A tailored course, built for your situation
Mastering CIS Controls for Operations Managers in Commercial Real Estate
Build defensible security practices with specific examples, sources, and reasoning frameworks that hold up under peer review.
Who this is for
Operations leader in commercial real estate managing security-adjacent infrastructure and vendor coordination, with influence across facilities, IT, and compliance teams.
Who this is not for
Entry-level IT staff, auditors focused solely on documentation, or executives who don't engage with control-level details.
What you walk away with
- Articulate the 'why' behind each CIS Control with reference to authoritative sources and real-world breaches it prevents
- Map CIS Controls to existing physical and digital infrastructure decisions at Empire State Realty Trust
- Defend control selections during peer reviews using specific examples from implementation tiers and benchmarked organizations
- Reference exact sub-controls when challenged on scope, cost, or priority
- Produce justification narratives that survive leadership changes and vendor turnover
The 12 modules (with all 144 chapters)
- What are CIS Controls
- The 18 Control Categories
- Implementation Groups Defined
- CIS vs NIST CSF Comparison
- Control Prioritization Logic
- How IG1 Differs from IG2
- The Role of Safeguards
- Mapping to MITRE ATT&CK
- Using the CIS Benchmark Tool
- Accessing the CIS Community
- Version History Overview
- Integrating with Existing Audits
- Defining Authorized Devices
- Active Discovery Tools
- Network Access Control Basics
- Asset Tagging Standards
- Decommissioning Processes
- Mobile Device Inclusion
- Virtual Machine Tracking
- Cloud Instance Inventory
- Hardware Lifecycle Policy
- Ownership Accountability
- Automated Alert Thresholds
- Integration with CMDB
- Software Approval Process
- Whitelist vs Blacklist Models
- Application Discovery Tools
- License Compliance Tracking
- End-of-Life Software Policy
- Shadow IT Detection
- SaaS Inventory Management
- Developer Tool Oversight
- Package Repository Control
- Software Removal Procedures
- Change Request Workflows
- Reporting to Audit Teams
- Defining Data Sensitivity Levels
- Data Flow Mapping
- Encryption at Rest and Transit
- Access Control Reviews
- Data Retention Policies
- DLP System Integration
- Third-Party Data Sharing
- Physical Document Security
- Secure Disposal Methods
- Breach Notification Triggers
- Regulatory Alignment Mapping
- Audit Trail Retention
- Baseline Configuration Standards
- CIS Benchmarks Usage
- Golden Image Creation
- Automated Compliance Scans
- Patch Management Cadence
- Firmware Update Policies
- Configuration Drift Detection
- Remote Work Device Settings
- Secure Boot Requirements
- Just-in-Time Access Models
- User Privilege Minimization
- Change Approval Workflows
- Identity Lifecycle Process
- Role-Based Access Control
- Least Privilege Enforcement
- Service Account Management
- Multi-Factor Authentication
- Privileged Access Workstations
- Password Policy Standards
- Shared Account Controls
- Emergency Access Procedures
- Audit Logging Requirements
- Access Review Frequency
- Integration with HR Systems
- Network Segmentation Design
- Zero Trust Principles
- Firewall Rule Management
- VLAN Configuration
- VPN Access Policies
- Remote Access Controls
- Database Access Restrictions
- Physical Access Integration
- Time-Based Access Rules
- Escalated Access Logging
- Role Changes and Transfers
- Automated Access Reviews
- Vulnerability Scanning Frequency
- CVSS Scoring Basics
- Patch Prioritization Framework
- Critical vs High Thresholds
- Automated Remediation Tools
- False Positive Handling
- Third-Party Risk Consideration
- Cloud-Specific Scans
- Reporting to Leadership
- Integration with Ticketing
- Historical Trend Analysis
- Vendor Coordination Process
- Log Collection Scope
- Centralized Logging
- Retention Requirements
- Log Integrity Protection
- SIEM Integration
- Search Query Examples
- Incident Triage Process
- Forensic Readiness
- User Behavior Baselines
- Anomaly Detection Rules
- Log Storage Security
- Cross-System Correlation
- Web Filtering Setup
- Phishing Simulation
- Email Gateway Controls
- URL Rewrite Rules
- Attachment Sanitization
- JavaScript Controls
- Browser Extension Policy
- Secure Browsing Standards
- User Training Integration
- Click-Through Monitoring
- Quarantine Workflow
- Threat Intelligence Feeds
- Endpoint Detection Strategy
- Antivirus vs EDR
- Ransomware Prevention
- Execution Control
- Sandboxing Uses
- Indicators of Compromise
- Incident Containment
- Network-Based Detection
- Hash Blacklisting
- Behavioral Monitoring
- Automated Response
- Recovery Playbooks
- The 'Why' Behind Controls
- Using CIS Implementation Guides
- Benchmarking Against Peers
- Documenting Rationale
- Responding to Pushback
- Tailoring Controls Safely
- Cost vs Risk Tradeoffs
- Reporting to Non-Technical Stakeholders
- Maintaining Consistency
- Revisiting Decisions
- Sharing Knowledge
- Building Organizational Memory
How this maps to your situation
- Onboarding new security vendors
- Responding to internal audit findings
- Updating facility access policies
- Justifying budget for cybersecurity tools
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed for completion over 6-8 weeks with real-world application between sections.
How this compares to the alternatives
Unlike generic cybersecurity courses, this program focuses specifically on the CIS Controls framework and builds practical, defensible decision-making, grounded in real-world infrastructure environments like yours.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.