
Gap assessment against CIS Controls with an implementation roadmap
Measure security maturity, benchmark it and turn it into an actionable roadmap.
An industrial company wanted to position its security maturity objectively and derive a reliable roadmap from it.
Starting point
The maturity of the IT security organization was not measurably captured. A prioritized basis for investment was missing.
Approach
- Gap assessment against the CIS Critical Security Controls via interviews and questionnaires
- Benchmark against other industrial companies
- Derived and prioritized measures and work packages
- Created a priority roadmap and supported the implementation
- Management report with KPIs via Power BI
Result
- An objective baseline with a benchmark
- A prioritized, actionable roadmap instead of a pure assessment
- Sustainable reporting on progress
- Supported implementation instead of a report in the drawer
Frameworks and tools used
CIS ControlsNIST CSF 2.0Zero TrustPower BI