8.1 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.