Center for Internet Security (CIS) Templates
The CIS benchmarks are available in the following security levels to match your organization's needs:
- CIS Level 1
- Establishes essential cybersecurity safeguards for organizations with limited IT resources, focusing on foundational controls to protect against common threats with minimal technical complexity.
- CIS Level 2
- Provides enhanced cybersecurity safeguards for organizations managing sensitive information or facing increased risk exposure, implementing intermediate controls that balance security effectiveness with operational scalability.
- CIS v8
- Establishes prioritized safeguards to mitigate common cyber attack vectors, providing actionable security controls organized by implementation groups for organizations of varying resources and risk profiles.
National Institute of Standards and Technology (NIST) Templates
- NIST 800-53 Rev 5 Low
- Provides baseline security controls for information systems and organizations with low-impact data, focusing on fundamental protections with minimal operational complexity.
- NIST 800-53 Rev 5 Moderate
- Establishes enhanced security controls for information systems handling moderate-impact data, balancing security requirements with operational efficiency.
- NIST 800-53 Rev 5 High
- Defines comprehensive security controls for information systems processing high-impact data, implementing the most stringent protections for critical assets.
- NIST 800-171
- Provides security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations, focusing on practical controls for contractors and partners handling sensitive government data.
Committee on National Security Systems Instruction (CNSSI) Templates
- CNSSI 1253 Low
- Defines baseline security controls for national security systems and organizations with low-impact data, establishing fundamental protections tailored to classified and sensitive government information.
- CNSSI 1253 Moderate
- Establishes enhanced security controls for national security systems handling moderate-impact data, balancing mission requirements with robust protections for classified information.
- CNSSI 1253 High
- Provides comprehensive security controls for national security systems processing high-impact data, implementing the most stringent safeguards for critical national security operations.
Cybersecurity Maturity Model Certification (CMMC) Templates
- US CMMC 2.0 Level 1
- Establishes foundational cybersecurity practices for Department of Defense contractors, focusing on basic safeguarding of Federal Contract Information through essential security controls.
- US CMMC 2.0 Level 2
- Defines advanced cybersecurity practices for Department of Defense contractors handling Controlled Unclassified Information, implementing comprehensive protections aligned with NIST 800-171 requirements.
Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)
- DISA STIG
- Provides technical configuration standards for hardening information systems and software, establishing prescriptive security settings to reduce vulnerabilities in Department of Defense environments.
Government Information Security Baseline 2 (BIO2)
- NLMAPGOV Base
- Establishes foundational security controls for Apple devices in Dutch government organizations, implementing essential protections aligned with the Government Information Security Baseline 2 (BIO2) requirements.
- NLMAPGOV Plus
- Provides enhanced security controls for Apple devices in Dutch government environments, building upon the base protections with additional safeguards to meet elevated BIO2 compliance requirements and risk profiles.