CIS RAM for Risk-Based Cybersecurity
What Is CIS RAM?
CIS RAM, the Center for Internet Security Risk Assessment Method, helps organizations evaluate risk and implement the CIS Controls in a reasonable and appropriate way.
HALOCK Security Labs and the Center for Internet Security co-developed CIS RAM to connect security controls to actual risk. Instead of assuming every CIS Control must be implemented at the same level, the method helps organizations determine which safeguards are justified for their environment. CIS RAM consulting helps organizations apply that methodology, define acceptable risk, evaluate threats, and select safeguards that support business, regulatory, and stakeholder needs.
Why Use CIS RAM for Risk-Based Cybersecurity?
A control gap does not automatically tell an organization how much risk exists or how urgently the gap should be addressed. CIS RAM gives practitioners a structured process to:
- identify important information assets;
- model foreseeable threats;
- establish risk criteria;
- estimate likelihood and impact;
- evaluate existing safeguards;
- determine whether additional CIS Controls are justified.
This creates risk-based cybersecurity decisions rather than treating a controls checklist as the final answer.
CIS RAM and Reasonable Security
CIS RAM applies DoCRA principles to the CIS Controls.
DoCRA establishes principles for determining whether safeguards are reasonable by balancing the risk to affected parties against the burden created by the safeguard. CIS RAM converts those principles into a practical assessment method for implementing CIS Controls.
The result helps organizations demonstrate reasonable security and due care through documented risk decisions.
Apply the Right Level of CIS Controls
Implementing every possible control without considering risk can waste resources and interfere with business operations. Implementing too little can leave important risks untreated.
CIS RAM helps organizations find the appropriate balance.
Through structured risk analysis, organizations can determine which safeguards materially reduce risk and whether their burden is justified. The resulting risk treatment priorities provide a practical roadmap for implementing CIS Controls based on the organization’s mission, objectives, obligations, and threat environment.
What Is New in CIS RAM 2.1?
CIS RAM 2.1 improves the assessment process by:
- automating more risk analysis through workbooks;
- estimating likelihood by comparing reported threat frequency with the strength of relevant CIS Safeguards;
- using the VERIS Community Database to support evidence-based likelihood estimation.
These changes help practitioners evaluate risk more consistently and efficiently.
Why Choose HALOCK for CIS RAM Consulting?
HALOCK helped develop CIS RAM and has deep experience applying DoCRA, CIS Controls, risk assessment, and Reasonable Security principles in operational environments. We help clients move from methodology to implementation by establishing risk criteria, conducting assessments, evaluating safeguards, prioritizing treatment, and documenting defensible decisions.
The objective is not simply to complete a CIS RAM workbook. It is to use the method to establish the right level of security for the organization.
Contact Us
What Is ‘Reasonable Security’?
If your information is breached and your case goes to litigation, you will be asked to demonstrate “due care.” Organizations must use safeguards to ensure that the risk is reasonable to the organization and appropriate to other interested parties at the time of the breach. For reasonable implementation of the CIS Controls, the CIS risk assessment method (RAM) helps your organization demonstrate the right level of due care.
What’s New in CIS RAM v2.1?
- Workbooks automate much of your risk analysis for faster results.
- CIS RAM 2.1 estimates the likelihood by comparing the commonality of reported threats to the strength of CIS Safeguards that prevent them.
- Using the Veris Community Database (VCDB), CIS RAM introduces an evidence-based heuristic for estimating likelihood.
FAQs on CIS RAM and DoCRA
Who authored DoCRA and CIS RAM?
The authors are CIS RAM and DoCRA:
- CIS RAM was originally developed by HALOCK Security Labs in partnership with the Center for Internet Security (CIS).
- The principal author of both DoCRA and CIS RAM is Chris Cronin (Partner at HALOCK Security Labs; Chair of the DoCRA Council).
- DoCRA itself is maintained by the DoCRA Council, a nonprofit body that includes CIS among its founding members.
How are “Reasonable Security,” CIS RAM, and DoCRA related?
Reasonable Security is the legal requirement. DoCRA defines how to judge what’s reasonable by balancing risk and burden, and CIS RAM applies DoCRA in practice so organizations can demonstrate that their security decisions are justified and defensible.
DoCRA and CIS RAM work together as a standard-and-method pair:
- DoCRA provides the principles for determining what is “reasonable,” guiding analysts to balance risk reduction with the burden of safeguards and the impact on all affected parties.
- CIS RAM applies those DoCRA principles directly to the CIS Critical Security Controls, giving organizations worksheets, criteria, and a repeatable process to evaluate risks and justify their security decisions.
HALOCK turns technical findings into legally defensible, business-aligned decisions. Our DoCRA and CIS RAM-driven risk assessments, continuous exposure programs, and incident response services give boards and regulators the evidence they expect. Protect revenue, reduce liability, and show reasonable security with HALOCK’s pragmatic, courtroom-tested approach.

