CIS RAM
The risk-assessment method built for the CIS Controls — it turns a safeguard list into a defensible argument about which risks are reasonable to accept and why.
Mapped, monitored, and audit-ready.
Every CIS RAM control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.
Talarity's pre-built control library covering CIS RAM, with linked evidence, owners, and testing schedules.
Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.
- Asset and software inventory
- Vulnerability scanner output
- Safeguard implementation status from the CIS assessment
- Incident history
- Risk acceptance and treatment records
Your CIS RAM dashboard
Every completed CIS RAM assessment updates this automatically — where you stand now, how that has changed, and which areas need work.
What gets easier with Talarity.
A CIS implementation percentage says nothing about whether the remaining gaps are acceptable.
CIS RAM scores each risk on likelihood and impact against the organisation's own burden threshold, so acceptance is argued rather than assumed.
Risk assessments are written for an auditor and then filed.
Every run is retained and trended, and treatment decisions become tracked work with owners.
The risk register and the controls assessment live in different tools.
Safeguard status feeds the risk assessment directly, so a control change moves the risk rather than requiring a re-key.
CIS RAM — common questions
- Is CIS RAM a control framework?
- No — it is a method for assessing risk against the CIS Controls. It produces a reasoned position on each safeguard rather than a compliance score, which is why this assessment reports a rating average rather than a maturity level.
- Do we need the CIS Controls assessment as well?
- They work together: the CIS assessment establishes implementation status, and CIS RAM reasons about the risk that remains. Talarity shares data between them.
- What does 'reasonable' mean here?
- CIS RAM asks whether the burden of a safeguard is acceptable relative to the risk it reduces — the duty-of-care test used in regulatory and litigation contexts. The assessment records that judgement and its evidence.
Working with CIS RAM
Step-by-step walkthroughs from the Talarity library.
- Compliance·8 min readPackage your audit evidence once — for the auditor, regulator, or customerAn auditor asks for your evidence and it's scattered across framework reports, vendor attestations, policy sign-offs, and resilience tests. Evidence Distribution Packages assemble the signed artifacts you already produced into one immutable package, then hand it to each audience as a redacted, watermarked, time-limited copy — with a record of who received what.
- Compliance·7 min readFramework readiness to audit package — the whole cycle on one screenAudit prep usually means a spreadsheet scramble — chasing evidence, tracking which controls are covered, re-checking what's expired. Talarity keeps a live readiness picture for every framework (SOC 2, ISO 27001, CIS, and more) — coverage, gaps, evidence freshness — and packages it into an auditor-ready export in one click.
- Compliance·7 min readContinuous compliance is a tooling problem, not a process problemEvery compliance program eventually decides it needs to be 'continuous.' Most then try to fix it with process. The actual fix is upstream — in the tools that make evidence freshness a default, not a sprint.
- Compliance·14 min readThe evidence nobody can deleteA legal hold is a promise that a specific piece of evidence will still exist months from now, made to people who will check. This is where you place one in Talarity, what the record has to survive, and — just as important — what a hold does not freeze.
Ready to ship CIS RAM?
Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.