This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC gives security teams one connected workspace to operationalize the CIS Critical Security Controls, with Safeguard-level assessments, asset and vendor inventories, risk tracking and exceptions, and scorecards and reporting for Implementation Group coverage, all in one place.




























Implementing all 18 CIS Controls and 153 Safeguards is challenging when teams work across email threads, shared drives, and spreadsheets. When assessment responses, asset inventories, and remediation tracking live in separate files, proving Implementation Group coverage can be harder than doing the work itself.
Launch Safeguard assessments from a prebuilt questionnaire library that covers CIS alongside NIST, HIPAA, GLBA, HECVAT, and CMMC. Send questions to the system owners and department leads closest to the work, let several people answer one questionnaire, and collect evidence with each answer. Templates stay customizable, so teams can start with the IG1 Safeguards and extend the same series into IG2 and IG3.
CIS Controls 1 and 2 call for an inventory of enterprise assets and software. In Isora, every asset, application, and vendor links to its assessments, risks, and exceptions, and the assessment workflow keeps it current. Scope a campaign by owning unit or data classification instead of running a discovery project each cycle.
Publish a Safeguard gap to the risk register as soon as an assessment finds it. Every risk traces back to the Safeguard, the question that surfaced it, the asset it affects, and the owner responsible for fixing it. Teams escalate a finding, document an exception with compensating controls and an expiration date, or close it with justification. Severity comes from a 5x5 likelihood-by-impact matrix, and an append-only log records every decision.
Generate scorecards by Control, by Implementation Group, or by organizational unit, and compare coverage across departments. Drill into any number to see the response and the evidence behind it, so an auditor can trace a finding without asking for more documents. Reports update as assessment data changes and export to PDF or CSV.
CIS Controls: What They Are and How to Implement Them The CIS Controls are 18 prioritized cybersecurity controls from the Center for Internet...
Managing an IT asset inventory means maintaining a comprehensive, continuously updated record of all systems, data, users, and networks—structured...
The CIS Critical Security Controls are a prioritized set of 18 Controls and 153 Safeguards published by the Center for Internet Security. They define concrete defensive actions across asset inventory, access control, data protection, incident response, and continuous monitoring. Organizations of any size use them as a starting framework, and CIS sorts the Safeguards into three Implementation Groups so smaller teams can begin with IG1.
Yes. Isora’s prebuilt questionnaire library covers CIS alongside NIST, HIPAA, GLBA, HECVAT, and CMMC, so teams launch from a ready template rather than building an assessment first. Templates stay customizable, which means teams can add questions, adjust scoring logic, or map to specific organizational requirements.
Yes. Assessments group into series by compliance goal, and templates are customizable, so teams commonly scope a first campaign to the 56 IG1 Safeguards that CIS defines as essential cyber hygiene. The same series extends into IG2 and IG3 as the program matures, without rebuilding the assessment.
CIS Controls v8.1, published June 2024, is the current release and keeps the same 18 Controls and 153 Safeguards as v8. Because Isora’s templates are customizable, teams working to either version, or migrating between them, assess against the Safeguard set they are accountable for.
Isora maintains a unified inventory of assets, applications, vendors, and organizational units with customizable metadata, ownership, and data classification. Each item links to its assessment history and associated risks, and the inventory updates through the assessment workflow rather than as a separate maintenance task.
Yes. CIS publishes mappings to more than 25 frameworks, including NIST CSF 2.0, NIST SP 800-53, ISO 27001, and PCI DSS. In Isora, the same inventories, risk register, and reporting infrastructure serve every framework, so a second framework reuses the existing setup on a shared data model.
Isora deploys in days to weeks, not months. No-code setup, no consultants, and no dedicated admin headcount. Enterprise platforms such as Archer and ServiceNow GRC serve enterprise-wide governance and audit, and they usually require months of configuration before the first assessment runs. Audit automation tools serve SOC 2 and ISO audit prep, a narrower job than the recurring Safeguard assessments a CIS program depends on.