Skip to content
Tidebreak Advisory

Vertical crosswalk · Legal

The rules your committee follows, mapped to the controls your carrier recognizes.

CIS Controls v8.1.2 × ABA Model Rules of Professional Conduct

Introduction and methodology

The ABA Model Rules of Professional Conduct do not read like a technical standard. Rule 1.6(c) asks for reasonable efforts to prevent inadvertent or unauthorized disclosure. Rule 5.3 extends supervisory obligations to the firm's nonlawyer assistance, including its IT provider. The Rules describe the obligation a lawyer carries; they do not prescribe the controls that satisfy it.

This crosswalk is rule-first. Each row names an ABA Model Rule and the conduct obligation it carries, then lists the CIS Controls v8.1.2 safeguards that support that obligation in a firm's IT environment. CIS Controls v8.1.2is the security framework a firm's cyber-insurance carrier, outside auditor, and regulator already recognize. The mapping is how a control finding lands in a register the firm's counsel can defend.

The mapping is directional, not exhaustive. A safeguard listed against a rule supports compliance with that rule; it does not, on its own, establish it. Where no meaningful mapping exists, the absence is information. The crosswalk is a reference tool, not an opinion.

The crosswalk

Ten representative rule rows. The ABA Model Rule is the organizing column; the CIS Controls v8.1.2safeguards are the supporting column.

ABA Model Rules of Professional Conduct mapped to supporting CIS Controls v8.1.2 safeguards.
ABA Model RuleConduct obligationSupporting CIS Controls v8.1.2 safeguards
Rule 1.1 Cmt 8Competence (technology)Maintain the technological competence to understand the risks and benefits of the technology the firm uses to hold client information.1.1 Detailed Enterprise Asset Inventory · 4.1 Secure Configuration Process
Rule 1.4CommunicationsKeep the client reasonably informed, which presumes the firm can detect and reconstruct events affecting a matter.8.1 Audit Log Management Process · 13.1 Centralize Security Event Alerting
Rule 1.6(c)Confidentiality of InformationMake reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation.3.3 Configure Data Access Control Lists · 3.12 Segment Data by Sensitivity
Rule 1.7Conflict of Interest: Current ClientsPrevent one client's matter from reaching personnel working an adverse current matter, including through shared systems.3.12 Segment Data by Sensitivity · 6.8 Define and Maintain Role-Based Access Control
Rule 1.9Duties to Former ClientsProtect former-client confidences, which requires retiring access that is no longer justified by a current need.5.1 Inventory of Accounts · 6.8 Role-Based Access Control
Rule 1.10Imputation of Conflicts of InterestHonor screening obligations where a conflict is imputed firm-wide, which depends on enforceable access segregation.3.3 Configure Data Access Control Lists · 6.8 Role-Based Access Control
Rule 1.15Safekeeping PropertySafeguard client property and records, including electronic trust-accounting and matter records, against loss.11.1 Establish and Maintain a Data Recovery Process · 3.1 Data Management Process
Rule 1.16(d)Declining or Terminating RepresentationReturn client materials on termination and retire the departing matter's access, which requires reliable revocation.5.1 Inventory of Accounts · 6.8 Role-Based Access Control
Rule 5.1Responsibilities of Supervisory LawyersMake reasonable efforts to ensure the firm has measures giving reasonable assurance of conformance with the Rules, which extends to the firm's IT governance.6.1 Establish an Access Granting Process · 14.1 Security Awareness Program
Rule 5.3Responsibilities Regarding Nonlawyer AssistanceExtend supervisory obligations to the firm's nonlawyer assistance, including the managed service provider that operates the firm's systems.6.1 Establish an Access Granting Process · 8.1 Audit Log Management Process

Worked examples

Four representative findings drawn from law-firm assessments, each dual-mapped to a CIS Controls v8.1.2safeguard set and the ABA Model Rules it implicates.

