If you’ve had a cloud security audit before, or read one of ours, you’ve probably seen findings referenced against “CIS 1.5” or “CIS 2.1.5” — control numbers pulled from the Center for Internet Security’s benchmark for your cloud provider. It’s the closest thing the industry has to an agreed-upon baseline for secure configuration. But most business owners have never actually been told what the Level 1 vs Level 2 distinction means, or why it matters for the decisions they’re making.
What CIS Benchmarks Are
The CIS Foundations Benchmark (there’s a version for AWS, Azure, and GCP) is a set of prescriptive configuration recommendations developed through a consensus process involving security practitioners, vendors, and government agencies. Instead of one auditor’s opinion of what “secure” looks like, it’s a peer-reviewed standard that auditors, insurers, and compliance frameworks already recognize.
Level 1: Practical, Low-Friction Controls
Level 1 recommendations are designed to be applied broadly with minimal impact on system functionality or performance. Think: enabling MFA on the root account, turning on audit logging, blocking public access on storage by default. These are the controls where there’s essentially no good argument against implementing them — the security benefit is high and the operational cost is close to zero.
For most small and mid-size businesses, full Level 1 compliance should be considered the minimum acceptable baseline, not an aspirational goal.
Level 2: Defense-in-Depth, With Real Trade-offs
Level 2 recommendations go further — additional encryption requirements, stricter network segmentation, more aggressive logging and retention, tighter password and session policies. These controls provide meaningful additional protection, but they can introduce friction: more complex key management, additional cost for extended log retention, or workflow changes for engineering teams.
Level 2 isn’t automatically “better” for every business — it’s a deliberate trade-off between security posture and operational overhead. Whether it’s worth it depends on what you’re protecting and what your regulatory or insurance obligations actually require.
How to Decide What You Need
A few questions we walk clients through:
- What data do you actually hold? Customer PII, payment data, and health records raise the bar significantly versus a marketing site with no sensitive data.
- What do your compliance obligations require? PCI-DSS, HIPAA, and SOC 2 each reference baseline expectations that often align closer to Level 2 in specific control areas, even if you’re not pursuing full Level 2 everywhere.
- What does your cyber insurance policy actually require? Increasingly, insurers are asking pointed technical questions before binding or renewing a policy, and gaps here can affect your premium or coverage.
In practice, most of our clients land on full Level 1 compliance plus targeted Level 2 controls in the specific areas that matter most for their data and industry — not an all-or-nothing choice.
Why This Matters Beyond the Audit Report
Benchmark alignment isn’t just a scoring mechanism. It gives you a defensible position if you’re ever asked “how do you know your cloud environment is secure?” by an insurer, a customer’s security questionnaire, or a board member. “We align to the CIS Foundations Benchmark, audited by a third party” is a very different answer than “we think we’re fine.”
If you want to see how findings get mapped to specific CIS controls in practice, our sample cloud security audit report shows the format we use, including control references for every finding.