What is the First 90 Days course about?
A step-by-step implementation guide to building your first 90-day security foundation aligned with healthcare compliance. Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
Security leaders spend weeks assembling evidence, chasing control ownership, and reworking documentation under audit pressure. The problem isn’t knowledge, it’s implementation structure. Without a repeatable foundation, even experienced CISOs burn cycles reinventing the wheel every quarter.
Who is the First 90 Days course for?
Healthcare CISOs and senior IT leaders with CISSP or CCSP credentials, responsible for standing up or refining security programs in regulated environments.
What do you take away from the First 90 Days course?
Ship a documented, assignee-mapped security foundation in 90 days Reduce recurring compliance preparation time by 80% Align CISSP domains directly to HIPAA, NIST, and internal audit requirements Eliminate last-minute evidence chasing with pre-built ownership templates Turn first-time control implementation into a repeatable pattern.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: 90 minutes per week for 12 weeks, with optional deep dives for complex modules.
How does this compare to the alternatives?
Consulting firms charge $25K+ for similar foundation builds; generic CISSP training lacks healthcare implementation detail. This course delivers the exact structure, templates, and sequencing needed , at 1% of the cost.
What does the First 90 Days cover on frequently asked?
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Closely related courses: First 90 Days as CISO in Pediatric Healthcare, First 90 Days Evaluation and First 90 Days Evaluation Kit, First 90 Days Toolkit, First 100 Days Toolkit.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building a Security Foundation Aligned to Healthcare Compliance
A step-by-step implementation guide to building your first 90-day security foundation aligned with healthcare compliance.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
Security leaders spend weeks assembling evidence, chasing control ownership, and reworking documentation under audit pressure. The problem isn’t knowledge, it’s implementation structure. Without a repeatable foundation, even experienced CISOs burn cycles reinventing the wheel every quarter.
Who this is for
Healthcare CISOs and senior IT leaders with CISSP or CCSP credentials, responsible for standing up or refining security programs in regulated environments.
Who this is not for
Entry-level analysts, consultants selling compliance services, or leaders in non-regulated sectors without healthcare compliance exposure.
What you walk away with
- Ship a documented, assignee-mapped security foundation in 90 days
- Reduce recurring compliance preparation time by 80%
- Align CISSP domains directly to HIPAA, NIST, and internal audit requirements
- Eliminate last-minute evidence chasing with pre-built ownership templates
- Turn first-time control implementation into a repeatable pattern
The 12 modules (with all 144 chapters)
- Identifying regulated data types in clinical and administrative systems
- Mapping patient data pathways across cloud and on-prem environments
- Defining system boundaries for audit scoping
- Classifying third-party vendors with data access
- Documenting scope justification for internal reviewers
- Aligning scope with HIPAA Security Rule requirements
- Using CISSP Domain 2 to inform asset classification
- Creating a visual data flow diagram for stakeholder review
- Establishing scope change control for future systems
- Integrating scope documentation into annual review cycles
- Avoiding common scope creep pitfalls in hybrid environments
- Template: Healthcare system boundary statement
- Drafting a minimum-viable acceptable use policy for healthcare staff
- Defining role-based access principles for clinical workflows
- Establishing baseline encryption standards for data at rest and in transit
- Creating a bring-your-own-device policy for clinical settings
- Documenting incident classification levels for medical systems
- Aligning policy language with NIST CSF categories
- Mapping CISSP Domain 5 controls to policy requirements
- Setting policy review and update cadence
- Gaining leadership sign-off with risk-informed rationale
- Distributing policies through secure, auditable channels
- Tracking employee attestation with automated reminders
- Template: Healthcare policy implementation checklist
- Inventorying user roles across clinical, billing, and administrative teams
- Defining least privilege access for EHR and pharmacy systems
- Mapping access rights to job functions, not departments
- Integrating IAM with HR onboarding and offboarding
- Setting quarterly access review cycles with department leads
- Documenting exceptions with time-bound approvals
- Using CISSP Domain 5 to structure access control models
- Aligning access logs with audit trail requirements
- Implementing just-in-time access for admin functions
- Monitoring for anomalous access patterns in clinical systems
- Creating a compensating control process for legacy applications
- Template: Access review tracking workbook
- Automating discovery of clinical devices and endpoints
- Classifying devices by criticality and data access level
- Defining secure configuration baselines for Windows and macOS
- Standardizing mobile device settings for nursing units
- Maintaining an up-to-date hardware and software inventory
- Integrating configuration management with patch cycles
- Using CISSP Domain 7 to inform device security practices
- Documenting configuration exceptions with risk justification
- Creating a process for decommissioning retired systems
- Aligning inventory practices with HIPAA Technical Safeguards
- Generating evidence reports for internal auditors
- Template: Healthcare device inventory register
- Scheduling regular vulnerability scans across clinical networks
