Skip to main content
Image coming soon

Direct Sign Off Authority on CIS Controls Implementation Scope

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Direct Sign Off Authority on CIS Controls Implementation Scope

Own the decisions that shape your organization's security posture without escalation

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior security governance practitioner influencing control scoping and implementation boundaries

Who this is not for

Entry level analysts, auditors, or consultants without authority over control scope decisions

What you walk away with

  • Documented authority to define scope of CIS Controls 1 through 20 for technical environments
  • Exemption justification templates accepted without escalation
  • Final determination on multi cloud boundary inclusion for audit coverage
  • Standardized scoping criteria adopted across teams
  • Peer recognition as default decision owner for control applicability

The 12 modules (with all 144 chapters)

Module 1. Control 1 Inventory and Device Management Scope
Define which systems fall under automated inventory tracking and baseline compliance requirements without review.
12 chapters in this module
  1. Asset classification tiers
  2. Discovery scope boundaries
  3. Exclusion criteria for niche systems
  4. Dynamic tagging rules
  5. Legacy system handling
  6. Cloud workload inclusion
  7. Container fleet coverage
  8. Serverless function scope
  9. Exemption documentation
  10. Boundary change requests
  11. Stakeholder alignment checklist
  12. Final sign off workflow
Module 2. Control 2 Secure Configuration for Hardware and Software
Set secure configuration baselines for end user devices and servers across hybrid environments.
12 chapters in this module
  1. OS hardening thresholds
  2. Approved configuration drift
  3. Automated enforcement tools
  4. Application whitelisting scope
  5. Registry setting standards
  6. Firmware update cadence
  7. Certificate lifecycle rules
  8. Browser policy enforcement
  9. Mobile device configuration
  10. Virtual desktop boundaries
  11. Patch compliance tolerance
  12. Configuration rollback criteria
Module 3. Control 3 Continuous Vulnerability Management
Own vulnerability scan frequency, severity thresholds, and remediation timelines across environments.
12 chapters in this module
  1. Scan schedule determination
  2. Critical severity definition
  3. False positive review process
  4. Risk accepted documentation
  5. Third party scan validation
  6. Cloud native scanner selection
  7. Remediation SLA setting
  8. Emergency patch criteria
  9. Zero day response protocol
  10. Vulnerability scoring model
  11. Exposure window approval
  12. Penetration test integration
Module 4. Control 4 Controlled Use of Administrative Privileges
Define rules for admin access provisioning and session logging across platforms.
12 chapters in this module
  1. Privileged account tiers
  2. Just in time access standards
  3. Break glass procedure
  4. Session recording requirement
  5. Password rotation rules
  6. PAM tool scope
  7. Emergency override criteria
  8. Remote admin conditions
  9. Third party access policy
  10. Privilege creep monitoring
  11. Access review frequency
  12. Escalation bypass documentation
Module 5. Control 5 Secure Configuration for Network Devices
Set firewall rule standards, segmentation policies, and network change control thresholds.
12 chapters in this module
  1. Firewall rule lifecycle
  2. Default deny implementation
  3. Micro segmentation criteria
  4. Network zone definitions
  5. Remote access conditions
  6. DMZ configuration rules
  7. Wireless access policy
  8. IoT device network placement
  9. Change freeze periods
  10. Emergency bypass logging
  11. VPN access standards
  12. Network monitoring depth
Module 6. Control 6 Maintenance Technical Vulnerabilities
Own patch management cadence and exception criteria for critical systems.
12 chapters in this module
  1. Critical system identification
  2. Patch testing window
  3. Emergency rollout protocol
  4. Vendor patch validation
  5. Offline system handling
  6. Legacy system exemption
  7. Automated deployment scope
  8. Rollback procedure
  9. Third party dependency check
  10. Downtime window approval
  11. Zero day patch integration
  12. Patch compliance reporting
Module 7. Control 7 Limitation and Control of Network Ports
Define which ports are open by default and approval process for exceptions.
12 chapters in this module
  1. Default deny port list
  2. Service port justification
  3. Dynamic port allocation
  4. Firewall rule exceptions
  5. Port scanning frequency
  6. Encrypted tunnel policy
  7. Remote desktop port rules
  8. Database port standards
  9. Cloud load balancer ports
  10. Application port documentation
  11. Port change request workflow
  12. Port closure enforcement
Module 8. Control 8 Boundary Defense Configuration
Set standards for perimeter defense layers and traffic inspection depth.
12 chapters in this module
  1. Perimeter segmentation
  2. Traffic inspection depth
  3. IPS rule thresholds
  4. DDoS protection baseline
  5. Geofencing criteria
  6. Bot traffic filtering
  7. Email gateway rules
  8. Web proxy configuration
  9. Content filtering standards
  10. Outbound traffic monitoring
  11. Encrypted traffic inspection
  12. Threat intel integration
Module 9. Control 9 Data Protection Mechanisms
Define encryption standards, data classification, and retention periods.
12 chapters in this module
  1. Data classification tiers
  2. Encryption at rest standard
  3. Encryption in transit rules
  4. Key management policy
  5. Data retention periods
  6. DLP scope definition
  7. Masking criteria
  8. Tokenization implementation
  9. Backup encryption
  10. Archive access policy
  11. Data transfer controls
  12. Declassification review
Module 10. Control 10 Data Loss Prevention
Own detection and response rules for unauthorized data transfers.
12 chapters in this module
  1. Policy trigger thresholds
  2. Sensitive data detection
  3. USB control enforcement
  4. Cloud upload monitoring
  5. Email attachment rules
  6. Print monitoring scope
  7. Screen capture policy
  8. Data exfiltration patterns
  9. Incident response protocol
  10. False positive review
  11. Whistleblower channel access
  12. Remediation workflow
Module 11. Control 11 Secure Authentication
Set MFA enforcement, password policy, and identity provider integration rules.
12 chapters in this module
  1. MFA enforcement levels
  2. Password complexity rules
  3. Account lockout policy
  4. SSO integration scope
  5. FIDO key adoption
  6. Biometric authentication
  7. Session timeout rules
  8. Risk based authentication
  9. Identity provider standards
  10. Directory sync frequency
  11. Account provisioning
  12. Deactivation workflow
Module 12. Control 12 Boundary Monitoring and Attack Detection
Define logging standards, SIEM rules, and incident escalation thresholds.
12 chapters in this module
  1. Log retention period
  2. Event correlation rules
  3. SIEM rule tuning
  4. Threat detection thresholds
  5. Incident classification
  6. Escalation path definition
  7. Forensic data collection
  8. Automated response actions
  9. Root cause documentation
  10. Threat hunting frequency
  11. Threat intel integration
  12. Incident report template

How this maps to your situation

  • New cloud environment rollout
  • Annual internal audit cycle
  • Third party risk assessment
  • Security control refresh initiative

Before vs. after

Before
Waiting for leadership approval on control boundaries and exemption reasoning
After
Your documented scoping decisions become the standard without escalation

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for completion within 6 weeks

If nothing changes
Continued reliance on senior review slows response to evolving threats and reduces your influence on security direction

How this compares to the alternatives

Unlike generic compliance courses, this program delivers documented decision rights on CIS Controls scope, turning governance into a source of authority rather than a bottleneck.

Frequently asked

How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
What makes this different from other security frameworks training?
It focuses on documented authority over control scoping decisions, not just knowledge of controls.
Will I receive templates?
Yes, every module includes downloadable templates and real world examples.
$199 one-time. Approximately 3 hours per module, designed for completion within 6 weeks.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours