Skip to content
CIS Controls

CIS Controls v8. What they are and how Microsoft 365 maps to them.

The CIS Controls are a prioritised set of safeguards organisations can implement to reduce cybersecurity risk. Microsoft 365 configured to CIS Benchmark recommendations directly addresses the majority of applicable controls.

Overview

18 control groups. Prioritised by impact.

CIS Controls v8 defines 18 control groups covering the most critical cybersecurity safeguards for organisations of any size. Each control group contains one or more Safeguards, each of which maps to an Implementation Group: IG1 (essential), IG2 (foundational), or IG3 (organisational).

The Microsoft 365 CIS Benchmark assessment addresses controls across all 18 groups. The largest concentrations are in Account Management (CIS 5), Access Control Management (CIS 6), Data Protection (CIS 3), and Audit Log Management (CIS 8).

IG1

Essential safeguards

Controls every organisation should implement. Addresses the most common attack vectors with the highest risk reduction per effort invested. All IG1 controls are in scope for the CIS M365 L1 assessment.

IG2

Foundational safeguards

Controls for organisations handling more sensitive data or with dedicated IT/security staff. Includes additional configuration hardening and more granular access controls.

IG3

Organisational safeguards

Controls for mature security programmes in high-risk environments. Typically applicable to financial services, healthcare, and defence supply chain organisations.

Licence coverage

Some controls require specific Microsoft 365 licences.

Not all CIS M365 Benchmark controls are available on every licence tier. Some controls require Microsoft 365 Business Premium, E3, or E5 features. The Datatechs assessment report identifies which controls apply to your current licence tier, and which would require a licence upgrade to implement.

Included in Microsoft 365 Business Basic / Standard

  • Exchange Online security baseline controls
  • Teams and SharePoint baseline controls
  • Entra ID security defaults and MFA
  • Audit logging and compliance reports

Requires Business Premium or E3/E5

  • Conditional Access policies (requires Entra ID P1)
  • Microsoft Defender for Office 365 controls
  • Microsoft Purview DLP and sensitivity labels
  • Advanced Identity Protection (requires Entra ID P2)

See how your environment maps to CIS Controls.

The Datatechs CIS M365 assessment tells you exactly which controls are met, which are not, and what is needed to address each gap.