Aspendora Technologies
Menu

Free self-service resource

The small-business compliance checklist

All 56 safeguards of CIS Controls v8.1, Implementation Group 1 — the recognized “essential cyber hygiene” baseline that underpins a Texas SB 2610 safe-harbor program. In plain English. Check off what you’ve already done; we’ll remember your progress on this device.

How to use this

Work top to bottom. Each item is a real CIS IG1 safeguard with its official ID and a plain-English version of what it asks you to do. Tick the boxes you can honestly say you’ve done and can prove. Your progress saves automatically in this browser — nothing is sent to us. Use Print for a clean copy or PDF.

A quick caveat

This is honest self-assessment, not a formal audit or legal advice. A real safe-harbor program needs the right scope for your headcount and evidence that each control is actually in place. We’re your security and IT partner; your attorney confirms how the safe harbor applies to you.

0of 56 safeguards
0%
Control 1

Inventory and Control of Enterprise Assets

0/2

You can’t protect what you don’t know you have. Start with a complete, current list of every device.

Control 2

Inventory and Control of Software Assets

0/3

Know exactly what software is running — and make sure it’s authorized and still supported.

Control 3

Data Protection

0/6

Know what sensitive data you hold, control who can reach it, and dispose of it safely.

Control 4

Secure Configuration of Enterprise Assets and Software

0/7

Devices and software ship insecure by default. Set — and document — a hardened standard.

Control 5

Account Management

0/4

Every account is a way in. Track them, keep them unique, and close the ones you don’t need.

Control 6

Access Control Management

0/5

Grant access deliberately, revoke it instantly, and require MFA where it counts.

Control 7

Continuous Vulnerability Management

0/4

Find weaknesses before attackers do — and patch on a predictable schedule.

Control 8

Audit Log Management

0/3

When something goes wrong, logs are how you know what happened. Turn them on and keep them.

Control 9

Email and Web Browser Protections

0/2

Email and the browser are where most attacks land. Keep them current and filtered.

Control 10

Malware Defenses

0/3

Anti-malware on every device, kept current, with risky auto-execution turned off.

Control 11

Data Recovery

0/4

Backups only count if they’re automated, protected, isolated — and actually restorable.

Control 12

Network Infrastructure Management

0/1

Your firewalls, switches, and access points need patching too.

Control 14

Security Awareness and Skills Training

0/8

Your people are your largest attack surface — and your best early-warning system.

Control 15

Service Provider Management

0/1

Your vendors’ security is your security. Know who has access to your data.

Control 17

Incident Response Management

0/3

Decide who does what, and how to report a problem, before you’re in the middle of one.

Why three controls are missing

CIS Controls 1–18 are complete, but three —13 (Network Monitoring and Defense), 16 (Application Software Security), 18 (Penetration Testing) — have no IG1 safeguards by design. CIS expects those of larger, more mature organizations (IG2 and IG3). At the IG1 baseline, the 56 items above are the complete list.

Email me my results + a personalized fix-list

Get a printable copy of this checklist with your answers, plus a prioritized remediation roadmap built from the gaps you found — the 56-safeguard baseline turned into a short, ordered to-do list. We’ll send it to your inbox.

No spam. We’ll only use this to send your results and follow up about your compliance baseline.

Found some gaps?

That’s the point of the exercise — and it’s normal. The hard part isn’t the checklist; it’s proving each item is real and keeping it that way. A baseline assessment scores you against all 56 safeguards, collects the evidence, and gives you a prioritized roadmap for the gaps. That’s what turns SB 2610 into a safe harbor you can actually stand on.

Find out what your "yes" is really worth.

Book a free 30-minute discovery call. In four weeks you’ll have a scored baseline, a prioritized roadmap, and evidence that stands up to an insurer or auditor.

Free 30-minute call · no obligation · no sales pressure — or call(281) 941-4028