From cis-controls
Determine appropriate CIS Controls Implementation Group (IG1/IG2/IG3)
How this command is triggered — by the user, by Claude, or both
Slash command
/cis-controls:ig-selectThe summary Claude sees in its command listing — used to decide when to auto-load this command
> _CIS Controls v8 content used under CC BY-SA 4.0 from the Center for Internet Security. This command's CIS-derived content is CC BY-SA 4.0. See [LICENSE-CIS.md](../LICENSE-CIS.md)._ # CIS Controls IG Selection Helps determine the appropriate Implementation Group (IG1, IG2, or IG3) for your organization based on size, resources, risk profile, and adversary sophistication. ## Arguments - `$1` - Organization size (optional: small, medium, large) - `$2` - Risk profile (optional: low, moderate, high, critical) ## Implementation Group Decision Framework ### IG1 - Essential Cyber Hygiene (...
CIS Controls v8 content used under CC BY-SA 4.0 from the Center for Internet Security. This command's CIS-derived content is CC BY-SA 4.0. See LICENSE-CIS.md.
Helps determine the appropriate Implementation Group (IG1, IG2, or IG3) for your organization based on size, resources, risk profile, and adversary sophistication.
$1 - Organization size (optional: small, medium, large)$2 - Risk profile (optional: low, moderate, high, critical)Recommended For:
Resource Requirements:
Threat Profile:
Example Organizations:
Recommended For:
Resource Requirements:
Threat Profile:
Example Organizations:
Recommended For:
Resource Requirements:
Threat Profile:
Example Organizations:
| Factor | IG1 | IG2 | IG3 |
|---|---|---|---|
| Employees | <100 | 100-1,000 | 1,000+ |
| IT Staff | 1-2 generalists | 3-10 with security focus | 10+ dedicated security |
| Annual Revenue | <$10M | $10M-$1B | $1B+ |
| Data Sensitivity | Basic business data | Customer PII, PHI | Trade secrets, critical infrastructure |
| Regulatory | Minimal | Moderate (HIPAA, SOX) | High (CMMC, NERC CIP) |
| Threat Level | Opportunistic | Targeted | Advanced/persistent |
| Security Budget | <$50K | $100K-$500K | $1M+ |
| Downtime Tolerance | Hours-days | Hours | Minutes |
Organizations should consider a phased approach:
Phase 1: Implement IG1 (Foundation)
Phase 2: Advance to IG2 (If needed)
Phase 3: Advance to IG3 (If needed)
High-Risk Factors (may warrant higher IG):
Offsetting Factors (may allow lower IG):
Healthcare:
Financial Services:
Manufacturing:
Technology:
# Determine IG for small healthcare practice
/cis:ig-select small moderate
# Assess IG needs for large financial institution
/cis:ig-select large critical
# Evaluate IG requirements for medium manufacturer
/cis:ig-select medium moderate
# General IG selection guidance
/cis:ig-select
npx claudepluginhub shipstuff/claude-grc-engineering --plugin cis-controls/ig-selectDetermines the appropriate CIS Controls Implementation Group (IG1, IG2, or IG3) based on organization size, risk profile, resources, and threat sophistication.
9plugins reuse this command
First indexed Apr 26, 2026
Showing the 6 earliest of 9 plugins