What it means
The CIS Critical Security Controls are a prioritised, prescriptive set of safeguards grouped into implementation groups by organisation size and capability. They are more concrete than outcome-based frameworks, which is their appeal to smaller teams.
Prescriptive lists answer what to do. They do not record why an organisation chose to defer one, or on what basis that deferral was reasonable.
Where MyRISK fits
What we do about it
MyRISK does not assess or score CIS implementation. The deferrals and exceptions — the parts of a control set an organisation consciously does not do yet, and why — are decisions, and Trace is where those are held.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.