CIS Controls® Implementation Group 1 (IG1): What It Means for Your Organization

CIS Controls® Implementation Group 1 (IG1) is the starting set of 56 Safeguards in the CIS Critical Security Controls®, version 8.1. The Center for Internet Security calls it “essential cyber hygiene,” the foundational set of cyber defense Safeguards every enterprise should apply to guard against the most common attacks. The CIS Controls are voluntary and free to use. In Texas, IG1 also matters for a specific reason: the SB 2610 cybersecurity safe harbor names it as part of the program requirements for businesses with at least 20 but fewer than 100 employees. ALCON DTS can help you assess against IG1, close the gaps and keep a record of the work.

Talk with ALCON DTSSee what you need in place

At a glance

  • Framework: CIS Critical Security Controls® (CIS Controls®) v8.1, Implementation Group 1. CIS released v8.1 on June 25, 2024, and still lists it as the latest version.
  • Published by: the Center for Internet Security (CIS), a nonprofit organization
  • What it contains: 56 Safeguards, drawn from 15 of the 18 CIS Controls. The full CIS Controls contain 153 Safeguards.
  • Who it is for: every enterprise, as a starting point. CIS says “Every enterprise should start with IG1.”
  • Cost: CIS says the CIS Controls “are free to use by anyone to improve their own cybersecurity.” Vendors and consultants who use them in services for customers do so under a CIS membership or other CIS permission.
  • Texas connection: Texas Business and Commerce Code Sec. 542.004(a)(4)(B) names CIS Controls IG1 in the moderate requirements for businesses with at least 20 but fewer than 100 employees that want the SB 2610 safe harbor
  • Enforced by: no regulator. The CIS Controls are a voluntary framework.
  • Official source: The 18 CIS Critical Security Controls
  • Last reviewed: September 30, 2026

What is CIS Controls IG1?

The CIS Critical Security Controls® are, in CIS’s words, “a prescriptive, prioritized, and simplified set of best practices that you can use to strengthen your cybersecurity posture.” They are organized into 18 Controls, and each Control is broken into specific actions called Safeguards. There are 153 Safeguards in CIS Controls v8 and v8.1.

Not every organization needs to start with all 153. CIS sorts the Safeguards into three Implementation Groups (IGs), “based on the risk profile and resources an enterprise has available to them”:

  • IG1 is “essential cyber hygiene,” 56 Safeguards that CIS says “every enterprise should apply to defend against the most common attacks.”
  • IG2 builds on IG1 (130 Safeguards in total).
  • IG3 “is comprised of all the Controls and Safeguards” (all 153).

CIS describes the typical IG1 enterprise as “small to medium-sized with limited IT and cybersecurity expertise,” with a limited tolerance for downtime. IG1 Safeguards “should be implementable with limited cybersecurity expertise and aimed to thwart general, non-targeted attacks.”

What changed in v8.1. CIS calls v8.1 “an iterative update to v8.” It updated alignment to other frameworks, revised asset classes and Safeguard descriptions, and added the “Govern” security function introduced in the NIST Cybersecurity Framework (CSF) 2.0. The IG pages list the same 56 IG1 Safeguards and 153 total Safeguards for v8 and v8.1.

What does IG1 cover, and what doesn’t it?

It covers: the basics that stop common, non-targeted attacks. That means knowing your devices and software, protecting data, secure settings, accounts and access, patching, logging, email and browser protection, malware defense, backups, network basics, security training, service providers and incident response.

It is not:

  • A certification. Putting IG1 in place does not by itself certify your organization. It is a set of practices you carry out and document.
  • The whole CIS Controls. IG1 is the first of three groups. Three Controls (Network Monitoring and Defense, Application Software Security and Penetration Testing) have no IG1 Safeguards at all.
  • A replacement for other rules. CIS says “The CIS Controls are not a replacement for any existing regulatory, compliance, or authorization scheme.” If HIPAA, PCI DSS or a contract applies to you, those still apply.
  • A one-time project. Devices, accounts and software change often. IG1 only helps if it is kept current.

Does CIS Controls IG1 apply to you?

No law requires most businesses to adopt the CIS Controls. IG1 becomes important in three common situations:

  1. You want the Texas SB 2610 safe harbor and have 20 to 99 employees. For a business entity “with at least 20 employees but fewer than 100 employees,” a qualifying program must meet “moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1” (Sec. 542.004(a)(4)(B)).
  2. You need a clear, prioritized starting point. CIS designed IG1 for organizations with limited in-house security expertise.
  3. Someone asks you to show basic security. A customer, partner or insurer may ask how you handle the basics. IG1 gives you a recognized way to answer.

Quick check: does this apply to you?

  • You are a Texas business entity with fewer than 250 employees that owns or licenses computerized data that includes sensitive personal information (the SB 2610 applicability test in Sec. 542.002), and you have at least 20 but fewer than 100 employees.
  • Or you do not have a documented security baseline today and want one you can explain to leadership and outsiders.