- Prioritizing findings based on exploitability and data exposure
- Establishing SLAs for critical and high-severity patches
- Coordinating patching windows with clinical operations
- Documenting risk acceptance decisions with executive sign-off
- Integrating scanner results into ticketing systems
- Using CISSP Domain 7 to structure vulnerability response
- Validating patch success with follow-up scanning
- Managing third-party patch dependencies for medical devices
- Reporting remediation status to leadership weekly
- Creating an emergency patch process for active threats
- Template: Vulnerability remediation tracking log
- Defining incident types relevant to healthcare operations
- Establishing escalation paths for ransomware and data exfiltration
- Creating roles and contact lists for incident response team
- Documenting HIPAA breach notification timelines and procedures
- Developing communication templates for patients and regulators
- Conducting tabletop exercises with clinical leadership
- Using CISSP Domain 6 to structure response workflows
- Integrating EHR downtime procedures into incident plan
- Logging and preserving evidence for forensic review
- Reviewing and updating plan after each incident
- Aligning response activities with NIST SP 800-61
- Template: Healthcare incident response playbook
- Identifying mission-critical applications in patient care
- Defining RTO and RPO for EHR and laboratory systems
- Documenting backup schedules and retention periods
- Testing failover procedures for on-prem and cloud systems
- Establishing alternate care sites for extended outages
- Using CISSP Domain 8 to structure continuity planning
- Aligning BCP with HIPAA Contingency Rule requirements
- Creating a communication plan for staff during outages
- Documenting lessons from past incidents and drills
- Reviewing insurance coverage for cyber events
- Integrating DR testing into annual compliance calendar
- Template: Healthcare BCP test results report
- Creating a vendor inventory with data access classification
- Conducting security assessments using SIG Lite or equivalent
- Requiring evidence of HIPAA BAAs from all relevant vendors
- Monitoring vendor compliance status throughout contract life
- Defining minimum security requirements for cloud providers
- Using CISSP Domain 5 to inform vendor control expectations
- Establishing a process for high-risk vendor onboarding
- Tracking vendor audit reports and renewal dates
- Responding to vendor security incidents with patient data impact
- Aligning third-party reviews with organizational risk appetite
- Creating a vendor offboarding checklist
- Template: Third-party risk assessment scorecard
- Designing training content for clinical, billing, and admin staff
- Scheduling annual and role-based training modules
- Creating phishing simulations with healthcare-themed lures
- Tracking completion rates and follow-up for non-compliance
- Using CISSP Domain 8 to inform security culture development
- Measuring training effectiveness with pre- and post-tests
- Incorporating new hire training into onboarding workflow
- Documenting training program for auditor review
- Updating content based on recent incidents and threats
- Engaging department champions to reinforce messaging
- Aligning training topics with current regulatory expectations
- Template: Security awareness completion dashboard
- Mapping controls to HIPAA, NIST, and internal audit requirements
- Creating a centralized evidence repository with access controls
- Documenting control operation with screenshots and logs
- Assigning evidence owners for each control
- Using CISSP Domain 10 to structure audit readiness
- Scheduling quarterly evidence reviews to avoid last-minute crunch
- Generating control status reports for leadership
- Responding to auditor inquiries with source-backed evidence
- Maintaining version history for policy and procedure documents
- Preparing walkthroughs with process owners
- Tracking open issues and remediation plans
- Template: Audit evidence tracker with ownership assignment
- Defining KPIs for patching, access reviews, and incident response
- Generating monthly security dashboards for leadership
- Conducting quarterly control effectiveness reviews
- Using CISSP Domain 10 to inform continuous improvement
- Integrating feedback from audits and incidents into updates
- Benchmarking performance against peer healthcare organizations
- Identifying emerging threats to clinical systems
- Adjusting security program focus based on risk trends
- Documenting changes to controls and rationale
- Aligning review cycles with fiscal and audit calendars
- Engaging external assessors for objective feedback
- Template: Security program review meeting agenda
- Transferring control ownership to permanent roles
- Embedding security tasks into existing job descriptions
- Establishing a security committee with cross-functional leads
- Using CISSP domains as a reference for ongoing decisions
- Integrating security reviews into project lifecycle gates
- Creating a backlog of incremental improvements
- Planning for annual policy and control refreshes
- Documenting the foundation for new team members
- Measuring program maturity over time
- Aligning security roadmap with organizational strategy
- Celebrating milestones to reinforce team engagement
- Template: 90-day handover and sustainment plan
How this maps to your situation
- First-time CISO in healthcare
- IT leader expanding security oversight
- Security program rebuild post-audit
- Cloud migration with compliance implications
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes per week for 12 weeks, with optional deep dives for complex modules.
How this compares to the alternatives
Consulting firms charge $25K+ for similar foundation builds; generic CISSP training lacks healthcare implementation detail. This course delivers the exact structure, templates, and sequencing needed , at 1% of the cost.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.