Skip to main content
Image coming soon

Deeper Command of the CIS Controls Framework

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Deeper Command of the CIS Controls Framework

Build unshakable fluency in the most widely adopted security control baseline

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior technical sales and advisory practitioners influencing enterprise security adoption decisions

Who this is not for

Entry-level implementers, auditors solely focused on compliance checkboxes, or those without influence on deployment scope

What you walk away with

  • Navigate all 18 CIS Controls with confidence and context
  • Map control requirements to common technical configurations
  • Anticipate validation criteria used in enterprise audits
  • Explain prioritization logic behind Implementation Groups
  • Lead discussions with confidence when security trade-offs arise

The 12 modules (with all 144 chapters)

Module 1. Introduction to CIS Controls and Their Role in Enterprise Security
Establish foundational understanding of the CIS Controls structure, purpose, and adoption drivers across global enterprises.
12 chapters in this module
  1. What the CIS Controls are
  2. How they differ from NIST CSF
  3. The role of CIS in benchmarking
  4. Who adopts these controls
  5. How controls map to risk
  6. Origin and evolution of the framework
  7. Use cases in enterprise sales
  8. Alignment with ISO 27001
  9. Common misconceptions clarified
  10. Structure of Implementation Groups
  11. Control vs sub-control hierarchy
  12. How regulators reference CIS
Module 2. CIS Control 1 to 6: Inventory and Business Risk Foundation
Master the first implementation group focusing on asset management, software inventory, secure configurations, and account control.
12 chapters in this module
  1. Asset inventory requirements
  2. Network device tracking methods
  3. Software inventory scope
  4. Secure configuration benchmarks
  5. Auto-updating policies
  6. Account provisioning standards
  7. Credential management baseline
  8. Multi-factor enforcement
  9. Access review cadence
  10. Service account controls
  11. Firewall rule documentation
  12. Network segmentation basics
Module 3. CIS Control 7 to 10: Continuous Vulnerability Management
Develop fluency in scanning, prioritization, patching cadence, and email protection mechanisms.
12 chapters in this module
  1. Vulnerability scan frequency
  2. CVSS scoring interpretation
  3. Patch within 72 hours rule
  4. Antivirus coverage requirements
  5. Email filtering standards
  6. Malware protection scope
  7. Phishing simulation frequency
  8. Spam filtering configuration
  9. DNS filtering setup
  10. Endpoint detection baseline
  11. Remediation validation steps
  12. Exception handling process
Module 4. CIS Control 11 to 14: Secure Network and Access Architecture
Understand network segmentation, authentication, wireless security, and data protection expectations.
12 chapters in this module
  1. Network segmentation design
  2. Default-deny rule philosophy
  3. Access control lists usage
  4. Encrypted session enforcement
  5. Wireless authentication mode
  6. Guest network isolation
  7. Data classification standards
  8. Encryption in transit rule
  9. Encryption at rest scope
  10. Portable device encryption
  11. Session timeout configuration
  12. Remote access policy baseline
Module 5. CIS Control 15 to 18: Incident Response and Organizational Policy
Gain mastery over audit logging, incident response planning, change management, and staff training expectations.
12 chapters in this module
  1. Log retention duration
  2. Centralized log collection
  3. Time synchronization setup
  4. Event correlation baseline
  5. Incident response team definition
  6. Response plan documentation
  7. Tabletop exercise cadence
  8. Change control process
  9. Secure development lifecycle
  10. Staff training frequency
  11. Security awareness content
  12. Third-party risk considerations
Module 6. Mapping CIS Controls to Real-World Configurations
Translate control language into technical implementation patterns across enterprise environments.
12 chapters in this module
  1. How Control 4 applies to Windows
  2. How Control 4 applies to Linux
  3. Endpoint encryption deployments
  4. Firewall rule examples
  5. Email filtering configurations
  6. DNS filtering setup steps
  7. Active Directory group policy
  8. Mobile device management setup
  9. Cloud storage encryption
  10. SaaS application access controls
  11. Audit log setup for AWS
  12. Audit log setup for Azure
