Skip to main content
Image coming soon

Deeper command of the CIS Controls framework

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Deeper command of the CIS Controls framework

Build unshakable fluency in the most actionable cybersecurity standard for enterprise environments

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior engagement leader in healthcare technology integration, responsible for aligning complex projects with security and compliance expectations

Who this is not for

Individuals seeking introductory cybersecurity training or certification prep, or those not involved in cross-functional system design or compliance validation

What you walk away with

  • Map CIS Controls to real architecture decisions with confidence
  • Anticipate auditor and reviewer pressure points in advance
  • Guide teams through control implementation without defaulting to consultants
  • Turn control documentation into repeatable, reusable playbooks
  • Influence vendor security posture assessments using CIS benchmarks

The 12 modules (with all 144 chapters)

Module 1. CIS Controls framework foundations
Understand the structure, evolution, and intent of the CIS Controls, including how they map to NIST CSF and ISO 27001 for context-specific application.
12 chapters in this module
  1. What the CIS Controls are
  2. How they differ from other standards
  3. Control tiers explained
  4. Implementation groups defined
  5. Mapping to NIST CSF
  6. Mapping to ISO 27001
  7. Role of CIS RAM tool
  8. How controls are updated
  9. Prioritization logic
  10. Relationship to cloud environments
  11. Healthcare-specific examples
  12. Common misinterpretations
Module 2. Inventory of authorized and unauthorized devices
Master Control 1: how to establish and maintain a complete, accurate, and automated device inventory across hybrid environments.
12 chapters in this module
  1. Defining device scope
  2. Network-based discovery methods
  3. Agent-based tracking
  4. Cloud instance tracking
  5. Virtual and container tracking
  6. Rogue device detection
  7. Classification by criticality
  8. Integration with CMDB
  9. Automated alerts setup
  10. Review cycle cadence
  11. Exception handling
  12. Audit evidence collection
Module 3. Inventory of authorized and unauthorized software
Master Control 2: implement robust software monitoring and approval workflows to reduce attack surface.
12 chapters in this module
  1. Software inventory requirements
  2. Active discovery tools
  3. Whitelist policy design
  4. Blocking unauthorized installs
  5. SaaS application tracking
  6. License compliance linkage
  7. Shadow IT identification
  8. User behavior analysis
  9. Approved software list
  10. Update validation process
  11. Integration with patching
  12. Audit trail generation
Module 4. Secure configurations for hardware and software
Implement Control 3 with precision across endpoints, servers, and cloud platforms using benchmarks and automation.
12 chapters in this module
  1. Baseline definition process
  2. CIS Benchmarks usage
  3. Hardening policy templates
  4. Group policy application
  5. Cloud configuration rules
  6. OS-specific settings
  7. Application hardening
  8. Configuration drift detection
  9. Automated remediation
  10. Change control integration
  11. Exception management
  12. Compliance reporting
Module 5. Continuous vulnerability management
Operationalize Control 4 with scanning, prioritization, and workflow integration that keeps pace with modern release cycles.
12 chapters in this module
  1. Scanning frequency standards
  2. Internal vs external scans
  3. Authenticated scanning setup
  4. Cloud asset coverage
  5. Patch prioritization logic
  6. CVSS scoring application
  7. Risk-based exceptions
  8. Ticketing integration
  9. Developer notifications
  10. Remediation SLAs
  11. False positive handling
  12. Executive reporting
Module 6. Controlled use of administrative privileges
Enforce Control 5 with least privilege design, session monitoring, and credential lifecycle oversight.
12 chapters in this module
  1. Privileged account identification
  2. Just-in-time access design
  3. Password vault integration
  4. Session recording setup
  5. Break-glass procedures
  6. Role-based access control
  7. Time-bound permissions
  8. Privilege auditing
  9. Emergency override tracking
  10. Multi-factor enforcement
  11. Blast radius reduction
  12. Privilege creep detection
Module 7. Maintenance, monitoring, and analysis of audit logs
