Who the standard applies to
- Entities regulated under the relevant authority
- Service providers processing in-scope data on their behalf
- Groups seeking a defensible baseline for the relevant risk domain
Defining the right scope is the single biggest determinant of CIS Controls v8 success. Too narrow and the certificate is meaningless; too broad and the programme stalls under its own weight.
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Icon grid titled "Scope dimensions" with 5 categories: Legal entities and business units in scope, Geographies and data residency boundaries, Cloud accounts, data centres and end-user computing estates, Third parties processing in-scope data on your behalf, Products, services or customer segments included.
Checklist titled "Scoping pitfalls to avoid" with 4 items, every item marked complete: Excluding shared services (HR, payroll, identity) that handle in-scope data.; Treating SaaS platforms as out-of-scope when they process production data.; Omitting DR, backup and recovery sites from the boundary.; Forgetting to include the security operations function itself..
A two-week scoping sprint with your sponsor, IT, security, legal and audit produces a written scope statement, an asset and data-flow map, and a signed-off boundary diagram. This becomes the anchor for the entire CIS Controls v8 programme.