Worked example

Critical

Shared attorney drive with standing privileged access

Security mapping

CIS Safeguards 3.3 · 3.12 · 6.8

Professional-standard mapping

ABA Model Rules 1.6, 1.7, 1.10, and 1.1 Cmt 8

Evidence 4, 7, 12

Firm-wide shared drive granted read and write access to matter documents for all users, including terminated staff retaining credentials. Access was not segregated by matter, and standing privileged access remained active for MSP engineers.

Recommended action. Segregate matter access by practice need, remove standing privileged access, and enforce quarterly entitlement reviews with documented sign-off by firm leadership.

Worked example

Critical

Departed attorney retained credentials and matter access

Security mapping

CIS Safeguards 5.1 · 6.8

Professional-standard mapping

ABA Model Rules 1.9 and 1.16(d)

Evidence 9, 14

Two attorneys who left the firm in the prior year retained active accounts and former-matter access. No offboarding checklist tied account revocation to departure, and no periodic account inventory reconciled active accounts against current staff.

Recommended action. Establish an account inventory reconciled against HR records each quarter, and tie revocation to a documented offboarding step that closes within one business day of departure.

Worked example

Moderate

No tested recovery path for matter and trust-accounting records

Security mapping

CIS Safeguards 3.1 · 11.1

Professional-standard mapping

ABA Model Rules 1.15 and 1.1 Cmt 8

Evidence 18, 21

Backups of matter files and trust-accounting records ran nightly, but no restoration test had been performed in over eighteen months. The firm could not demonstrate that a recovery would succeed, and retention of the records was not governed by a data-management process.

Recommended action. Document a data-management process with retention rules, and perform and record a restoration test of matter and trust-accounting records at least semi-annually.

Worked example

Moderate

Managed service provider operating without documented supervision

Security mapping

CIS Safeguards 6.1 · 8.1

Professional-standard mapping

ABA Model Rules 5.1 and 5.3

Evidence 3, 11, 25

The firm's MSP provisioned accounts and held administrative access, but no access-granting process required firm approval, and audit logs of administrative sessions were neither retained nor reviewed. The MSP had not been asked about its access in three years.

Recommended action. Adopt an access-granting process requiring firm sign-off for privileged access, and require the MSP to retain and surface administrative audit logs for periodic firm review.

Regulatory variation

The ABA Model Rules are a model. Each jurisdiction adopts and amends them, and state bar opinions interpret the technology-competence and confidentiality obligations differently. This crosswalk maps to the Model Rules as updated through 2023; it does not substitute for the rules and opinions of the firm's governing jurisdiction.

  • California. Adopted its own numbered Rules of Professional Conduct in 2018, with confidentiality grounded in Business and Professions Code section 6068(e). The substance tracks Model Rule 1.6, but the citations and several comments differ.
  • New York. Retains its own Rules of Professional Conduct, and the New York State Bar Association has issued ethics opinions addressing cloud storage and vendor access that inform the reasonable-efforts standard.
  • Florida and Texas-Illinois.Florida imposes a defined technology continuing-education requirement, and the Texas and Illinois rules carry their own comment language on competence and supervision. A firm should map to its own jurisdiction's text before relying on this crosswalk.

Disclaimers

  1. Not legal advice. This document does not constitute legal advice. Firm leadership and the firm's counsel make all legal determinations.
  2. Not an attestation. Tidebreak performs assessments, not attest audits. This crosswalk is a reference mapping, not an opinion, certification, or attestation.
  3. Framework currency. Framework references are to the editions identified in this document: CIS Controls v8.1.2 (2024), NIST CSF 2.0 (2024), and the ABA Model Rules of Professional Conduct as updated through 2023. Frameworks are reviewed annually and on material changes.
  4. Regulatory or jurisdictional scope. This crosswalk does not address state bar opinions or jurisdiction-specific variations beyond those enumerated in the Regulatory Variation section.
  5. Distribution. This document is provided for the use of the client and its designated advisors. Further distribution, in whole or part, requires written permission.

Tidebreak performs independent assessments.