If either is true, IG1 is very likely a good fit for you. Whether your program qualifies for the SB 2610 safe harbor is a legal question decided on the facts. Chapter 542 does not say how employees are counted. Confirm with your attorney.

What do you need to have in place?

IG1 has 56 Safeguards spread across 15 Controls. The table shows each Control, what it covers in plain terms and how many of its Safeguards are in IG1.

Control names and descriptions summarized from CIS, “The 18 CIS Critical Security Controls.” Safeguard counts from the CIS Controls v8.1 Implementation Groups pages. Download the full Safeguard list from CIS for exact wording.
CIS Control (v8.1) What it covers IG1 Safeguards
1. Inventory and Control of Enterprise Assets Know every device connected to your environment, on site, remote and in the cloud, and deal with unknown ones 2 of 5
2. Inventory and Control of Software Assets Know what software is installed, allow only authorized software, and find and remove the rest 3 of 7
3. Data Protection Identify, classify, securely handle, retain and dispose of data 6 of 14
4. Secure Configuration of Enterprise Assets and Software Set and maintain secure settings on devices and software 7 of 12
5. Account Management Manage user, administrator and service accounts 4 of 6
6. Access Control Management Create, assign, manage and revoke access and privileges 5 of 8
7. Continuous Vulnerability Management Track and fix vulnerabilities on all assets 4 of 7
8. Audit Log Management Collect, review and keep logs that help you detect and recover from an attack 3 of 12
9. Email and Web Browser Protections Protect against threats that arrive by email and the web 2 of 7
10. Malware Defenses Prevent or control malicious software 3 of 7
11. Data Recovery Keep recovery practices that can restore systems to a trusted state 4 of 5
12. Network Infrastructure Management Manage network devices so attackers cannot exploit weak services and access points 1 of 8
13. Network Monitoring and Defense Monitor and defend the network 0 of 11
14. Security Awareness and Skills Training Train your workforce to be security conscious and properly skilled 8 of 9
15. Service Provider Management Evaluate service providers who hold sensitive data or run critical platforms 1 of 7
16. Application Software Security Manage the security of software you build, host or acquire 0 of 14
17. Incident Response Management Prepare to detect and respond quickly to an attack 3 of 9
18. Penetration Testing Test your defenses by simulating an attacker 0 of 5
Total 56 of 153

How do you get started?

A practical path looks like this:

  1. Download the CIS Controls v8.1 from CIS so you work from the exact Safeguard text.
  2. Assess where you are against each of the 56 IG1 Safeguards: in place, partly in place or not in place.
  3. Write down what you find, including who owns each Safeguard and what evidence shows it works.
  4. Fix the gaps in order of risk, starting with the gaps that expose your most important data and systems.
  5. Review on a regular cycle and after big changes, such as a new office, a new system or a new service provider.

How does IG1 relate to the Texas SB 2610 tiers?

Texas Business and Commerce Code Sec. 542.004(a)(4) scales the program by employee count:

Tier text quoted from Texas Business and Commerce Code Sec. 542.004(a)(4). The “Where IG1 fits” column is general information, not a reading of the law for your situation.
Employees What Sec. 542.004(a)(4) says Where IG1 fits
Fewer than 20 “simplified requirements, including password policies and appropriate employee cybersecurity training” IG1 is not named for this tier. IG1’s account, access and training Safeguards can support the password and training elements
At least 20 but fewer than 100 “moderate requirements, including the requirements of the Center for Internet Security Controls Implementation Group 1” IG1 is named here
At least 100 but fewer than 250 “compliance with the requirements of Subsection (b)” IG1 is not named. Subsection (b) means conforming to one or more listed frameworks (the CIS Critical Security Controls are one, Sec. 542.004(b)(1)(E)), plus HIPAA, GLBA Title V, FISMA or HITECH if you are subject to them, and PCI DSS if it applies to you (Sec. 542.004(b)(2) and (3))

For every tier, the statute also says the program must contain administrative, technical and physical safeguards, “conform to an industry-recognized cybersecurity framework as described by Subsection (b),” and be designed to protect sensitive information (Sec. 542.004(a)(1) to (3)). The framework list in Subsection (b) includes “the Center for Internet Security Critical Security Controls for Effective Cyber Defense.” Talk with your attorney about how these parts of the statute work together for your organization.

How can ALCON DTS help you?

You keep the compliance decisions. We run the controls. You decide which framework to follow and how much risk to accept. ALCON DTS can help you assess against IG1, run many of the Safeguards on the systems we manage and keep the evidence in one place.

IG1 area What ALCON DTS provides
Framework assessment and documentation Compliance tracking against your chosen framework, with documented policies, procedures and an organized evidence file
Controls 1, 2 and 4: inventory and secure configuration Device management, managed patching and updates, and automated documentation of systems and configurations
Control 3: data protection Device encryption and protection on the systems we manage. Data inventory, classification and retention decisions stay with you
Controls 5 and 6: accounts and access Identity and access with multifactor authentication and tight administrator rights; joiner, mover and leaver changes handled promptly; guest and vendor access kept under control
Control 7: vulnerability management Managed patching and updates
Control 8: audit logs Centralized logging and security monitoring, so you know what is logged
Control 9: email and web Email security and filtering, plus email domain authentication
Control 10: malware defenses Endpoint detection and response, application control and managed administrator rights
Control 11: data recovery Tested backup and recovery
Control 12: network basics Managed firewalls, switching and secure wireless networks
Control 14: training Security awareness training with completion records
Control 15: service providers A review of vendor access, with guest and vendor access kept under control
Control 17: incident response Monitoring that routes alerts to a named owner. When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control.

The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. Some IG1 Safeguards, such as your data retention decisions and your incident response roles, are yours to own. ALCON DTS does not certify organizations against the CIS Controls, and whether the SB 2610 safe harbor applies to a claim is a legal question.

Want to know where you stand against IG1? We will compare your current controls with the 56 IG1 Safeguards and show you what would close the gaps.

Talk with ALCON DTS

How does CIS Controls IG1 fit with other rules?

  • Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). IG1 is named in the moderate requirements for business entities with at least 20 but fewer than 100 employees (Sec. 542.004(a)(4)(B)). When a framework listed in Sec. 542.004(b)(1) is updated, a program keeps meeting the requirements if it is updated by the later of the implementation date published in the updated standard or the first anniversary of the update’s publication (Sec. 542.004(c)). Ask your attorney how this applies to the IG1 requirement for the 20 to 99 tier. See Texas SB 2610 Cybersecurity Safe Harbor.
  • Texas duty to protect sensitive personal information (Bus. and Com. Code Sec. 521.052). Businesses must “implement and maintain reasonable procedures” to protect sensitive personal information. A documented IG1 program is one practical way to show what your procedures are. It does not change your breach notification duties under Sec. 521.053.
  • NIST Cybersecurity Framework (CSF) 2.0. CIS Controls v8.1 realigned its security function mappings to match NIST CSF 2.0, including the Govern function. CIS also notes that the NIST framework calls out the CIS Controls as an informative reference, a way to help users put the framework into practice.
  • HIPAA Security Rule. CIS says the CIS Controls map to regulations such as HIPAA, but they are not a replacement for it. If you are a HIPAA covered entity or business associate, you still need a HIPAA security risk analysis and the safeguards it calls for. SB 2610 also expects your program to conform to HIPAA if you are subject to it (Sec. 542.004(b)(2)(A)).
  • PCI DSS. If you accept payment cards and PCI DSS applies to you, SB 2610 expects your program to conform to its current version (Sec. 542.004(b)(3)).

Frequently asked questions

The first of three Implementation Groups in the CIS Critical Security Controls. CIS defines it as “essential cyber hygiene,” 56 Safeguards that every enterprise should apply to defend against the most common attacks.

56, out of 153 Safeguards in CIS Controls v8.1. They come from 15 of the 18 Controls.

Version 8.1, released June 25, 2024. As of September 30, 2026, CIS still calls v8.1 the latest version.

Not as a mandate. SB 2610 is a voluntary safe harbor. For business entities with at least 20 but fewer than 100 employees that want its protection, the program requirements include CIS Controls IG1 (Sec. 542.004(a)(4)(B)).

No. For fewer than 20 employees, the statute calls for “simplified requirements, including password policies and appropriate employee cybersecurity training” (Sec. 542.004(a)(4)(A)). IG1 is named for the 20 to 99 employee tier.

Yes, for your own organization. CIS says the CIS Controls “are free to use by anyone to improve their own cybersecurity.” Vendors and consultants who use them in services for customers need a CIS SecureSuite membership or other CIS permission. You download them from CIS after a short sign in.

No. IG1 is a set of practices you carry out and document. It is not a certification of your organization.

It is a strong starting point, not the finish line. CIS says every enterprise should start with IG1, and IG2 and IG3 add Safeguards for organizations with more risk or more resources. Other laws and contracts that apply to you still apply.

Sources

Last reviewed: September 30, 2026

This page is general information about the CIS Critical Security Controls and related Texas law, not legal advice for your situation.

CIS Controls® is a registered trademark of the Center for Internet Security, Inc.

Talk with ALCON DTS about CIS Controls IG1

Not sure how many of the 56 IG1 Safeguards you already meet, or which gaps matter most? We will walk through your environment, show you what is in place and give you a clear plan for the rest.

Email: info@alcondts.com · Phone: 512-892-6900

Talk with ALCON DTS