A tailored course, built for your situation
CIS Controls outputs that are accurate defendable and polished the first time
Build governance artefacts that stand up under scrutiny, with precision, consistency, and confidence from day one
The situation this course is for
Teams waste cycles refining compliance outputs because foundational quality isn’t baked in early. Practitioners default to iterative fixes instead of getting it right the first time, costing time, credibility, and capacity.
Who this is for
Senior practitioner leading compliance or risk implementation with direct ownership of control frameworks
Who this is not for
Those seeking introductory overviews or high-level summaries of CIS Controls
What you walk away with
- Produce CIS Controls documentation that requires no rework before review
- Build audit-ready control descriptions with sourced rationale and clear logic flow
- Refine language to be precise, consistent, and stakeholder-appropriate the first time
- Accelerate sign-off cycles with outputs that anticipate scrutiny
- Establish reusable templates that maintain quality across teams and projects
The 12 modules (with all 144 chapters)
- Defining quality in control documentation
- Accuracy vs completeness tradeoffs
- Sources of truth for control rationale
- Structure of a defensible control statement
- Common language pitfalls to avoid
- From checklist to narrative flow
- Version control without clutter
- Balancing brevity and depth
- Tone for technical and executive readers
- Formatting for consistency
- Checklist integration without redundancy
- First principles of clean output
- Asset inventory scope definition
- Automated discovery integration points
- Software license tracking structure
- Hardware lifecycle documentation
- Virtual and cloud asset mapping
- Orphaned system identification method
- Decommissioning logs maintenance
- Tagging strategy for traceability
- Ownership assignment clarity
- Integration with service catalog
- Versioning asset records
- Cross-reference to network maps
- Standard account provisioning steps
- Role-based access rationale
- Emergency account protocols
- Service account documentation
- Password policy integration
- MFA implementation specifics
- Access review frequency logic
- Orphaned account detection
- Delegation controls in place
- Privileged account tracking
- Temporary access workflows
- Audit trail requirements
- Scan frequency by system tier
- Tool selection justification
- Severity threshold definitions
- Patch deployment windows
- Exception handling process
- False positive validation steps
- Remediation SLA documentation
- Risk acceptance workflow
- External scan coordination
- Internal vs external scope split
- Reporting cadence clarity
- Integration with ticketing
- Just-in-time access rationale
- Session monitoring specifications
- Break glass account rules
- Privilege elevation logging
- Dual control requirements
- Approval workflow design
- Time-bound privilege grants
- Privileged group membership rules
- Session recording policies
- Alerting on misuse patterns
- Re-certification frequency
- Integration with PAM tools
- Baseline ownership assignment
- OS-specific configuration rules
- Cloud platform hardening
- Automated compliance checks
- Drift detection mechanisms
- Configuration drift response
- Approved deviation process
- Golden image management
- Firmware update policies
- Boot integrity verification
- Trusted platform module use
- Remote attestation process
- Log retention duration rules
- Centralized logging architecture
- Log source completeness check
- Encryption in transit and at rest
- Access controls on logs
- Log integrity verification
- Searchable indexing structure
- Retention policy documentation
- Audit trail completeness
- Correlation across systems
- Incident response integration
- Log review frequency
- Phishing simulation cadence
- Email filtering rule tiers
- URL rewriting implementation
- Browser extension governance
- Pop-up blocker policy
- Tab isolation settings
- Safe browsing enforcement
- Cached data purge frequency
- Cookie management rules
- Plugin disable standards
- Download scanning process
- User awareness integration
- Endpoint detection scope
- Signature vs behavior-based tools
- Cloud workload protection
- Quarantine procedures
- Threat intel integration
- Sandboxing use cases
- File reputation services
- Remediation playbooks
- Zero-day response design
- Patch urgency criteria
- Malware type classification
- Reporting integration
- Backup frequency by system tier
- Encryption of backup media
- Retention period rules
- Test restore cadence
- RTO and RPO documentation
- Air-gapped backup strategy
- Geographic redundancy
- Immutable storage use
- Recovery orchestration flow
- Access controls on backups
- Chain of custody process
- Disaster recovery integration
- Development environment segmentation
- Production data masking
- Code repository access
- Static analysis integration
- Dependency scanning frequency
- Sandbox escape prevention
- Local admin rights policy
- Developer training requirements
- IDE security settings
- Build pipeline controls
- Artifact signing rules
- Peer review standards
- Quality checklist per control
- Peer review workflow
- Template reuse strategy
- Update cycle integration
- Change tracking method
- Stakeholder feedback loop
- Cross-team consistency
- Training for new hires
- Audit prep simulation
- Lessons learned capture
- Continuous improvement cycle
- Leadership briefing package
How this maps to your situation
- When building a new control framework from scratch
- Before an external audit or certification cycle
- After a leadership change requiring fresh documentation
- During a platform migration or cloud transition
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 2.5 hours per module, designed for just-in-time learning during active implementation cycles.
How this compares to the alternatives
Unlike generic CIS Controls overviews, this course focuses on the quality of output, how to write, structure, and defend control documentation so it passes review the first time, every time.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.