ASSESS · SOLUTION

CIS Controls IG1 Assessment

Map public and tenant evidence to CIS Controls IG1 questions while showing which safeguards remain unknown.

Run a free domain scoreJoin Open Beta

Last reviewed September 25, 2026.

A CIS Controls IG1 assessment should distinguish evidence that supports a safeguard from evidence that merely raises a question. SCOUTz can connect supported public and customer-approved tenant observations to an IG1 discussion, but it does not turn unread safeguards into passes or claim certification.

SCOUTz keeps the source, timestamp, boundary, and next choice together. That makes the page useful to the seller, the owner, and the operator who receives the work after the meeting.

What can public evidence contribute to IG1?

It can support a narrow set of externally observable configuration and exposure questions. The record can show what a domain publishes and when. It cannot establish inventory completeness, internal process, staff behavior, or recovery testing.

The practical test is whether another person can understand the claim, identify its source, and decide what should happen next without treating an unknown as a pass.

What does tenant evidence add?

A customer-approved read-only review can provide supported configuration and metadata context. The MSP still needs to validate scope, ownership, exceptions, and operational practice with the customer.

The practical test is whether another person can understand the claim, identify its source, and decide what should happen next without treating an unknown as a pass.

How should an unknown safeguard appear?

As unknown or could not be read, with the source needed to answer it. This is more useful than a green checkbox because it tells the MSP what the next conversation must establish.

The practical test is whether another person can understand the claim, identify its source, and decide what should happen next without treating an unknown as a pass.

Evidence, support, and boundary

Evidence stateWhat it supportsBoundary
Published domain recordsA narrow external-control discussionNot a complete IG1 implementation record
Tenant configuration metadataSupported identity and application questionsNot proof policies are followed operationally
Customer attestation and MSP recordsProcess and ownership contextMust remain clearly labeled as supplied evidence

Worked example

A published mail policy can support a question about sender authentication. The IG1 mapping still leaves asset inventory, secure configuration process, and recovery testing for the sources that can actually establish them.

This example is deliberately narrow. A finding can start a useful business conversation without proving a breach, a clean environment, a complete compliance program, or a commercial outcome. The report should say which of those statements it can support and which remain for the MSP and customer to establish.

How SCOUTz gets the MSP there

SCOUTz begins with the least intrusive source that can answer the question. The public domain layer dispatches 35 collectors and can reach 123 distinct finding types. When a customer approves the next step, the read-only cloud layer is a superset with 93 collectors and 370 reachable finding types. Platform-wide, 601 finding types across 91 emitting modules include fusion and correlation logic that runs on top of collector output.

Every finding carries authored business-language explanation, consequence, recommendation, and the evidence it came from. The ledger separates 440 scored findings, 107 context observations, and 22 declared non-reads. A check that could not be read appears as NOT ASSESSED THIS SCAN, so the next choice is visible instead of hidden inside a score.

The MSP still owns authorization, interpretation, customer communication, remediation, and the final commercial decision. SCOUTz supplies the record and the route. That boundary is what makes the output safe to use in a real relationship.

Frequently asked questions

What does SCOUTz actually read?

The public domain layer reads disclosed public records and signals. A customer-approved Microsoft 365 review reads supported configuration and metadata through a read-only connection. SCOUTz does not read messages, files, documents, chats, or prompts.

Does an unknown result count as clean?

No. A check that could not be read is declared as a non-read. It remains visible on the record and is not converted into a pass or a blended score.

Can an MSP use its own branding?

Yes. Client-safe output is designed for the MSP's name, logo, colors, contact details, and delivery motion while operator evidence remains available to the team doing the work.

What happens after the first result?

The MSP reviews the evidence, agrees the next action with the customer, performs the work through its own process, and uses a supported rescan or source refresh to show what changed.

Does SCOUTz certify CIS IG1?

No. It organizes evidence and unknowns around supported questions. Certification, attestation, and control ownership remain with the MSP and customer.

Keep the evidence attached to the work.

Read the methodology, review the trust boundary, see the sample report, compare pricing, and run the public tools before you choose the next step.

RELATED SOLUTIONS

SCOUTz OPEN BETA

Point SCOUTz at your next prospect. Walk in with a defensible answer.

Join Open Beta with a real MSP workflow. A person reviews every application before a workspace goes live. SCOUTz runs without an agent or install and never changes a configuration on its own.

SCOUTz prepares the conversation. The relationship and the sale stay yours.