Skip to content
Framework · CIS v2.1 (for CIS Controls v8)

CIS RAM

The risk-assessment method built for the CIS Controls — it turns a safeguard list into a defensible argument about which risks are reasonable to accept and why.

153 Talarity controls mapped
Who it's for: Organisations using the CIS Controls that need to show a duty-of-care rationale, not just an implementation percentage.
Talarity coverage

Mapped, monitored, and audit-ready.

Every CIS RAM control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

153
Talarity controls mapped

Talarity's pre-built control library covering CIS RAM, with linked evidence, owners, and testing schedules.

Cross-maps to
CIS Controls v8NIST CSFISO 27001

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • Asset and software inventory
  • Vulnerability scanner output
  • Safeguard implementation status from the CIS assessment
  • Incident history
  • Risk acceptance and treatment records

Your CIS RAM dashboard

Every completed CIS RAM assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed CIS Risk Assessment Method assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

A CIS implementation percentage says nothing about whether the remaining gaps are acceptable.

Talarity

CIS RAM scores each risk on likelihood and impact against the organisation's own burden threshold, so acceptance is argued rather than assumed.

Pain

Risk assessments are written for an auditor and then filed.

Talarity

Every run is retained and trended, and treatment decisions become tracked work with owners.

Pain

The risk register and the controls assessment live in different tools.

Talarity

Safeguard status feeds the risk assessment directly, so a control change moves the risk rather than requiring a re-key.

CIS RAM — common questions

Is CIS RAM a control framework?
No — it is a method for assessing risk against the CIS Controls. It produces a reasoned position on each safeguard rather than a compliance score, which is why this assessment reports a rating average rather than a maturity level.
Do we need the CIS Controls assessment as well?
They work together: the CIS assessment establishes implementation status, and CIS RAM reasons about the risk that remains. Talarity shares data between them.
What does 'reasonable' mean here?
CIS RAM asks whether the burden of a safeguard is acceptable relative to the risk it reduces — the duty-of-care test used in regulatory and litigation contexts. The assessment records that judgement and its evidence.

Working with CIS RAM

Step-by-step walkthroughs from the Talarity library.

Ready to ship CIS RAM?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.