Module 7. Implementation Groups and Prioritization Logic
Understand how IG1, IG2, and tailored adoption pathways shape deployment strategies.
12 chapters in this module
  1. Purpose of Implementation Groups
  2. IG1 baseline scope
  3. IG2 additional requirements
  4. Determining IG eligibility
  5. Gap assessment process
  6. Roadmap sequencing logic
  7. Leadership sign-off steps
  8. Resource estimation model
  9. Vendor alignment checklist
  10. Internal stakeholder mapping
  11. Budgeting for control gaps
  12. Measuring progress toward IG2
Module 8. Auditor Expectations and Evidence Collection
Anticipate what assessors require for each control and how to streamline evidence gathering.
12 chapters in this module
  1. Common auditor questions
  2. Evidence types per control
  3. Interview preparation checklist
  4. Documentation formatting
  5. Screenshot standards
  6. Configuration file exports
  7. Timestamp verification
  8. Sampling methodology
  9. Exception justification
  10. Remediation tracking log
  11. Sign-off workflows
  12. Pre-audit validation steps
Module 9. Integrating CIS Controls with Other Frameworks
Align CIS Controls with NIST CSF, ISO 27001, and internal compliance programs.
12 chapters in this module
  1. Mapping CIS to NIST CSF
  2. CIS vs SOC 2 overlap
  3. Integration with ISO 27001
  4. Cross-walking control sets
  5. Avoiding duplicate effort
  6. Single evidence strategy
  7. Unified policy documentation
  8. Consolidated training approach
  9. Unified audit timeline
  10. Shared responsibility models
  11. Cloud provider alignment
  12. Third-party attestation usage
Module 10. CIS Controls in Sales Engineering and Customer Engagement
Leverage framework fluency to guide customer conversations and shape solution scope.
12 chapters in this module
  1. Positioning controls early
  2. Identifying customer maturity
  3. Gap analysis conversation
  4. Solution bundling logic
  5. Vendor comparison points
  6. Differentiating with depth
  7. Addressing competitive claims
  8. Risk-based prioritization
  9. Implementation timeline estimates
  10. Stakeholder communication plan
  11. Executive summary templates
  12. Customer readiness assessment
Module 11. Maintaining Compliance Over Time
Establish practices for continuous monitoring, change tracking, and control sustainability.
12 chapters in this module
  1. Automated control checks
  2. Configuration drift alerts
  3. Change review workflows
  4. Periodic access reviews
  5. Audit log retention checks
  6. Control ownership model
  7. Role rotation considerations
  8. Third-party reassessment
  9. Policy refresh cycle
  10. Training recertification
  11. Incident response updates
  12. Documentation version control
Module 12. Final Validation and Readiness for External Assessment
Prepare for external validation with confidence using proven readiness steps and stakeholder alignment.
12 chapters in this module
  1. Pre-assessment checklist
  2. Internal mock audit
  3. Evidence completeness review
  4. Stakeholder alignment
  5. Executive briefing prep
  6. Remediation backlog triage
  7. Scope finalization
  8. Auditor logistics
  9. Evidence delivery method
  10. Post-audit action plan
  11. Certification tracking
  12. Continuous improvement loop

How this maps to your situation

  • Customer security readiness assessment
  • Competitive positioning on controls depth
  • Internal team alignment on control ownership
  • Executive briefing on compliance posture

Before vs. after

Before
Surface-level familiarity with CIS Controls used in customer conversations
After
Confident, detailed command enabling precise guidance and strategic influence

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for completion over 6 weeks with real-world application.

How this compares to the alternatives

Unlike generic compliance courses, this program delivers specific implementation patterns, auditor expectations, and sales engineering applications tailored to senior practitioners influencing enterprise security adoption.

Frequently asked

Is this course technical or strategic?
It bridges both, focused on technical control understanding with strategic application in sales and advisory roles.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me respond to RFPs?
Yes, each control is paired with evidence standards and implementation examples used in real assessments.
$199 one-time. Approximately 3 hours per module, designed for completion over 6 weeks with real-world application..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours