Skip to main content
Image coming soon

SEC9900 Mastering CIS Controls for Investment Banking Vice Presidents

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for Investment Banking Vice Presidents

Build a self-reinforcing security posture that compounds across mandates and client engagements

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Investment Banking Vice President operating at the intersection of regulatory compliance, client assurance, and deal execution in a global financial institution

Who this is not for

Junior analysts looking for foundational compliance training or professionals outside financial services dealing with non-regulated infrastructure

What you walk away with

  • Deploy CIS Controls as reusable templates across client engagements
  • Reduce time spent on control scoping by leveraging past-mapped architectures
  • Strengthen audit readiness through compoundable documentation
  • Position yourself as the internal reference for control consistency across deals
  • Accelerate client assurance cycles using pre-validated control narratives

The 12 modules (with all 144 chapters)

Module 1. Introduction to CIS Controls in Financial Services
Establish the role of CIS Controls in investment banking contexts, emphasizing alignment with APRA CPS 234, client due diligence, and deal-specific security assurance.
12 chapters in this module
  1. Origins of the CIS Controls framework
  2. Relevance to financial services risk profiles
  3. Mapping CIS to regulatory expectations
  4. Integration with deal lifecycle stages
  5. Benchmarking control maturity
  6. Linking CIS to client assurance requirements
  7. Understanding implementation tiers
  8. Control prioritization by deal type
  9. CIS and third-party risk assessment
  10. Internal stakeholder alignment
  11. Documenting control inheritance
  12. Setting up a compounding control library
Module 2. CIS Control 1: Inventory and Control of Hardware Assets
Learn how to establish and reuse hardware asset inventories across engagements using automated tagging and ownership validation.
12 chapters in this module
  1. Defining hardware scope in banking environments
  2. Automated discovery methods
  3. Ownership validation workflows
  4. Integration with Nomura-like IT systems
  5. Client-facing hardware disclosure
  6. Version control for asset registers
  7. Reusing hardware profiles across deals
  8. Tagging for regulatory reporting
  9. Handling virtualized infrastructure
  10. Cloud provider inventory alignment
  11. Audit trail preparation
  12. Template reuse across mandates
Module 3. CIS Control 2: Inventory and Control of Software Assets
Develop standardized software tracking practices that compound across teams and client engagements.
12 chapters in this module
  1. Software identification techniques
  2. Licensing compliance tracking
  3. Version control integration
  4. End-of-life software detection
  5. Client assurance documentation
  6. Software risk tiering
  7. Cross-deal software baseline creation
  8. Automated update validation
  9. Reusability of software inventories
  10. Integration with patch management
  11. Reporting to senior stakeholders
  12. Template library for software disclosures
Module 4. CIS Control 3: Data Protection
Implement repeatable data classification and protection frameworks applicable across client data environments.
12 chapters in this module
  1. Data classification frameworks
  2. Encryption standards selection
  3. Data residency alignment
  4. Client data handling policies
  5. PII detection automation
  6. Cross-border data flow controls
  7. Reusing classification schemas
  8. Data loss prevention integration
  9. Audit documentation templates
  10. Data retention scheduling
  11. Client-specific data mappings
  12. Versioned data control playbooks
Module 5. CIS Control 4: Secure Configuration for Enterprise Assets
Build secure baselines for enterprise systems that are validated and reused across client projects.
12 chapters in this module
  1. Establishing secure configuration baselines
  2. Hardening web servers
  3. Operating system benchmarks
  4. Client-specific deviation tracking
  5. Automated compliance scanning
  6. Reusing hardened profiles
  7. Patch adherence validation
  8. Integration with CI/CD pipelines
  9. Documenting exceptions
  10. Cross-team configuration sharing
  11. Client assurance reporting
  12. Version-controlled baseline updates
Module 6. CIS Control 5: Account Management
Standardize identity and access management practices that compound across teams and engagements.
12 chapters in this module
  1. User provisioning workflows
  2. Role-based access control design
  3. Privileged account oversight
  4. Multi-factor enforcement
  5. Access review automation
  6. Reusing access control models
  7. Client identity integration
  8. Segregation of duties rules
  9. Centralized logging setup
  10. Audit trail generation
  11. Template-based access policies
  12. Cross-engagement identity patterns
Module 7. CIS Control 6: Access Control Management
