Skip to main content
All answers

How do CIS benchmarks map to ISO 27001?

CISGuard maps CIS benchmark results to 36 of the 93 ISO/IEC 27001:2022 Annex A controls. Coverage concentrates on the technological controls that a configuration scan can evidence; people controls (A.6) are process-oriented and not automatable through scanning. CISGuard generates an ISO 27001 Framework Coverage Report you can attach to your Statement of Applicability as configuration evidence.

The longer answer.

Of the 36 mapped controls, 21 are technological controls (A.8), 12 are organizational controls (A.5), 2 are physical controls (A.7) and 1 is a people control, A.6.7 remote working, where endpoint settings provide evidence. Technological controls dominate because they describe settings a scan can check, such as configuration management (A.8.9), logging (A.8.15) and use of cryptography (A.8.24).

The ISO 27001 Framework Coverage Report rates each mapped control as Satisfied, Partially Satisfied or Not Met and includes a methodology note for the auditor. It supports, rather than replaces, the organizational evidence an ISMS needs, such as policies, risk treatment and management review.

More questions on Framework Mapping?

Our compliance engineers can show you exactly how CISGuard handles Framework Mapping in a briefing scoped to your environment.