Skip to main content
Image coming soon

CIS Controls outputs that are accurate defendable and polished the first time

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

CIS Controls outputs that are accurate defendable and polished the first time

Build governance artefacts that stand up under scrutiny, with precision, consistency, and confidence from day one

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Drafts that don’t land. Revisions that pile up. Audit cycles that start over.

The situation this course is for

Teams waste cycles refining compliance outputs because foundational quality isn’t baked in early. Practitioners default to iterative fixes instead of getting it right the first time, costing time, credibility, and capacity.

Who this is for

Senior practitioner leading compliance or risk implementation with direct ownership of control frameworks

Who this is not for

Those seeking introductory overviews or high-level summaries of CIS Controls

What you walk away with

  • Produce CIS Controls documentation that requires no rework before review
  • Build audit-ready control descriptions with sourced rationale and clear logic flow
  • Refine language to be precise, consistent, and stakeholder-appropriate the first time
  • Accelerate sign-off cycles with outputs that anticipate scrutiny
  • Establish reusable templates that maintain quality across teams and projects

The 12 modules (with all 144 chapters)

Module 1. Foundations of quality in control design
Establish what makes a control description accurate, defensible, and polished. Learn the markers of high-quality output and how to avoid common drafting pitfalls.
12 chapters in this module
  1. Defining quality in control documentation
  2. Accuracy vs completeness tradeoffs
  3. Sources of truth for control rationale
  4. Structure of a defensible control statement
  5. Common language pitfalls to avoid
  6. From checklist to narrative flow
  7. Version control without clutter
  8. Balancing brevity and depth
  9. Tone for technical and executive readers
  10. Formatting for consistency
  11. Checklist integration without redundancy
  12. First principles of clean output
Module 2. CIS Control 1 inventory management
Apply quality standards to hardware and software asset management descriptions. Build accurate, audit-ready narratives.
12 chapters in this module
  1. Asset inventory scope definition
  2. Automated discovery integration points
  3. Software license tracking structure
  4. Hardware lifecycle documentation
  5. Virtual and cloud asset mapping
  6. Orphaned system identification method
  7. Decommissioning logs maintenance
  8. Tagging strategy for traceability
  9. Ownership assignment clarity
  10. Integration with service catalog
  11. Versioning asset records
  12. Cross-reference to network maps
Module 3. CIS Control 2 account management
Document identity lifecycle processes with precision and compliance alignment.
12 chapters in this module
  1. Standard account provisioning steps
  2. Role-based access rationale
  3. Emergency account protocols
  4. Service account documentation
  5. Password policy integration
  6. MFA implementation specifics
  7. Access review frequency logic
  8. Orphaned account detection
  9. Delegation controls in place
  10. Privileged account tracking
  11. Temporary access workflows
  12. Audit trail requirements
Module 4. CIS Control 3 continuous vulnerability management
Craft clear descriptions of scanning cadence, tooling, and remediation workflows.
12 chapters in this module
  1. Scan frequency by system tier
  2. Tool selection justification
  3. Severity threshold definitions
  4. Patch deployment windows
  5. Exception handling process
  6. False positive validation steps
  7. Remediation SLA documentation
  8. Risk acceptance workflow
  9. External scan coordination
  10. Internal vs external scope split
  11. Reporting cadence clarity
  12. Integration with ticketing
Module 5. CIS Control 4 controlled use of administrative privileges
Document privileged access governance with defensible structure and logic.
12 chapters in this module
  1. Just-in-time access rationale
  2. Session monitoring specifications
  3. Break glass account rules
  4. Privilege elevation logging
  5. Dual control requirements
  6. Approval workflow design
  7. Time-bound privilege grants
  8. Privileged group membership rules
  9. Session recording policies
  10. Alerting on misuse patterns
  11. Re-certification frequency
  12. Integration with PAM tools
Module 6. CIS Control 5 secure configuration
Build standard configuration baselines that are clear, testable, and enforceable.
12 chapters in this module
  1. Baseline ownership assignment
  2. OS-specific configuration rules
  3. Cloud platform hardening
  4. Automated compliance checks
  5. Drift detection mechanisms
  6. Configuration drift response
  7. Approved deviation process
  8. Golden image management
  9. Firmware update policies
  10. Boot integrity verification
  11. Trusted platform module use
  12. Remote attestation process
Module 7. CIS Control 6 maintenance, monitoring, and analysis of audit logs
Design log management practices with clarity and audit readiness.
12 chapters in this module
  1. Log retention duration rules
  2. Centralized logging architecture
  3. Log source completeness check
  4. Encryption in transit and at rest
  5. Access controls on logs
  6. Log integrity verification
  7. Searchable indexing structure
  8. Retention policy documentation
  9. Audit trail completeness
  10. Correlation across systems
  11. Incident response integration
  12. Log review frequency
Module 8. CIS Control 7 email and web browser protections
Document protections with specificity and operational clarity.
12 chapters in this module
  1. Phishing simulation cadence
  2. Email filtering rule tiers
  3. URL rewriting implementation
  4. Browser extension governance
  5. Pop-up blocker policy
  6. Tab isolation settings
  7. Safe browsing enforcement
  8. Cached data purge frequency
  9. Cookie management rules
  10. Plugin disable standards
  11. Download scanning process
  12. User awareness integration
Module 9. CIS Control 8 malware defenses
Articulate anti-malware strategy with precision and layered logic.
12 chapters in this module
  1. Endpoint detection scope
  2. Signature vs behavior-based tools
  3. Cloud workload protection
  4. Quarantine procedures
  5. Threat intel integration
  6. Sandboxing use cases
  7. File reputation services
  8. Remediation playbooks
  9. Zero-day response design
  10. Patch urgency criteria
  11. Malware type classification
  12. Reporting integration
Module 10. CIS Control 9 data recovery
Document backup and recovery with audit-ready detail and clarity.
12 chapters in this module
  1. Backup frequency by system tier
  2. Encryption of backup media
  3. Retention period rules
  4. Test restore cadence
  5. RTO and RPO documentation
  6. Air-gapped backup strategy
  7. Geographic redundancy
  8. Immutable storage use
  9. Recovery orchestration flow
  10. Access controls on backups
  11. Chain of custody process
  12. Disaster recovery integration
Module 11. CIS Control 10 developer environment hardening
Define secure development practices with structured, repeatable descriptions.
12 chapters in this module
  1. Development environment segmentation
  2. Production data masking
  3. Code repository access
  4. Static analysis integration
  5. Dependency scanning frequency
  6. Sandbox escape prevention
  7. Local admin rights policy
  8. Developer training requirements
  9. IDE security settings
  10. Build pipeline controls
  11. Artifact signing rules
  12. Peer review standards
Module 12. Sustaining quality across the control set
Embed a quality-first mindset across ongoing compliance work.
12 chapters in this module
  1. Quality checklist per control
  2. Peer review workflow
  3. Template reuse strategy
  4. Update cycle integration
  5. Change tracking method
  6. Stakeholder feedback loop
  7. Cross-team consistency
  8. Training for new hires
  9. Audit prep simulation
  10. Lessons learned capture
  11. Continuous improvement cycle
  12. Leadership briefing package

How this maps to your situation

  • When building a new control framework from scratch
  • Before an external audit or certification cycle
  • After a leadership change requiring fresh documentation
  • During a platform migration or cloud transition

Before vs. after

Before
Drafts that loop through revisions, lack stakeholder confidence, and delay approval
After
Clear, structured, and audit-ready outputs produced accurately the first time

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 2.5 hours per module, designed for just-in-time learning during active implementation cycles.

If nothing changes
Continuing to produce iterative drafts risks delays in compliance cycles, undermines credibility with auditors, and drains team capacity on rework instead of strategic improvement.

How this compares to the alternatives

Unlike generic CIS Controls overviews, this course focuses on the quality of output, how to write, structure, and defend control documentation so it passes review the first time, every time.

Frequently asked

Is this course for technical or leadership roles?
It’s designed for practitioners who own or influence control documentation, whether technical implementers or senior leaders shaping compliance strategy.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this with my team?
Yes, the templates and playbooks are built for reuse and scaling across teams.
$199 one-time. Approximately 2.5 hours per module, designed for just-in-time learning during active implementation cycles..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours