Skip to content
CIS Controls

Map supported security findings to CIS Controls evidence.

CIS Controls are organized around what an attacker does, which makes them a natural fit for configuration evidence. Retrievy associates each supported finding with the Safeguards it speaks to, so a control review starts from collected fact.

How evidence flows

How a finding reaches a Safeguard

The association is explicit and traceable in both directions.

  1. 1 Observed

    Collected condition

    A specific state observed on a connected source, such as an administrative account with no multi-factor requirement.

  2. 2 Associated

    Associated Safeguard

    The Safeguards that condition is evidence for, at the implementation group level your programme targets.

  3. 3 Presented

    Control view

    Each control shows its associated findings, their severity and status, so a reviewer sees the basis rather than a verdict.

  4. 4 Confirmed

    Verified closure

    Remediation is owned, then confirmed by a later scan that re-collects the same condition.

Which controls get real coverage

Controls concerning inventory, secure configuration, account and access management, audit log settings, network infrastructure management and malware defences receive the most direct evidence, because they describe machine-readable configuration on the sources Retrievy connects to.

CIS Benchmarks for the specific platforms assessed sit alongside this. A Benchmark result is evidence for a Control; the two are related but not interchangeable, and Retrievy keeps them distinct rather than presenting a Benchmark pass as a Control pass.

Which controls do not, and why that matters

Controls covering security awareness training, service provider management, incident response process and penetration testing describe organizational activity rather than system state. No configuration scanner can observe them, so they fall outside what Retrievy maps.

This matters because a partial mapping presented as a coverage percentage invites the reading that the remainder is fine. The mapping does not prove that every CIS Safeguard is implemented, and a Safeguard outside the mapping carries no assertion at all.

Evidence that refreshes

A control review built from a spreadsheet is accurate on the day it is written. Because every scan re-collects the same configuration, the findings behind each Safeguard reflect the estate as it stands now, and a control that regressed after an infrastructure change shows up when that change is scanned.

Each finding also carries its own closure evidence: the later scan that confirmed the condition was gone. That is what lets a reviewer ask "how do you know" and get an answer that is not a screenshot.

Boundaries

What the CIS mapping does not claim

  • The mapping does not prove that every CIS Safeguard is implemented.
  • Safeguards describing training, process or third-party management fall outside the mapping, and are never treated as passing.
  • A CIS Benchmark result is evidence for a Control, not a substitute for one.
  • Retrievy is not a CIS-accredited assessor and issues no attestation.
  • Evidence covers the sources you connected, within the scopes you granted.
Questions

Frequently asked questions

Does Retrievy cover all 18 CIS Controls?
It provides technical evidence for the controls that describe system configuration and access. The rest fall outside the mapping. The mapping does not prove that every CIS Safeguard is implemented, and controls about training, process or vendor management have no configuration evidence to collect.
What is the difference between CIS Controls and CIS Benchmarks here?
A Benchmark is a hardening standard for a specific platform. A Control is an outcome-level objective. Retrievy assesses Benchmarks for the platforms it supports and treats those results as evidence for the related Controls, while keeping the two views distinct.
Can we report against a specific implementation group?
Yes. Findings are presented against the implementation group your programme targets, so the view is not padded with Safeguards from a tier you have not adopted.
Is this an official CIS assessment?
No. Retrievy is not accredited by CIS and produces no attestation. It organizes your own collected evidence against the Controls so that an assessment, however it is conducted, starts from fact rather than from a spreadsheet.

Start the control review from collected evidence.

Connect a source read-only and see which Safeguards your current configuration actually speaks to.