Map supported security findings to CIS Controls evidence.
CIS Controls are organized around what an attacker does, which makes them a natural fit for configuration evidence. Retrievy associates each supported finding with the Safeguards it speaks to, so a control review starts from collected fact.
How a finding reaches a Safeguard
The association is explicit and traceable in both directions.
-
1
Observed
Collected condition
A specific state observed on a connected source, such as an administrative account with no multi-factor requirement.
-
2
Associated
Associated Safeguard
The Safeguards that condition is evidence for, at the implementation group level your programme targets.
-
3
Presented
Control view
Each control shows its associated findings, their severity and status, so a reviewer sees the basis rather than a verdict.
-
4
Confirmed
Verified closure
Remediation is owned, then confirmed by a later scan that re-collects the same condition.
Which controls get real coverage
Controls concerning inventory, secure configuration, account and access management, audit log settings, network infrastructure management and malware defences receive the most direct evidence, because they describe machine-readable configuration on the sources Retrievy connects to.
CIS Benchmarks for the specific platforms assessed sit alongside this. A Benchmark result is evidence for a Control; the two are related but not interchangeable, and Retrievy keeps them distinct rather than presenting a Benchmark pass as a Control pass.
Which controls do not, and why that matters
Controls covering security awareness training, service provider management, incident response process and penetration testing describe organizational activity rather than system state. No configuration scanner can observe them, so they fall outside what Retrievy maps.
This matters because a partial mapping presented as a coverage percentage invites the reading that the remainder is fine. The mapping does not prove that every CIS Safeguard is implemented, and a Safeguard outside the mapping carries no assertion at all.
Evidence that refreshes
A control review built from a spreadsheet is accurate on the day it is written. Because every scan re-collects the same configuration, the findings behind each Safeguard reflect the estate as it stands now, and a control that regressed after an infrastructure change shows up when that change is scanned.
Each finding also carries its own closure evidence: the later scan that confirmed the condition was gone. That is what lets a reviewer ask "how do you know" and get an answer that is not a screenshot.
What the CIS mapping does not claim
- The mapping does not prove that every CIS Safeguard is implemented.
- Safeguards describing training, process or third-party management fall outside the mapping, and are never treated as passing.
- A CIS Benchmark result is evidence for a Control, not a substitute for one.
- Retrievy is not a CIS-accredited assessor and issues no attestation.
- Evidence covers the sources you connected, within the scopes you granted.
Frequently asked questions
- Does Retrievy cover all 18 CIS Controls?
- It provides technical evidence for the controls that describe system configuration and access. The rest fall outside the mapping. The mapping does not prove that every CIS Safeguard is implemented, and controls about training, process or vendor management have no configuration evidence to collect.
- What is the difference between CIS Controls and CIS Benchmarks here?
- A Benchmark is a hardening standard for a specific platform. A Control is an outcome-level objective. Retrievy assesses Benchmarks for the platforms it supports and treats those results as evidence for the related Controls, while keeping the two views distinct.
- Can we report against a specific implementation group?
- Yes. Findings are presented against the implementation group your programme targets, so the view is not padded with Safeguards from a tier you have not adopted.
- Is this an official CIS assessment?
- No. Retrievy is not accredited by CIS and produces no attestation. It organizes your own collected evidence against the Controls so that an assessment, however it is conducted, starts from fact rather than from a spreadsheet.
Related resources
Start the control review from collected evidence.
Connect a source read-only and see which Safeguards your current configuration actually speaks to.