Skip to main content
Image coming soon

SEC1104 Mastering CIS Controls for Operations Managers in Commercial Real Estate

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for Operations Managers in Commercial Real Estate

Build defensible security practices with specific examples, sources, and reasoning frameworks that hold up under peer review.

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Operations leader in commercial real estate managing security-adjacent infrastructure and vendor coordination, with influence across facilities, IT, and compliance teams.

Who this is not for

Entry-level IT staff, auditors focused solely on documentation, or executives who don't engage with control-level details.

What you walk away with

  • Articulate the 'why' behind each CIS Control with reference to authoritative sources and real-world breaches it prevents
  • Map CIS Controls to existing physical and digital infrastructure decisions at Empire State Realty Trust
  • Defend control selections during peer reviews using specific examples from implementation tiers and benchmarked organizations
  • Reference exact sub-controls when challenged on scope, cost, or priority
  • Produce justification narratives that survive leadership changes and vendor turnover

The 12 modules (with all 144 chapters)

Module 1. Understanding CIS Controls v8 Structure
Break down the framework into prioritized actions, adoption levels, and implementation groups. Learn how the top 5 controls prevent 80% of known attacks.
12 chapters in this module
  1. What are CIS Controls
  2. The 18 Control Categories
  3. Implementation Groups Defined
  4. CIS vs NIST CSF Comparison
  5. Control Prioritization Logic
  6. How IG1 Differs from IG2
  7. The Role of Safeguards
  8. Mapping to MITRE ATT&CK
  9. Using the CIS Benchmark Tool
  10. Accessing the CIS Community
  11. Version History Overview
  12. Integrating with Existing Audits
Module 2. Inventory and Control of Hardware Assets
Establish authoritative asset registers using automated discovery methods and policy enforcement points.
12 chapters in this module
  1. Defining Authorized Devices
  2. Active Discovery Tools
  3. Network Access Control Basics
  4. Asset Tagging Standards
  5. Decommissioning Processes
  6. Mobile Device Inclusion
  7. Virtual Machine Tracking
  8. Cloud Instance Inventory
  9. Hardware Lifecycle Policy
  10. Ownership Accountability
  11. Automated Alert Thresholds
  12. Integration with CMDB
Module 3. Inventory and Control of Software Assets
Maintain accurate software lists and enforce approved inventories to reduce attack surface.
12 chapters in this module
  1. Software Approval Process
  2. Whitelist vs Blacklist Models
  3. Application Discovery Tools
  4. License Compliance Tracking
  5. End-of-Life Software Policy
  6. Shadow IT Detection
  7. SaaS Inventory Management
  8. Developer Tool Oversight
  9. Package Repository Control
  10. Software Removal Procedures
  11. Change Request Workflows
  12. Reporting to Audit Teams
Module 4. Data Protection
Classify and protect sensitive data across systems and personnel handling.
12 chapters in this module
  1. Defining Data Sensitivity Levels
  2. Data Flow Mapping
  3. Encryption at Rest and Transit
  4. Access Control Reviews
  5. Data Retention Policies
  6. DLP System Integration
  7. Third-Party Data Sharing
  8. Physical Document Security
  9. Secure Disposal Methods
  10. Breach Notification Triggers
  11. Regulatory Alignment Mapping
  12. Audit Trail Retention
Module 5. Secure Configuration for Hardware and Software
Implement secure baselines across endpoints, servers, and network devices.
12 chapters in this module
  1. Baseline Configuration Standards
  2. CIS Benchmarks Usage
  3. Golden Image Creation
  4. Automated Compliance Scans
  5. Patch Management Cadence
  6. Firmware Update Policies
  7. Configuration Drift Detection
  8. Remote Work Device Settings
  9. Secure Boot Requirements
  10. Just-in-Time Access Models
  11. User Privilege Minimization
  12. Change Approval Workflows
Module 6. Account Management
Ensure proper provisioning, deprovisioning, and privilege assignment.
12 chapters in this module
  1. Identity Lifecycle Process
  2. Role-Based Access Control
  3. Least Privilege Enforcement
  4. Service Account Management
  5. Multi-Factor Authentication
  6. Privileged Access Workstations
  7. Password Policy Standards
  8. Shared Account Controls
  9. Emergency Access Procedures
  10. Audit Logging Requirements
  11. Access Review Frequency
  12. Integration with HR Systems
Module 7. Access Control Management
Enforce segmentation and permissions across systems and roles.
12 chapters in this module
  1. Network Segmentation Design
  2. Zero Trust Principles
  3. Firewall Rule Management
  4. VLAN Configuration
  5. VPN Access Policies
  6. Remote Access Controls
  7. Database Access Restrictions
  8. Physical Access Integration
  9. Time-Based Access Rules
  10. Escalated Access Logging
  11. Role Changes and Transfers
  12. Automated Access Reviews
Module 8. Continuous Vulnerability Management
Detect, prioritize, and remediate vulnerabilities systematically.
12 chapters in this module
  1. Vulnerability Scanning Frequency
  2. CVSS Scoring Basics
  3. Patch Prioritization Framework
  4. Critical vs High Thresholds
  5. Automated Remediation Tools
  6. False Positive Handling
  7. Third-Party Risk Consideration
  8. Cloud-Specific Scans
  9. Reporting to Leadership
  10. Integration with Ticketing
  11. Historical Trend Analysis
  12. Vendor Coordination Process
Module 9. Audit Log Management
Collect, protect, and analyze logs to support investigations.
12 chapters in this module
  1. Log Collection Scope
  2. Centralized Logging
  3. Retention Requirements
  4. Log Integrity Protection
  5. SIEM Integration
  6. Search Query Examples
  7. Incident Triage Process
  8. Forensic Readiness
  9. User Behavior Baselines
  10. Anomaly Detection Rules
  11. Log Storage Security
  12. Cross-System Correlation
Module 10. Email and Web Browser Protections
Reduce exposure from common internet-facing applications.
12 chapters in this module
  1. Web Filtering Setup
  2. Phishing Simulation
  3. Email Gateway Controls
  4. URL Rewrite Rules
  5. Attachment Sanitization
  6. JavaScript Controls
  7. Browser Extension Policy
  8. Secure Browsing Standards
  9. User Training Integration
  10. Click-Through Monitoring
  11. Quarantine Workflow
  12. Threat Intelligence Feeds
Module 11. Malware Defenses
Deploy layered protection against malicious code.
12 chapters in this module
  1. Endpoint Detection Strategy
  2. Antivirus vs EDR
  3. Ransomware Prevention
  4. Execution Control
  5. Sandboxing Uses
  6. Indicators of Compromise
  7. Incident Containment
  8. Network-Based Detection
  9. Hash Blacklisting
  10. Behavioral Monitoring
  11. Automated Response
  12. Recovery Playbooks
Module 12. Defensible Security Decision-Making
Justify control choices using sources, precedents, and logical reasoning patterns.
12 chapters in this module
  1. The 'Why' Behind Controls
  2. Using CIS Implementation Guides
  3. Benchmarking Against Peers
  4. Documenting Rationale
  5. Responding to Pushback
  6. Tailoring Controls Safely
  7. Cost vs Risk Tradeoffs
  8. Reporting to Non-Technical Stakeholders
  9. Maintaining Consistency
  10. Revisiting Decisions
  11. Sharing Knowledge
  12. Building Organizational Memory

How this maps to your situation

  • Onboarding new security vendors
  • Responding to internal audit findings
  • Updating facility access policies
  • Justifying budget for cybersecurity tools

Before vs. after

Before
Decisions questioned due to lack of documented rationale or external support
After
Confidently walk through the reasoning behind any control choice using verbatim frameworks and real-world examples

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for completion over 6-8 weeks with real-world application between sections.

How this compares to the alternatives

Unlike generic cybersecurity courses, this program focuses specifically on the CIS Controls framework and builds practical, defensible decision-making, grounded in real-world infrastructure environments like yours.

Frequently asked

Who is this course for?
Operations Managers and infrastructure leads in commercial real estate and facilities management who influence cybersecurity decisions but may lack formal security training.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I apply this to my current role?
Yes, each module includes templates and examples tailored to real estate operations, including vendor coordination, physical access systems, and building technology integrations.
$199 one-time. Approximately 3 hours per module, designed for completion over 6-8 weeks with real-world application between sections..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours