CIS Controls® Implementation Group 1 (IG1): What It Means for Your Organization
CIS Controls® Implementation Group 1 (IG1) is the starting set of 56 Safeguards in the CIS Critical Security Controls®, version 8.1. The Center for Internet Security calls it “essential cyber hygiene,” the foundational set of cyber defense Safeguards every enterprise should apply to guard against the most common attacks. The CIS Controls are voluntary and free to use. In Texas, IG1 also matters for a specific reason: the SB 2610 cybersecurity safe harbor names it as part of the program requirements for businesses with at least 20 but fewer than 100 employees. ALCON DTS can help you assess against IG1, close the gaps and keep a record of the work.
This page answers:
At a glance
- Framework: CIS Critical Security Controls® (CIS Controls®) v8.1, Implementation Group 1. CIS released v8.1 on June 25, 2024, and still lists it as the latest version.
- Published by: the Center for Internet Security (CIS), a nonprofit organization
- What it contains: 56 Safeguards, drawn from 15 of the 18 CIS Controls. The full CIS Controls contain 153 Safeguards.
- Who it is for: every enterprise, as a starting point. CIS says “Every enterprise should start with IG1.”
- Cost: CIS says the CIS Controls “are free to use by anyone to improve their own cybersecurity.” Vendors and consultants who use them in services for customers do so under a CIS membership or other CIS permission.
- Texas connection: Texas Business and Commerce Code Sec. 542.004(a)(4)(B) names CIS Controls IG1 in the moderate requirements for businesses with at least 20 but fewer than 100 employees that want the SB 2610 safe harbor
- Enforced by: no regulator. The CIS Controls are a voluntary framework.
- Official source: The 18 CIS Critical Security Controls
- Last reviewed: September 30, 2026
What is CIS Controls IG1?
The CIS Critical Security Controls® are, in CIS’s words, “a prescriptive, prioritized, and simplified set of best practices that you can use to strengthen your cybersecurity posture.” They are organized into 18 Controls, and each Control is broken into specific actions called Safeguards. There are 153 Safeguards in CIS Controls v8 and v8.1.
Not every organization needs to start with all 153. CIS sorts the Safeguards into three Implementation Groups (IGs), “based on the risk profile and resources an enterprise has available to them”:
- IG1 is “essential cyber hygiene,” 56 Safeguards that CIS says “every enterprise should apply to defend against the most common attacks.”
- IG2 builds on IG1 (130 Safeguards in total).
- IG3 “is comprised of all the Controls and Safeguards” (all 153).
CIS describes the typical IG1 enterprise as “small to medium-sized with limited IT and cybersecurity expertise,” with a limited tolerance for downtime. IG1 Safeguards “should be implementable with limited cybersecurity expertise and aimed to thwart general, non-targeted attacks.”
What changed in v8.1. CIS calls v8.1 “an iterative update to v8.” It updated alignment to other frameworks, revised asset classes and Safeguard descriptions, and added the “Govern” security function introduced in the NIST Cybersecurity Framework (CSF) 2.0. The IG pages list the same 56 IG1 Safeguards and 153 total Safeguards for v8 and v8.1.
What does IG1 cover, and what doesn’t it?
It covers: the basics that stop common, non-targeted attacks. That means knowing your devices and software, protecting data, secure settings, accounts and access, patching, logging, email and browser protection, malware defense, backups, network basics, security training, service providers and incident response.
It is not:
- A certification. Putting IG1 in place does not by itself certify your organization. It is a set of practices you carry out and document.
- The whole CIS Controls. IG1 is the first of three groups. Three Controls (Network Monitoring and Defense, Application Software Security and Penetration Testing) have no IG1 Safeguards at all.
- A replacement for other rules. CIS says “The CIS Controls are not a replacement for any existing regulatory, compliance, or authorization scheme.” If HIPAA, PCI DSS or a contract applies to you, those still apply.
- A one-time project. Devices, accounts and software change often. IG1 only helps if it is kept current.
Does CIS Controls IG1 apply to you?
No law requires most businesses to adopt the CIS Controls. IG1 becomes important in three common situations:
- You want the Texas SB 2610 safe harbor and have 20 to 99 employees. For a business entity “with at least 20 employees but fewer than 100 employees,” a qualifying program must meet “moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1” (Sec. 542.004(a)(4)(B)).
- You need a clear, prioritized starting point. CIS designed IG1 for organizations with limited in-house security expertise.
- Someone asks you to show basic security. A customer, partner or insurer may ask how you handle the basics. IG1 gives you a recognized way to answer.
Quick check: does this apply to you?
- You are a Texas business entity with fewer than 250 employees that owns or licenses computerized data that includes sensitive personal information (the SB 2610 applicability test in Sec. 542.002), and you have at least 20 but fewer than 100 employees.
- Or you do not have a documented security baseline today and want one you can explain to leadership and outsiders.
If either is true, IG1 is very likely a good fit for you. Whether your program qualifies for the SB 2610 safe harbor is a legal question decided on the facts. Chapter 542 does not say how employees are counted. Confirm with your attorney.
What do you need to have in place?
IG1 has 56 Safeguards spread across 15 Controls. The table shows each Control, what it covers in plain terms and how many of its Safeguards are in IG1.
| CIS Control (v8.1) | What it covers | IG1 Safeguards |
|---|---|---|
| 1. Inventory and Control of Enterprise Assets | Know every device connected to your environment, on site, remote and in the cloud, and deal with unknown ones | 2 of 5 |
| 2. Inventory and Control of Software Assets | Know what software is installed, allow only authorized software, and find and remove the rest | 3 of 7 |
| 3. Data Protection | Identify, classify, securely handle, retain and dispose of data | 6 of 14 |
| 4. Secure Configuration of Enterprise Assets and Software | Set and maintain secure settings on devices and software | 7 of 12 |
| 5. Account Management | Manage user, administrator and service accounts | 4 of 6 |
| 6. Access Control Management | Create, assign, manage and revoke access and privileges | 5 of 8 |
| 7. Continuous Vulnerability Management | Track and fix vulnerabilities on all assets | 4 of 7 |
| 8. Audit Log Management | Collect, review and keep logs that help you detect and recover from an attack | 3 of 12 |
| 9. Email and Web Browser Protections | Protect against threats that arrive by email and the web | 2 of 7 |
| 10. Malware Defenses | Prevent or control malicious software | 3 of 7 |
| 11. Data Recovery | Keep recovery practices that can restore systems to a trusted state | 4 of 5 |
| 12. Network Infrastructure Management | Manage network devices so attackers cannot exploit weak services and access points | 1 of 8 |
| 13. Network Monitoring and Defense | Monitor and defend the network | 0 of 11 |
| 14. Security Awareness and Skills Training | Train your workforce to be security conscious and properly skilled | 8 of 9 |
| 15. Service Provider Management | Evaluate service providers who hold sensitive data or run critical platforms | 1 of 7 |
| 16. Application Software Security | Manage the security of software you build, host or acquire | 0 of 14 |
| 17. Incident Response Management | Prepare to detect and respond quickly to an attack | 3 of 9 |
| 18. Penetration Testing | Test your defenses by simulating an attacker | 0 of 5 |
| Total | 56 of 153 |
How do you get started?
A practical path looks like this:
- Download the CIS Controls v8.1 from CIS so you work from the exact Safeguard text.
- Assess where you are against each of the 56 IG1 Safeguards: in place, partly in place or not in place.
- Write down what you find, including who owns each Safeguard and what evidence shows it works.
- Fix the gaps in order of risk, starting with the gaps that expose your most important data and systems.
- Review on a regular cycle and after big changes, such as a new office, a new system or a new service provider.
How does IG1 relate to the Texas SB 2610 tiers?
Texas Business and Commerce Code Sec. 542.004(a)(4) scales the program by employee count:
| Employees | What Sec. 542.004(a)(4) says | Where IG1 fits |
|---|---|---|
| Fewer than 20 | “simplified requirements, including password policies and appropriate employee cybersecurity training” | IG1 is not named for this tier. IG1’s account, access and training Safeguards can support the password and training elements |
| At least 20 but fewer than 100 | “moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1” | IG1 is named here |
| At least 100 but fewer than 250 | “compliance with the requirements of Subsection (b)” | IG1 is not named. Subsection (b) means conforming to one or more listed frameworks (the CIS Critical Security Controls are one, Sec. 542.004(b)(1)(E)), plus HIPAA, GLBA Title V, FISMA or HITECH if you are subject to them, and PCI DSS if it applies to you (Sec. 542.004(b)(2) and (3)) |
For every tier, the statute also says the program must contain administrative, technical and physical safeguards, “conform to an industry-recognized cybersecurity framework as described by Subsection (b),” and be designed to protect sensitive information (Sec. 542.004(a)(1) to (3)). The framework list in Subsection (b) includes “the Center for Internet Security Critical Security Controls for Effective Cyber Defense.” Talk with your attorney about how these parts of the statute work together for your organization.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. You decide which framework to follow and how much risk to accept. ALCON DTS can help you assess against IG1, run many of the Safeguards on the systems we manage and keep the evidence in one place.
| IG1 area | What ALCON DTS provides |
|---|---|
| Framework assessment and documentation | Compliance tracking against your chosen framework, with documented policies, procedures and an organized evidence file |
| Controls 1, 2 and 4: inventory and secure configuration | Device management, managed patching and updates, and automated documentation of systems and configurations |
| Control 3: data protection | Device encryption and protection on the systems we manage. Data inventory, classification and retention decisions stay with you |
| Controls 5 and 6: accounts and access | Identity and access with multifactor authentication and tight administrator rights; joiner, mover and leaver changes handled promptly; guest and vendor access kept under control |
| Control 7: vulnerability management | Managed patching and updates |
| Control 8: audit logs | Centralized logging and security monitoring, so you know what is logged |
| Control 9: email and web | Email security and filtering, plus email domain authentication |
| Control 10: malware defenses | Endpoint detection and response, application control and managed administrator rights |
| Control 11: data recovery | Tested backup and recovery |
| Control 12: network basics | Managed firewalls, switching and secure wireless networks |
| Control 14: training | Security awareness training with completion records |
| Control 15: service providers | A review of vendor access, with guest and vendor access kept under control |
| Control 17: incident response | Monitoring that routes alerts to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. Some IG1 Safeguards, such as your data retention decisions and your incident response roles, are yours to own. ALCON DTS does not certify organizations against the CIS Controls, and whether the SB 2610 safe harbor applies to a claim is a legal question.
Want to know where you stand against IG1? We will compare your current controls with the 56 IG1 Safeguards and show you what would close the gaps.
How does CIS Controls IG1 fit with other rules?
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). IG1 is named in the moderate requirements for business entities with at least 20 but fewer than 100 employees (Sec. 542.004(a)(4)(B)). When a framework listed in Sec. 542.004(b)(1) is updated, a program keeps meeting the requirements if it is updated by the later of the implementation date published in the updated standard or the first anniversary of the update’s publication (Sec. 542.004(c)). Ask your attorney how this applies to the IG1 requirement for the 20 to 99 tier. See Texas SB 2610 Cybersecurity Safe Harbor.
- Texas duty to protect sensitive personal information (Bus. and Com. Code Sec. 521.052). Businesses must “implement and maintain reasonable procedures” to protect sensitive personal information. A documented IG1 program is one practical way to show what your procedures are. It does not change your breach notification duties under Sec. 521.053.
- NIST Cybersecurity Framework (CSF) 2.0. CIS Controls v8.1 realigned its security function mappings to match NIST CSF 2.0, including the Govern function. CIS also notes that the NIST framework calls out the CIS Controls as an informative reference, a way to help users put the framework into practice.
- HIPAA Security Rule. CIS says the CIS Controls map to regulations such as HIPAA, but they are not a replacement for it. If you are a HIPAA covered entity or business associate, you still need a HIPAA security risk analysis and the safeguards it calls for. SB 2610 also expects your program to conform to HIPAA if you are subject to it (Sec. 542.004(b)(2)(A)).
- PCI DSS. If you accept payment cards and PCI DSS applies to you, SB 2610 expects your program to conform to its current version (Sec. 542.004(b)(3)).
Frequently asked questions
What is CIS Controls IG1?
How many Safeguards are in IG1?
What is the current version of the CIS Controls?
Does Texas law require IG1?
Is IG1 named for businesses with fewer than 20 employees?
Are the CIS Controls free?
Does meeting IG1 make you certified?
Is IG1 enough on its own?
Sources
- The 18 CIS Critical Security Controls (Center for Internet Security)
- CIS Critical Security Controls Version 8.1 (Center for Internet Security)
- CIS Critical Security Controls Implementation Groups (Center for Internet Security)
- CIS Critical Security Controls Implementation Group 1 (Center for Internet Security)
- Center for Internet Security (CIS) Releases CIS Controls v8.1 with New Governance Recommendations, June 25, 2024 (Center for Internet Security press release)
- CIS Critical Security Controls FAQ (Center for Internet Security)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas SB 2610, enrolled bill text, 89th Legislature (Texas Legislature Online)
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information (Texas Constitution and Statutes)
Last reviewed: September 30, 2026
This page is general information about the CIS Critical Security Controls and related Texas law, not legal advice for your situation.
CIS Controls® is a registered trademark of the Center for Internet Security, Inc.
Talk with ALCON DTS about CIS Controls IG1
Not sure how many of the 56 IG1 Safeguards you already meet, or which gaps matter most? We will walk through your environment, show you what is in place and give you a clear plan for the rest.
Email: info@alcondts.com · Phone: 512-892-6900

