Free self-service resource
All 56 safeguards of CIS Controls v8.1, Implementation Group 1 — the recognized “essential cyber hygiene” baseline that underpins a Texas SB 2610 safe-harbor program. In plain English. Check off what you’ve already done; we’ll remember your progress on this device.
Work top to bottom. Each item is a real CIS IG1 safeguard with its official ID and a plain-English version of what it asks you to do. Tick the boxes you can honestly say you’ve done and can prove. Your progress saves automatically in this browser — nothing is sent to us. Use Print for a clean copy or PDF.
This is honest self-assessment, not a formal audit or legal advice. A real safe-harbor program needs the right scope for your headcount and evidence that each control is actually in place. We’re your security and IT partner; your attorney confirms how the safe harbor applies to you.
Aspendora Compliance · https://aspendoracompliance.com · (281) 941-4028
You can’t protect what you don’t know you have. Start with a complete, current list of every device.
Know exactly what software is running — and make sure it’s authorized and still supported.
Know what sensitive data you hold, control who can reach it, and dispose of it safely.
Devices and software ship insecure by default. Set — and document — a hardened standard.
Every account is a way in. Track them, keep them unique, and close the ones you don’t need.
Grant access deliberately, revoke it instantly, and require MFA where it counts.
Find weaknesses before attackers do — and patch on a predictable schedule.
When something goes wrong, logs are how you know what happened. Turn them on and keep them.
Email and the browser are where most attacks land. Keep them current and filtered.
Anti-malware on every device, kept current, with risky auto-execution turned off.
Backups only count if they’re automated, protected, isolated — and actually restorable.
Your firewalls, switches, and access points need patching too.
Your people are your largest attack surface — and your best early-warning system.
Your vendors’ security is your security. Know who has access to your data.
Decide who does what, and how to report a problem, before you’re in the middle of one.
Why three controls are missing
CIS Controls 1–18 are complete, but three —13 (Network Monitoring and Defense), 16 (Application Software Security), 18 (Penetration Testing) — have no IG1 safeguards by design. CIS expects those of larger, more mature organizations (IG2 and IG3). At the IG1 baseline, the 56 items above are the complete list.
Get a printable copy of this checklist with your answers, plus a prioritized remediation roadmap built from the gaps you found — the 56-safeguard baseline turned into a short, ordered to-do list. We’ll send it to your inbox.
No spam. We’ll only use this to send your results and follow up about your compliance baseline.
That’s the point of the exercise — and it’s normal. The hard part isn’t the checklist; it’s proving each item is real and keeping it that way. A baseline assessment scores you against all 56 safeguards, collects the evidence, and gives you a prioritized roadmap for the gaps. That’s what turns SB 2610 into a safe harbor you can actually stand on.
Book a free 30-minute discovery call. In four weeks you’ll have a scored baseline, a prioritized roadmap, and evidence that stands up to an insurer or auditor.
Free 30-minute call · no obligation · no sales pressure — or call(281) 941-4028