A meeting in a bright meeting room

Gap assessment against CIS Controls with an implementation roadmap

Measure security maturity, benchmark it and turn it into an actionable roadmap.

An industrial company wanted to position its security maturity objectively and derive a reliable roadmap from it.

Starting point

The maturity of the IT security organization was not measurably captured. A prioritized basis for investment was missing.

Approach

  • Gap assessment against the CIS Critical Security Controls via interviews and questionnaires
  • Benchmark against other industrial companies
  • Derived and prioritized measures and work packages
  • Created a priority roadmap and supported the implementation
  • Management report with KPIs via Power BI

Result

  • An objective baseline with a benchmark
  • A prioritized, actionable roadmap instead of a pure assessment
  • Sustainable reporting on progress
  • Supported implementation instead of a report in the drawer

Frameworks and tools used

CIS ControlsNIST CSF 2.0Zero TrustPower BI