Implement Control 6 to ensure logs are complete, protected, and actionable across systems and teams.
12 chapters in this module
  1. Log source identification
  2. Centralized logging design
  3. Retention policy setup
  4. Encryption in transit
  5. Integrity protection
  6. Log normalization
  7. Correlation rule creation
  8. Retention by regulation
  9. Search capability design
  10. Access controls on logs
  11. Automated alerting
  12. Incident readiness
Module 8. Email and web browser protections
Strengthen Control 7 across user-facing applications with configuration, filtering, and awareness integration.
12 chapters in this module
  1. Browser hardening steps
  2. Email link scanning
  3. Attachment sandboxing
  4. Phishing simulation use
  5. URL filtering setup
  6. Certificate validation
  7. Plugin management
  8. User training integration
  9. Compromised credential alerts
  10. Domain-based message auth
  11. Click-rate monitoring
  12. Threat intel feeds
Module 9. Malware defenses
Deploy Control 8 with layered prevention, detection, and response capabilities tailored to organizational risk.
12 chapters in this module
  1. Endpoint protection tools
  2. Signature-based detection
  3. Behavioral analysis
  4. EDR deployment
  5. Ransomware-specific rules
  6. File reputation services
  7. Execution control setup
  8. Quarantine workflows
  9. Indicators of compromise
  10. Threat hunting integration
  11. Zero-day response plan
  12. Vendor performance review
Module 10. Limitation and control of network ports, protocols, and services
Implement Control 9 to reduce exposure through proactive network segmentation and service governance.
12 chapters in this module
  1. Port inventory process
  2. Default-deny philosophy
  3. Service justification
  4. Firewall rule auditing
  5. Micro-segmentation design
  6. Protocol monitoring
  7. Network access control
  8. Legacy system handling
  9. Change approval workflow
  10. Service timeout policies
  11. Encrypted traffic inspection
  12. Cloud VPC rules
Module 11. Data recovery
Implement Control 11 with reliable, tested backup processes that ensure resilience against ransomware and data loss.
12 chapters in this module
  1. Critical system identification
  2. Backup frequency standards
  3. Encryption of backups
  4. Air-gapped storage
  5. Recovery time objectives
  6. Test restoration process
  7. Immutable storage setup
  8. Offsite replication
  9. Backup monitoring
  10. Disaster recovery linkage
  11. Ransomware response integration
  12. Chain of custody
Module 12. Security awareness and skills training
Operationalize Control 14 with role-specific, behavior-driven programs that move beyond annual check-the-box training.
12 chapters in this module
  1. Role-based curriculum design
  2. Phishing simulation use
  3. Secure coding training
  4. Third-party onboarding
  5. Metrics that matter
  6. Behavior change tracking
  7. Leadership engagement
  8. Incident reporting culture
  9. New hire integration
  10. Refresher cadence
  11. Curriculum updates
  12. Effectiveness measurement

How this maps to your situation

  • When onboarding a new healthcare system integration
  • Before audit preparation cycles begin
  • During vendor security assessments
  • After a control gap is identified in review

Before vs. after

Before
Relying on consultants or patchwork documentation when addressing CIS Controls in engagements
After
Leading with authoritative, structured knowledge of the CIS Controls framework and applying it confidently across projects

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 2.5 hours per module, designed to be completed alongside active projects over 6, 8 weeks.

How this compares to the alternatives

Unlike generic compliance courses, this program focuses exclusively on the CIS Controls with real-world implementation patterns from healthcare and enterprise IT environments, giving you practical fluency, not just theory.

Frequently asked

Who is this course for?
Senior engagement leaders, technical program managers, and compliance leads who need to apply the CIS Controls confidently in complex, regulated environments.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Is this certification prep?
No. This course builds practical mastery of the CIS Controls framework, not exam readiness. It’s designed for practitioners who lead real projects, not test takers.
$199 one-time. Approximately 2.5 hours per module, designed to be completed alongside active projects over 6, 8 weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours