We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. CIS Controls assessment
CIS Critical Security Controls assessment, UAE

Eighteen controls, in a deliberate order. The first two are an inventory, because everything after them depends on knowing what you have.

The CIS Critical Security Controls are a prescriptive, prioritised and simplified set of best practices. The prioritisation is the whole point: the order is not alphabetical or thematic, it reflects what protects most for least effort. Version 8.1 adds a governance function and updated alignment to other frameworks.

Book a CIS Controls assessmentSee the eighteen controls
CIS Critical Security Controls assessment for UAE organisations
  • 18 controlsCIS Controls version 8.1
  • PrioritisedThe order is the guidance
  • GovernanceThe security function added in v8.1
  • MeasurableAssessed, scored, and re-assessed
Why this framework

Seven reasons the CIS Controls are the right starting framework for most organisations.

The Center for Internet Security describes the Controls as a prescriptive, prioritised and simplified set of best practices for strengthening cybersecurity posture. Each of those three words is doing work, and together they explain why an organisation with no framework should usually start here rather than with something larger.

It is prioritised, and the order is the advice

Control 1 is inventory and control of enterprise assets. Control 2 is inventory and control of software assets. They are first because every subsequent control depends on knowing what exists. An organisation that starts at control 10, malware defences, because it feels urgent, is protecting an estate it cannot enumerate. The sequence is the most valuable thing the framework provides.

It is prescriptive, which is rarer than it sounds

Many frameworks tell you to have appropriate controls and leave the definition to you, which produces documents that satisfy an auditor and change nothing. The CIS Controls describe specific things to do. That makes an assessment produce a task list rather than a maturity narrative, and a task list is what actually gets funded and finished.

Version 8.1 adds a governance function

CIS describes v8.1 as introducing a governance security function alongside updated alignment to evolving industry standards and frameworks. That reflects the same direction other frameworks have moved in, and it matters because it makes explicit what previous versions left implicit: somebody has to own each control and answer for it.

It maps to the frameworks you may already be measured against

Updated alignment to evolving industry standards and frameworks is one of the stated changes in v8.1. For UAE organisations that are simultaneously being asked about NIST, ISO, a regulator questionnaire and a customer security review, doing the work once against the CIS Controls and mapping outwards is considerably cheaper than answering each independently.

It covers the whole estate, not only the technology

Control 14 is security awareness and skills training. Control 15 is service provider management. Control 17 is incident response management. Those sit alongside the technical controls deliberately, because an organisation with excellent technology, untrained people and unmanaged suppliers has a well-defended perimeter around an open door.

It produces a score you can move

Because the controls are specific, an assessment produces a position per control rather than an overall impression. That is what allows the second assessment, six or twelve months later, to demonstrate movement. A framework that only produces a narrative cannot show improvement, which makes the next round of funding much harder to justify.

It is a starting point, not a certification

The CIS Controls are not certifiable in the way ISO 27001 is, and that is a feature rather than a gap. An organisation can adopt them immediately, at whatever depth is realistic, without an audit body, a scope statement or a certification budget. Where certification is required later, the work done here transfers directly.

The thing organisations skip

Controls 1 and 2 are an inventory. Almost nobody has one, and everything else depends on it.

The order of the eighteen controls is not arbitrary. The first two exist because the rest are unmeasurable without them.

  • Control 1 is inventory and control of enterprise assets. Control 2 is inventory and control of software assets. Together they answer what you have and what is running on it.
  • Every control after them is qualified by that answer. Vulnerability management covers the assets you know about. Malware defences protect the endpoints you know about. Audit log management collects from the systems you know about. Coverage percentages mean nothing without a denominator.
  • In practice this is the least popular part of any assessment and the most valuable. It is unglamorous, it takes real effort, and it consistently produces the finding that changes the rest of the programme, which is usually that the estate is ten to thirty percent larger than the register says.
  • That is also why external attack surface discovery and software inventory tooling belong in the first phase rather than the last. Building the inventory by hand from what people remember reproduces exactly the gap the control exists to close.
Ask us to start with the inventory
How we approach it

Four things that make a controls assessment worth more than the report.

Framework assessments have a reputation for producing documents rather than change, and it is deserved. Every point below exists to make this one different.

We assess on evidence, not on a questionnaire

The answer to whether a control is implemented is frequently different from the answer given in a workshop, and it is not because anybody is being dishonest. It is because the person answering describes the intent and the evidence describes the reality. Asking for the artefact rather than the assurance is what makes the finding useful.

We keep the published order unless there is a reason not to

The prioritisation is the framework main contribution, and it is easy to argue away in favour of work that feels more interesting. Departing from the sequence is legitimate when there is a regulatory obligation, a customer requirement or a recent incident driving it. It is not legitimate because control 1 is tedious.

We name an owner per control, because v8.1 asks us to

Version 8.1 introduces a governance security function, and the practical expression of that is a named person accountable for each control rather than a collective assumption that IT has it covered. Controls with no owner are the ones that regress first, and the regression is invisible until the next assessment.

We book the re-assessment before delivering the first one

The second assessment is what converts a report into a programme. Comparable format, same eighteen controls, twelve months later, showing movement. Booking it in advance changes the behaviour of everybody involved, because remediation stops being optional the moment it will be measured again on a known date.

How we run it

Four phases, and the assessment is the smallest part.

An assessment that produces a report and stops has wasted everybody time. The value is in the sequence that follows it, and in the second assessment that proves the sequence worked.
  1. 01
    Weeks 1 to 3

    Assess against all eighteen

    Evidence-based rather than questionnaire-based wherever possible, because the answer to whether a control is implemented is frequently different from the answer somebody gives in a workshop. Controls 1 and 2 get disproportionate attention, since the accuracy of everything else depends on the inventory being real.

    • A documented position on each of the eighteen controls
    • Evidence recorded against each finding, not assertion
    • Asset and software inventory gap quantified
    • Findings mapped to the frameworks you are also measured against
  2. 02
    Weeks 4 to 6

    Prioritise using the published order, then adjust for you

    The CIS order is the default prioritisation and it is a good one. Adjusting it means having a reason: a regulatory obligation, a customer requirement, a recent incident, or a control that is nearly complete and cheap to finish. Everything else follows the published sequence, because arguing with a prioritised framework usually means preferring the comfortable work.

    • A remediation plan ordered by control number and adjusted for context
    • Owner and target date against every item
    • Quick wins separated from programme-level work
    • Effort and dependency mapped so the plan is deliverable
  3. 03
    Months 2 to 9

    Remediate, starting with the inventory

    Controls 1 and 2 first, because every measurement after them depends on the denominator being right. Then through the sequence, with the governance question asked at each control: who owns this, and what happens when they leave. Version 8.1 makes governance an explicit function rather than an assumption.

    • A real asset and software inventory, maintained rather than snapshotted
    • Controls implemented in sequence with evidence retained
    • An owner named against every control
    • Progress reported in the same format the assessment used
  4. 04
    Month 12

    Re-assess and show the movement

    The same assessment, run again, in the same format. That is the artefact that justifies the next year of investment, because it converts security spending from a cost that produced a report into a cost that produced measurable movement across eighteen named controls.

    • A second assessment directly comparable to the first
    • Movement quantified per control
    • The remaining gap re-prioritised for the following year
    • A board-readable summary, because this framework produces one
Where this fits

Six UAE situations where the CIS Controls are the right framework to start with.

The common case is an organisation that needs to improve, knows it, and has no way to decide what to do first or to demonstrate afterwards that it worked.

A business with no security framework and a growing list of requests

Customers asking for security questionnaires, an insurer asking about controls, a board asking whether the organisation is safe. Eighteen prescriptive controls in a prioritised order turns that into a plan, and because v8.1 aligns to other frameworks, the answers largely transfer to whatever questionnaire arrives next.

A regulated firm that needs technical substance behind a policy set

Regulatory frameworks in the UAE frequently require appropriate controls without prescribing them. The CIS Controls provide the prescription. Mapping the eighteen to the regulatory obligation gives you both a defensible technical baseline and a clear line from each control to the requirement it satisfies.

An organisation that has just had an incident

The instinct after an incident is to fix the thing that happened, which is necessary and insufficient. A full assessment against the eighteen answers the question the board will actually ask, which is what else looks like that. Controls 1, 2, 5, 6 and 8 usually explain how the incident progressed as far as it did.

An operator with an estate nobody has fully enumerated

Plants, yards and remote facilities accumulate technology locally. Controls 1 and 2 are the entire value of the engagement for this profile, because the gap between what the register says and what exists is where the risk lives. Everything downstream becomes measurable once that gap is closed.

A healthcare or education organisation with limited security resource

A prioritised framework matters most where there is least capacity. Knowing that controls 1 through 6 deserve the available effort, and that control 18 can wait, is more valuable to a small team than a comprehensive framework that gives equal weight to everything and is therefore never finished.

A group standardising security across several entities

The same eighteen controls, assessed the same way, across each entity, produces a comparable picture that a group function can act on. That is difficult with a narrative framework and straightforward with a prescriptive one, which is why multi-entity groups tend to end up here even when an individual entity would have chosen otherwise.

Three positions

How UAE organisations decide what security work to do.

The middle column is the most common and the most expensive over time. Work gets done, it is genuinely useful, and nobody can say whether the organisation is better off than last year.
Known position on every control
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsNo
No framework at allNo
Work prioritised by impact
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsBy urgency
No framework at allNo
Asset and software inventory real
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsPartly
No framework at allNo
Owner named per control
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsNo
No framework at allNo
Progress measurable year on year
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsNo
No framework at allNo
Maps to other frameworks asked about
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsNo
No framework at allNo
Non-technical controls included
Assessed against a prioritised frameworkYes
Work driven by incidents and requestsRarely
No framework at allNo
Answer for a customer security review
Assessed against a prioritised frameworkEvidence
Work driven by incidents and requestsAssertions
No framework at allNone
Budget case for next year
Assessed against a prioritised frameworkStraightforward
Work driven by incidents and requestsDifficult
No framework at allVery difficult
Cost to start
Assessed against a prioritised frameworkAssessment
Work driven by incidents and requestsNone
No framework at allNone
Feature
Assessed against a prioritised framework
Work driven by incidents and requests
No framework at all
Known position on every control
YesNoNo
Work prioritised by impact
YesBy urgencyNo
Asset and software inventory real
YesPartlyNo
Owner named per control
YesNoNo
Progress measurable year on year
YesNoNo
Maps to other frameworks asked about
YesNoNo
Non-technical controls included
YesRarelyNo
Answer for a customer security review
EvidenceAssertionsNone
Budget case for next year
StraightforwardDifficultVery difficult
Cost to start
AssessmentNoneNone
The eighteen

CIS Controls version 8.1, in published order.

Control numbers and names as published by the Center for Internet Security. The right hand column is where we most often find the gap in UAE organisations, which is ours rather than CIS.
ControlNameWhere the gap usually is
1Inventory and Control of Enterprise AssetsThe register is incomplete, and nobody knows by how much
2Inventory and Control of Software AssetsSoftware installed by users, and applications nobody owns
3Data ProtectionNo classification, so no way to prioritise anything
4Secure Configuration of Enterprise Assets and SoftwareA baseline was set once and has drifted since
5Account ManagementLeavers, shared accounts and service accounts nobody owns
6Access Control ManagementAccess granted correctly and never taken back
7Continuous Vulnerability ManagementScanning happens, remediation does not
8Audit Log ManagementLogs collected, retention undefined, nobody reviews them
9Email and Web Browser ProtectionsLicensed features that were never configured
10Malware DefensesServers running something different from endpoints
11Data RecoveryBackups exist, restores have never been tested
12Network Infrastructure ManagementFirewall rules added, never removed
13Network Monitoring and DefenseAlerts generated, nobody works the queue
14Security Awareness and Skills TrainingAn annual module nobody remembers taking
15Service Provider ManagementNo inventory of who has access to what
16Application Software SecurityCustom applications with no security testing
17Incident Response ManagementA plan that has never been exercised
18Penetration TestingTested once, findings not fully remediated
How an engagement runs

Five steps, and the second assessment is part of the first engagement.

Typically three to five weeks for the assessment, then a remediation programme sized to what the assessment finds, with a re-assessment booked at the outset.
  1. 1

    Agree scope and gather evidence

    Which entities, which environments, whether third-party managed systems and custom software are included. Then evidence collection rather than a questionnaire, because the artefact and the assurance frequently differ and only one of them survives an audit.

  2. 2

    Assess all eighteen controls

    A documented position on each, with the evidence recorded against it. Controls 1 and 2 get disproportionate attention because the accuracy of every coverage figure depends on the inventory being genuine rather than remembered.

  3. 3

    Build the plan in the published order

    The CIS sequence as the default prioritisation, adjusted where a regulatory obligation, customer requirement or recent incident gives a reason. Every item gets an owner and a target date, and quick wins are separated from programme-level work so the first three months show visible movement.

  4. 4

    Remediate, with governance named

    Starting with inventory, then through the sequence, with an owner named against each control per the governance function introduced in version 8.1. Evidence retained as work completes, in the format the re-assessment will use, so nothing has to be reconstructed later.

  5. 5

    Re-assess and report the movement

    The same assessment, same format, at the interval agreed at the start. Movement quantified per control, the remaining gap re-prioritised, and a summary that a board can read. That comparison is the single most useful security artefact most organisations can produce.

Straight answers

What organisations ask about the CIS Controls.

Version 8.1 is current, and the Center for Internet Security describes it as adding updated alignment to evolving industry standards and frameworks, and introducing a governance security function. There are eighteen controls, and the numbering and order have been stable enough that work done against a recent earlier version transfers with little rework.

In published order: inventory and control of enterprise assets, inventory and control of software assets, data protection, secure configuration of enterprise assets and software, account management, access control management, continuous vulnerability management, audit log management, email and web browser protections, malware defences, data recovery, network infrastructure management, network monitoring and defence, security awareness and skills training, service provider management, application software security, incident response management, and penetration testing.

Because it is the denominator for everything else. Controls 1 and 2 are first in a prioritised framework for a reason: vulnerability coverage, endpoint protection coverage and logging coverage are all percentages of a total, and if the total is wrong every subsequent measurement is wrong with it. It is the least popular finding and the one that changes the most.

Not in the way ISO 27001 offers certification. The CIS Controls are a prescriptive set of best practices rather than a certifiable management system standard. That is genuinely useful early on, because you can adopt them immediately at whatever depth is realistic. Where certification is later required, the control work transfers into it directly.

They answer different questions. The CIS Controls tell you specifically what to do and in what order. A management system standard tells you how to run a programme that decides what to do. Most organisations that have neither should start with the CIS Controls, because they produce action fastest, then adopt a management system standard when the programme needs formalising.

It makes explicit what earlier versions assumed. Somebody has to own each control and answer for it, and controls with no owner are the ones that regress. In practice it converts an assessment output from a list of technical gaps into a list of technical gaps each with a name attached, which is a materially different document.

Eventually, at a depth appropriate to your organisation. Not at once, and not equally. The prioritisation exists precisely so an organisation with limited capacity knows where to spend it. An honest position on all eighteen, with real progress on the first six, is worth considerably more than partial progress spread evenly across all of them.

Three to five weeks for most organisations, depending on scope and how readily evidence can be produced. The evidence question is usually the variable. Where documentation is current and systems are accessible it moves quickly. Where the inventory has to be built during the assessment, that is itself the first finding and the timeline reflects it.

The pattern is consistent. Controls 1 and 2, because the inventory is incomplete. Control 5 and 6, because access is granted correctly and never taken back. Control 8, because logs are collected and nobody reviews them. Control 11, because backups exist and restores have never been tested. And control 17, because the incident plan has never been exercised.

Substantially, and it is one of the more immediate returns. Because version 8.1 includes updated alignment to evolving industry standards and frameworks, a documented position against the eighteen answers most of what a customer questionnaire asks, with evidence behind it rather than assertions. The second and third questionnaire then cost a fraction of the first.

For some controls, yes, and for others it would substitute for a decision. Configuration hardening in particular benefits from automation, and CISGuard is a product we deploy for automating benchmark compliance. But tooling against control 4 does not fix an incomplete answer to controls 1 and 2, and buying it first is a common and expensive sequencing error.

Annually is the usual rhythm, and we book it at the start of the first engagement rather than at the end. That single scheduling decision changes behaviour, because remediation stops being optional once there is a known date on which it will be measured again in a directly comparable format.

Yes, and it is one of the better frameworks for that. The same eighteen controls assessed the same way produces a comparable position per entity, which a group function can act on. Narrative frameworks produce documents that cannot be compared, which is why multi-entity groups tend to end up with a prescriptive framework even when an individual entity would not have chosen one.

Then we map rather than restart. Work done against another framework generally satisfies specific CIS controls, and version 8.1 aligned alignment to other standards makes that mapping straightforward. The assessment then identifies what your existing framework does not cover, which is usually a shorter list than starting again would imply.

We scope per organisation, driven by the number of entities and environments in scope and how readily evidence can be produced. The remediation programme afterwards is sized by what the assessment finds, which is why we would rather assess first and quote the programme against real findings than estimate both in advance.
Before the assessment

Fifteen questions that shape the engagement.

The first group is scope, the second is evidence, and the third is what happens after the report, which is where most framework assessments quietly end.

Scope

  • Which entities are in scope?
    Groups often assess one and assume the rest.
  • Are cloud and on-premises both included?
    The controls apply to both.
  • Are third-party managed systems in scope?
    Control 15 covers service providers.
  • Is custom software in scope?
    Control 16 covers application security.
  • Are you also measured against another framework?
    v8.1 aligns to several.

Evidence

  • Can you produce an asset inventory today?
    Control 1, and the usual first finding.
  • Can you produce a software inventory?
    Control 2.
  • Are configuration baselines documented?
    Control 4, and drift is the usual issue.
  • Has a restore been tested this year?
    Control 11.
  • Has the incident plan been exercised?
    Control 17.

Afterwards

  • Who owns the remediation plan?
    A report without an owner is a document.
  • Is there budget for the first phase?
    Inventory work is effort, not licences.
  • Who owns each control long term?
    v8.1 makes governance explicit.
  • When is the re-assessment booked?
    Before the first one is delivered.
  • Who sees the results?
    This framework reports well upwards.
Related reading

The pages around this one.

NIST CSF assessment

The management framework, and how the two fit together.

Learn more

IT general controls audit

The financial audit view of controls, which overlaps in specific places.

Learn more

IT audit services

The wider audit practice, and the other assessments available.

Learn more
Next step

Ask whether anyone can produce a complete asset inventory today.

That is control 1, it is first for a reason, and the honest answer in most organisations is no. Knowing the size of that gap is the single most useful thing an assessment produces, and it takes days rather than weeks to establish.

Book a CIS Controls assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Gap Assessment

Distance to a target you actually have to meet

Learn more

Security Policy Development

Policies you can actually comply with

Learn more

NIST CSF 2.0 Assessment

Know where you stand, without committing to certification

Learn more

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Cybersecurity Audit

Security assessment and compliance audit

Learn more

Vulnerability Assessment

Continuous vulnerability scanning and remediation

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy