Skip to content
πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
Compliance Β· Helping hand

Security Control Library

One cross-mapped set of 34 security controls that right-sizes to your organisation β€” flip between Startup, SMB and Enterprise and the list adjusts. Each control says what it requires in plain language and maps to NIST CSF 2.0, CIS v8, ISO 27001:2022 and the CISA CPGs, so you can get organised and walk into a conversation with your auditor prepared.

A helping hand for small and medium businesses β€” not an audit, not a certification, not legal advice. US & Global.

Org profile
Region

Small/medium business (up to ~200 staff) β€” the core baseline. Your view and any download reflect this profile.

Showing 27 of 34 controls Β· SMB
Govern Β· 4
GV-1
Named security ownerfrom Startup

One person is explicitly accountable for security decisions, even if it is a part-time or shared role.

CSF GV.RRISO A.5.2CPG 1.B
GV-2
Information security & acceptable-use policyfrom Startup

A short written security policy and acceptable-use policy exist and staff acknowledge them on joining.

CSF GV.POCIS 14ISO A.5.1
GV-3
Risk assessment on recordfrom SMB

Security risks are identified, rated and recorded in a register, and reviewed at least annually.

CSF GV.RMISO A.5.9
GV-4
Third-party / supplier risk managementfrom SMB

Vendors with access to data or systems are assessed before onboarding and tracked over time.

CSF GV.SCCIS 15ISO A.5.19
Identify Β· 4
ID-1
Hardware & software asset inventoryfrom Startup

A current inventory of devices and software in use is maintained; unknown assets are investigated.

CIS 1CIS 2E8 Β· patch (prereq)CPG 1.AISO A.5.9
ID-2
Data inventory & classificationfrom SMB

Sensitive data (personal, financial, customer) is inventoried, classified and its location known.

CIS 3ISO A.5.12FTC
ID-3
Network & system documentationfrom SMB

Key systems, data flows and external connections are documented and kept current.

ISO A.8.9CIS 12
ID-4
Critical / key systems registerfrom SMB

Systems the business cannot operate without are identified and recorded, with an owner for each.

ISO A.5.9CIS 1
Protect Β· 10
PR-1
Multi-factor authenticationfrom Startup

MFA is enforced on email, remote access, admin accounts and any internet-facing service.

CIS 6E8 Β· MFACPG 1.C
PR-2
Unique accounts & least privilegefrom Startup

Every user has their own account; access is the minimum needed; no shared or default credentials.

CIS 5CIS 6ISO A.5.15
PR-3
Timely patching of OS & applicationsfrom Startup

Operating systems and applications are patched on a defined schedule; critical fixes applied fast.

CIS 7E8 Β· patch appsE8 Β· patch OSCPG 1.E
PR-4
Tested, offline/immutable backupsfrom Startup

Important data is backed up regularly, with at least one copy offline or immutable, and restores are tested.

CIS 11E8 Β· backupsISO A.8.13
PR-5
Endpoint protection / EDRfrom SMB

Endpoints run maintained anti-malware/EDR with alerts going somewhere a human sees them.

CIS 10ISO A.8.7
PR-6
Email authentication & filteringfrom SMB

SPF, DKIM and DMARC are configured and spam/phishing filtering is enabled.

CIS 9CPG
PR-7
Restrict administrative privilegesfrom SMB

Admin rights are limited, separated from day-to-day accounts and reviewed periodically.

E8 Β· restrict adminCIS 5ISO A.5.15
PR-8
Encryption in transit & at restfrom SMB

Sensitive data is encrypted in transit (TLS) and at rest on devices and in storage.

ISO A.8.24CIS 3
PR-9
Security awareness trainingfrom SMB

Staff receive security and phishing awareness training at onboarding and periodically after.

CIS 14ISO A.6.3
PR-10
Secure configuration baselinesfrom SMB

Systems are set up from a hardened baseline; default/insecure settings are changed.

CIS 4ISO A.8.9
Detect Β· 3
DE-1
Centralised logging & retentionfrom SMB

Security-relevant logs are collected centrally and retained for a defined period.

CIS 8ISO A.8.15
DE-2
Monitoring & alertingfrom SMB

Suspicious activity generates alerts that are reviewed and triaged by someone.

CIS 8CIS 13CPG
DE-3
Vulnerability scanningfrom SMB

Internet-facing and internal systems are scanned for vulnerabilities and findings are tracked.

CIS 7ISO A.8.8
Respond Β· 4
RS-1
Incident response planfrom Startup

A written IR plan exists: roles, steps, and who decides β€” short enough that people actually use it.

CIS 17ISO A.5.24CPG
RS-2
Contacts & escalation listfrom Startup

An up-to-date list of who to call (internal, provider, legal, insurer, regulator) is kept offline.

CIS 17ISO A.5.24
RS-3
Reporting obligations & deadlines knownfrom SMB

The team knows which regulator to notify and by when for a reportable incident (US: CIRCIA, SEC, state breach laws).

CIRCIA Β· 72h/24hISO A.5.24
RS-4
Breach notification processfrom SMB

A process exists to notify affected individuals and regulators of a personal-data breach where required.

FTCISO A.5.26
Recover Β· 2
RC-1
Test restores from backupfrom Startup

Restoring from backup is tested on a schedule β€” not assumed to work.

CIS 11E8 Β· backups
RC-2
Recovery objectives (RTO/RPO)from SMB

Recovery time and recovery point objectives are defined for key systems and data.

ISO A.5.30CIS 11
Loading…

A helping hand, not an audit or certification β€” and not legal advice. Controls are cross-referenced to well-known frameworks (NIST CSF, CIS, ISO 27001, CISA CPGs) for orientation; verify specifics against the current source and your own obligations.

TL;DR

What this tool is

  • A cross-mapped security control library, right-sized by org profile β€” flip between Startup, SMB and Enterprise and the 34 controls re-scope to that tier.
  • Each control is written in plain language (what it requires) and cross-referenced to NIST CSF 2.0, CIS v8, ISO 27001:2022 and the CISA CPGs for orientation.
  • View is free; download the profile-scoped list as CSV or Markdown (Pro) to drop into a risk register or hand to your auditor.
  • A helping hand for small and medium businesses β€” not an audit, not a certification, not legal advice.

Frequently asked questions

What is the Control Library?

A single, cross-mapped set of 34 security controls that re-scopes to your organisation profile. Pick Startup (lean essentials), SMB (the core baseline) or Enterprise (the full set) and the list adjusts β€” one dataset, not three separate libraries.

Which frameworks does it map to?

Each control references NIST CSF 2.0 functions, CIS Critical Security Controls v8, ISO/IEC 27001:2022 Annex A, and the CISA Cross-Sector Cybersecurity Performance Goals. These are orientation references, not a claim of certification.

Does it cover other countries?

The baseline is framework-neutral (Global); a US lens adds CISA/CIRCIA/FTC context. We deliberately keep it to US and Global rather than claiming per-country tailoring.

Is this an audit or a compliance certificate?

No. It is a self-assessment and planning aid β€” a helping hand to get organised and talk to your auditor. It is not an audit, not a certification, and not legal advice.

Is it free?

The library view is free to use. Downloading your profile-scoped control list (CSV or Markdown) is a Pro feature included with any PlayCISO paid plan.

Security Control Library β€” Startup / SMB / Enterprise, cross-mapped Β· PlayCISO