Develop scalable access governance frameworks applicable across deal types and client environments.
12 chapters in this module
  1. Network access policy design
  2. Firewall rule standardization
  3. Zero trust alignment
  4. Client-specific segmentation
  5. Automated access reviews
  6. Reusing access control matrices
  7. Integration with identity providers
  8. Remote access safeguards
  9. Change approval workflows
  10. Audit documentation packaging
  11. Cross-mandate access templates
  12. Versioned control matrices
Module 8. CIS Control 7: Continuous Vulnerability Management
Deploy standardized scanning and remediation workflows that accumulate knowledge across engagements.
12 chapters in this module
  1. Vulnerability scanning frequency
  2. CVE prioritization frameworks
  3. Automated patch deployment
  4. Client-specific risk scoring
  5. Remediation tracking systems
  6. Reusing vulnerability baselines
  7. Integration with ticketing tools
  8. Third-party scan validation
  9. Reporting to client stakeholders
  10. Historical trend analysis
  11. Template-based findings packages
  12. Compoundable remediation playbooks
Module 9. CIS Control 8: Audit Log Management
Establish centralized, reusable logging practices that support compliance and client assurance efforts.
12 chapters in this module
  1. Log source identification
  2. Centralized SIEM integration
  3. Retention policy design
  4. Client-specific logging requirements
  5. Automated log analysis
  6. Reusing log correlation rules
  7. Incident response alignment
  8. Audit readiness packaging
  9. Cross-engagement log templates
  10. Normalization standards
  11. Reporting to oversight teams
  12. Version-controlled log playbooks
Module 10. CIS Control 9: Email and Web Browser Protections
Implement standardized browser and email security configurations that are portable across client-facing roles.
12 chapters in this module
  1. Email filtering configuration
  2. Phishing simulation integration
  3. Browser extension control
  4. Client communication security
  5. Reusing browser hardening profiles
  6. User awareness tracking
  7. Integration with security training
  8. Automated policy enforcement
  9. Client assurance documentation
  10. Cross-team browser baselines
  11. Versioned email security templates
  12. Scalable browser control deployment
Module 11. CIS Control 10: Malware Defenses
Build reusable endpoint protection strategies that compound across client environments.
12 chapters in this module
  1. Antivirus deployment standards
  2. EDR solution integration
  3. Malware signature updates
  4. Behavioral detection rules
  5. Client-specific policy tailoring
  6. Reusing defense configurations
  7. Automated threat response
  8. Incident escalation workflows
  9. Audit documentation packaging
  10. Cross-engagement malware baselines
  11. Version-controlled endpoint profiles
  12. Client assurance reporting
Module 12. Compounding Security Outcomes Across Mandates
Synthesize all controls into a reusable, compounding security framework for investment banking.
12 chapters in this module
  1. Integrating CIS Controls across deals
  2. Building a control inheritance model
  3. Reducing setup time for new mandates
  4. Creating client-specific assurance packages
  5. Strengthening re-engagement positioning
  6. Documenting compoundable artifacts
  7. Leveraging past playbooks
  8. Cross-team knowledge transfer
  9. Maintaining control versioning
  10. Scaling audit readiness
  11. Future-proofing control investments
  12. Finalizing the compounding security library

How this maps to your situation

  • Client due diligence preparation
  • Regulatory audit readiness
  • Cross-border transaction assurance
  • Internal governance reporting

Before vs. after

Before
Starting from scratch on control frameworks for each new client mandate, with limited ability to reuse past work.
After
Using a growing library of validated CIS Control implementations that accelerate delivery and strengthen consistency across deals.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for completion over 4-6 weeks with real-world application between modules.

How this compares to the alternatives

Unlike generic compliance training, this course delivers field-tested, banking-specific implementations of CIS Controls designed to compound across real client mandates , not just pass a certification exam.

Frequently asked

Is this course relevant to non-US banking regulations?
Yes. The course includes adaptations for APRA CPS 234, NIS2, and other regional frameworks as they intersect with CIS Controls.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I apply this to client-facing deliverables?
Yes. Each module includes templates and narratives designed for direct reuse in client assurance and due diligence processes.
$199 one-time. Approximately 3 hours per module, designed for completion over 4-6 weeks with real-world application between modules..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours