Security Control Library
One cross-mapped set of 34 security controls that right-sizes to your organisation β flip between Startup, SMB and Enterprise and the list adjusts. Each control says what it requires in plain language and maps to NIST CSF 2.0, CIS v8, ISO 27001:2022 and the CISA CPGs, so you can get organised and walk into a conversation with your auditor prepared.
A helping hand for small and medium businesses β not an audit, not a certification, not legal advice. US & Global.
Small/medium business (up to ~200 staff) β the core baseline. Your view and any download reflect this profile.
One person is explicitly accountable for security decisions, even if it is a part-time or shared role.
A short written security policy and acceptable-use policy exist and staff acknowledge them on joining.
Security risks are identified, rated and recorded in a register, and reviewed at least annually.
Vendors with access to data or systems are assessed before onboarding and tracked over time.
A current inventory of devices and software in use is maintained; unknown assets are investigated.
Sensitive data (personal, financial, customer) is inventoried, classified and its location known.
Key systems, data flows and external connections are documented and kept current.
Systems the business cannot operate without are identified and recorded, with an owner for each.
MFA is enforced on email, remote access, admin accounts and any internet-facing service.
Every user has their own account; access is the minimum needed; no shared or default credentials.
Operating systems and applications are patched on a defined schedule; critical fixes applied fast.
Important data is backed up regularly, with at least one copy offline or immutable, and restores are tested.
Endpoints run maintained anti-malware/EDR with alerts going somewhere a human sees them.
SPF, DKIM and DMARC are configured and spam/phishing filtering is enabled.
Admin rights are limited, separated from day-to-day accounts and reviewed periodically.
Sensitive data is encrypted in transit (TLS) and at rest on devices and in storage.
Staff receive security and phishing awareness training at onboarding and periodically after.
Systems are set up from a hardened baseline; default/insecure settings are changed.
Security-relevant logs are collected centrally and retained for a defined period.
Suspicious activity generates alerts that are reviewed and triaged by someone.
Internet-facing and internal systems are scanned for vulnerabilities and findings are tracked.
A written IR plan exists: roles, steps, and who decides β short enough that people actually use it.
An up-to-date list of who to call (internal, provider, legal, insurer, regulator) is kept offline.
The team knows which regulator to notify and by when for a reportable incident (US: CIRCIA, SEC, state breach laws).
A process exists to notify affected individuals and regulators of a personal-data breach where required.
Restoring from backup is tested on a schedule β not assumed to work.
Recovery time and recovery point objectives are defined for key systems and data.
A helping hand, not an audit or certification β and not legal advice. Controls are cross-referenced to well-known frameworks (NIST CSF, CIS, ISO 27001, CISA CPGs) for orientation; verify specifics against the current source and your own obligations.
What this tool is
- A cross-mapped security control library, right-sized by org profile β flip between Startup, SMB and Enterprise and the 34 controls re-scope to that tier.
- Each control is written in plain language (what it requires) and cross-referenced to NIST CSF 2.0, CIS v8, ISO 27001:2022 and the CISA CPGs for orientation.
- View is free; download the profile-scoped list as CSV or Markdown (Pro) to drop into a risk register or hand to your auditor.
- A helping hand for small and medium businesses β not an audit, not a certification, not legal advice.
Frequently asked questions
What is the Control Library?
A single, cross-mapped set of 34 security controls that re-scopes to your organisation profile. Pick Startup (lean essentials), SMB (the core baseline) or Enterprise (the full set) and the list adjusts β one dataset, not three separate libraries.
Which frameworks does it map to?
Each control references NIST CSF 2.0 functions, CIS Critical Security Controls v8, ISO/IEC 27001:2022 Annex A, and the CISA Cross-Sector Cybersecurity Performance Goals. These are orientation references, not a claim of certification.
Does it cover other countries?
The baseline is framework-neutral (Global); a US lens adds CISA/CIRCIA/FTC context. We deliberately keep it to US and Global rather than claiming per-country tailoring.
Is this an audit or a compliance certificate?
No. It is a self-assessment and planning aid β a helping hand to get organised and talk to your auditor. It is not an audit, not a certification, and not legal advice.
Is it free?
The library view is free to use. Downloading your profile-scoped control list (CSV or Markdown) is a Pro feature included with any PlayCISO paid plan.