Identity & Access Management capability of SimpliKeys (SK), mapped to the IAM-relevant Safeguards
CIS Controls v8.1 (June 2024) · Prepared mid-2026 · Capability mapping, not a compliance attestation
Coverage of the 18 IAM-relevant safeguards
CIS Controls v8.1 (June 2024) is the current version — an iterative update to v8.0 with the same 18 controls and 153 safeguards, a new 'Govern' security function aligned to NIST CSF 2.0, and revised asset classes. There is no v9. Implementation Group (IG1/IG2/IG3) tags below reflect common understanding; confirm exact levels in the CIS Controls Navigator.
The IAM-relevant safeguards — Control 5 (Account Management), Control 6 (Access Control Management), and the access-related logging safeguards in Control 8 (Audit Log Management). This is NOT a full CIS Controls mapping: the other controls and the non-IAM safeguards are out of scope here.
SimpliKeys is a single unified platform: the capabilities described below are facets of one system applied to each control, not separate products. It protects every identity with the same vaulting, brokering and session recording, and applies strong authentication from a configurable spectrum of factors that can be targeted per system, chained, and stepped up within a session.
Every rating below holds only to the extent of two things: (1) breadth — the scope of the environment SimpliKeys is protecting; a control is supported only where SimpliKeys sits in the access path, not for systems outside its reach; and (2) depth — how SimpliKeys is configured. The analysis assumes SimpliKeys is deployed and configured as the central authentication manager for the in-scope environment.
Entries describe summarised SimpliKeys capability under common circumstances and when appropriately configured. They do not represent verified or certified behaviour.
The CIS Controls are a voluntary, prioritized set of best-practice safeguards — there is no certification against them (some U.S. state safe-harbour statutes reference them). SimpliKeys can help implement specific safeguards when appropriately configured, but no tool makes an organisation 'CIS-compliant'; the organisation implements and self-assesses its safeguards. Treat every 'Supports' as 'capability provided when appropriately configured.'
Supports
SimpliKeys provides the capability that meets this control when appropriately configured; configuration to the applicable thresholds and implementation still apply.
Partial
SimpliKeys addresses part of this control; full compliance needs additional measures, or depends on coverage or architecture beyond SimpliKeys alone.
Assists
SimpliKeys does not perform this control (it is organisational or process), but supplies information, logs, visibility, or evidence that makes it easier to complete or to demonstrate.
Out of scope / N/A
Outside SimpliKeys’ role — purely organisational, or not applicable to SimpliKeys (e.g., applies only to third-party service providers).
Filter by coverage
Maintain an inventory of all accounts (user and administrator), reviewed regularly.
What SimpliKeys does
Maintains a single inventory of the identities and accounts it manages, with account visibility from one console.
Customer responsibility & notes
Customer confirms the inventory captures OS, database and application accounts across in-scope assets brought under SimpliKeys.
Use unique passwords for all in-scope assets (minimum 8 characters with MFA, 14 without).
What SimpliKeys does
Enforces password policy and holds unique service-account credentials in the vault.
Customer responsibility & notes
Customer sets the minimum length/complexity to meet the 8/14-character guidance.
Delete or disable accounts dormant for more than 45 days, where supported.
What SimpliKeys does
Disables accounts automatically after a configurable period of inactivity.
Customer responsibility & notes
Customer sets the dormancy period to 45 days (or its standard); SimpliKeys detects inactivity and auto-disables.
Use dedicated, separate accounts for administrative work.
What SimpliKeys does
Separates and brokers privileged access, vaulting and recording dedicated administrator accounts apart from day-to-day accounts.
Customer responsibility & notes
Customer defines which accounts are administrative; SimpliKeys enforces the separation and records their use.
Maintain an inventory of service (non-human) accounts, reviewed regularly.
What SimpliKeys does
Manages and inventories service and other non-human identities with the same lifecycle and visibility as any identity.
Customer responsibility & notes
Customer brings service accounts under SimpliKeys; discovery/inventory coverage depends on the systems connected.
Centralize account management through a directory or identity service.
What SimpliKeys does
Is the central identity platform, integrating directories (AD/Entra/LDAP) and managing accounts from one place.
Customer responsibility & notes
Customer brings all in-scope assets under central management, including legacy systems.
Use a defined process to grant access when roles or employment change.
What SimpliKeys does
Grants access through request and approval workflows tied to role and joiner/mover events.
Customer responsibility & notes
Customer defines approvers and the granting workflow.
Use a defined process to revoke access on termination or role change.
What SimpliKeys does
Revokes access on termination or role change, driven by joiner/mover/leaver events from connected HR and source systems.
Customer responsibility & notes
Customer connects the source systems so revocation propagates promptly to all connected systems.
Enforce MFA on externally-exposed or third-party applications, where supported.
What SimpliKeys does
Enforces strong authentication at every externally-exposed application it fronts, from a spectrum of factors including phishing-resistant FIDO2/passkeys.
Customer responsibility & notes
Customer routes externally-exposed applications through SimpliKeys to enforce MFA.
Enforce MFA for remote network access.
What SimpliKeys does
Applies the same authentication policy to remote network access, with adaptive, risk-based decisions.
Customer responsibility & notes
Customer integrates SimpliKeys with the remote-access path (VPN/ZTNA).
Enforce MFA for all administrative access.
What SimpliKeys does
Applies strong authentication to all administrative access, the same way it protects every privileged session.
Customer responsibility & notes
Customer ensures all administrative entry points, including break-glass, route through SimpliKeys.
Maintain an inventory of the enterprise's authentication and authorization systems.
What SimpliKeys does
Surfaces the identity sources and systems it integrates with, and as the central platform reduces the number of separate auth/authz systems to track.
Customer responsibility & notes
SimpliKeys provides visibility into the auth/authz systems it connects to, which helps build the inventory; maintaining the enterprise-wide inventory of all such systems is an organisational task the customer owns.
Centralize access control through a directory or SSO service.
What SimpliKeys does
Centralizes access control as the unified SSO and directory-integrated platform.
Customer responsibility & notes
Customer brings in-scope assets under the SSO/directory service.
Define and document RBAC and review access rights against roles.
What SimpliKeys does
Defines and enforces role-based access and runs periodic reviews of access against roles.
Customer responsibility & notes
Customer defines and documents the roles; SimpliKeys enforces them and supports the periodic review.
Collect audit logs across enterprise assets per the logging process.
What SimpliKeys does
Records identity and access activity — every action on the network by any identity — and forwards it to SIEM.
Customer responsibility & notes
Customer confirms identity/access logs are collected; broader asset logs may use other sources.
Collect detailed logs (event source, date, user, timestamp, and so on).
What SimpliKeys does
Records detailed identity/access events including user, device, location, timestamp and keystroke detail.
Customer responsibility & notes
Customer confirms SimpliKeys records include all the detail elements it requires.
Centralize audit-log collection and retention.
What SimpliKeys does
Forwards its identity/access logs to a centralized SIEM (e.g., Splunk, QRadar).
Customer responsibility & notes
SimpliKeys forwards the logs; central retention and storage are handled by the SIEM — customer owns the pipeline and retention.
Review audit logs to detect anomalies or abnormal events.
What SimpliKeys does
Analyzes identity/access logs with behavioural analytics and surfaces anomalies in real time.
Customer responsibility & notes
SimpliKeys performs the automated analysis and detection; the review cadence and responsibilities remain the customer's.
Mapping reflects CIS Controls v8.1 (June 2024) as understood in mid-2026, reviewed safeguard-by-safeguard with SimpliKeys. Safeguard text is paraphrased; the Controls are free at cisecurity.org. IG tags reflect common understanding — confirm in the CIS Controls Navigator. 'Supports' = capability provided when appropriately configured; the customer implements, configures and self-assesses its safeguards.
30 minutes against a real environment — we’ll walk your controls line by line.
Book demo