Skip to main content
Image coming soon

SEC4801 First 90 Days: Building a Security Governance Foundation in Financial Services

$198.00
Adding to cart… The item has been added

What is the First 90 Days course about?

A step-by-step guide to building a security governance foundation in your first 90 days Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

What situation is the First 90 Days for?

New security leaders in financial services often spend their first 60-90 days assembling disjointed control evidence, chasing stakeholder inputs, and revising documentation under time pressure, especially when audit or regulator cycles converge. This delays strategic momentum and exposes early gaps in authority and traceability.

Who is the First 90 Days course for?

Head of Information Security in financial services, often holding CISA, CISSP, or CCSP credentials, responsible for standing up or refining security governance in a regulated environment within the first three months of role start or structural change.

What do you take away from the First 90 Days course?

Launch a fully traceable security governance framework within 90 days Produce regulator-ready control documentation that passes internal review on first submission Map stakeholder responsibilities and escalation paths before the first audit cycle Reduce rework in evidence collection by implementing pre-validated templates Establish clear ownership of control assertions and monitoring cycles from day one.

How does this map to your situation?

Onboarding as new Head of Information Security Responding to audit findings requiring governance overhaul Preparing for regulator examination under DORA-type rules Aligning security controls with executive risk appetite.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the First 90 Days cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 90 minutes per week over 12 weeks, or 20 hours total, with flexible pacing.

How does this compare to the alternatives?

Unlike generic compliance courses, this program delivers a structured, week-by-week implementation plan tailored to financial services, with real-world templates and CISA-specific mappings used by practitioners in regulated environments.

Closely related courses: First 90 Days Evaluation and First 90 Days Evaluation Kit, First 90 Days Toolkit, First 100 Days Toolkit, First 90 Days Evaluation Toolkit.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

First 90 Days: Building a Security Governance Foundation in Financial Services

A step-by-step guide to building a security governance foundation in your first 90 days

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Governance playbooks that get bounced back during audit prep or regulator cycles

The situation this course is for

New security leaders in financial services often spend their first 60-90 days assembling disjointed control evidence, chasing stakeholder inputs, and revising documentation under time pressure, especially when audit or regulator cycles converge. This delays strategic momentum and exposes early gaps in authority and traceability.

Who this is for

Head of Information Security in financial services, often holding CISA, CISSP, or CCSP credentials, responsible for standing up or refining security governance in a regulated environment within the first three months of role start or structural change

Who this is not for

Security analysts, junior auditors, or IT support staff not responsible for end-to-end governance design or control ownership

What you walk away with

  • Launch a fully traceable security governance framework within 90 days
  • Produce regulator-ready control documentation that passes internal review on first submission
  • Map stakeholder responsibilities and escalation paths before the first audit cycle
  • Reduce rework in evidence collection by implementing pre-validated templates
  • Establish clear ownership of control assertions and monitoring cycles from day one

The 12 modules (with all 144 chapters)

Module 1. Week 1: Assessing Current State and Regulatory Baseline
Establish the starting point of your governance environment and align with applicable mandates.
12 chapters in this module
  1. Reviewing existing control inventories and policy documentation
  2. Mapping current compliance obligations to financial services regulations
  3. Identifying recent audit findings or control exceptions
  4. Determining scope of security governance ownership
  5. Engaging with legal and compliance for regulatory context
  6. Documenting jurisdictional and cross-border data handling rules
  7. Assessing alignment with CISA control objectives
  8. Cataloging known third-party vendor risks
  9. Identifying key internal stakeholders and decision owners
  10. Setting up governance documentation repository
  11. Defining thresholds for risk acceptance and escalation
  12. Creating the initial governance project charter
Module 2. Week 2: Defining Governance Structure and Roles
Design the operating model and accountability framework for security governance.
12 chapters in this module
  1. Establishing RACI matrix for control ownership
  2. Defining roles: control owner, reviewer, operator, auditor
  3. Aligning with enterprise risk management structure
  4. Integrating with existing GRC or audit teams
  5. Setting up governance steering meetings cadence
  6. Documenting escalation paths for control failures
  7. Clarifying decision rights on policy exceptions
  8. Mapping to executive leadership reporting lines
  9. Onboarding committee structures for policy approval
  10. Designing communication plan for control updates
  11. Setting thresholds for incident vs. anomaly reporting
  12. Integrating with change management workflows
Module 3. Week 3: Inventorying Assets and Classifying Data
Build the foundational asset and data classification model for control scoping.
12 chapters in this module
  1. Creating comprehensive IT asset inventory
  2. Classifying systems by criticality and data sensitivity
  3. Mapping data flows across internal and external systems
  4. Applying financial services-specific data categories
  5. Documenting data residency and跨境 storage rules
  6. Linking asset ownership to business units
  7. Tagging systems for regulatory reporting requirements
  8. Integrating with CMDB or configuration management tools
  9. Validating inventory completeness with network scans
  10. Establishing refresh cadence for asset records
  11. Handling shadow IT and undocumented systems
  12. Using classification to drive control applicability
Module 4. Week 4: Mapping Controls to Frameworks
Align control implementation with CISA and other relevant standards.
12 chapters in this module
  1. Selecting baseline control frameworks for financial services
  2. Mapping CISA control objectives to technical and operational controls
  3. Cross-walking controls to internal policies
  4. Identifying overlapping requirements to reduce duplication
  5. Documenting control implementation status per system
  6. Using control matrices for traceability
  7. Linking controls to risk register entries
  8. Establishing testing procedures for each control
  9. Defining evidence types: logs, screenshots, attestations
  10. Creating control ownership sign-off process
  11. Integrating with automated compliance monitoring tools
  12. Setting up version control for the control map
Module 5. Week 5: Designing Policy and Procedure Framework
Develop the core policy suite that governs security operations.
12 chapters in this module
  1. Identifying required policies for financial services
  2. Drafting Information Security Policy with board alignment
  3. Creating Acceptable Use and Access Control Policies
  4. Documenting Incident Response and Breach Notification procedures
  5. Establishing BYOD and remote access rules
  6. Writing Data Handling and Encryption Standards
  7. Developing Third-Party Risk Management policy
  8. Aligning policy language with audit terminology
  9. Setting policy review and update cycles
  10. Obtaining legal and compliance sign-off
  11. Publishing policy to employee portals
  12. Tracking policy acknowledgments across workforce
Module 6. Week 6: Implementing Evidence Collection Workflows
Automate and standardize how control evidence is gathered and validated.
12 chapters in this module
  1. Defining evidence requirements per control
  2. Setting up centralized evidence repository
  3. Designing automated log collection processes
  4. Integrating with SIEM and endpoint detection tools
  5. Creating screenshot and configuration snapshot templates
  6. Standardizing attestation formats for manual controls
  7. Scheduling recurring evidence collection cycles
  8. Assigning evidence owners per control
  9. Implementing timestamp and integrity checks
  10. Validating completeness before audit cycles
  11. Using checklists for evidence readiness
  12. Reducing last-minute scrambles with pre-collection
Module 7. Week 7: Establishing Monitoring and Reporting Cadence
Set up ongoing control monitoring and executive reporting.
12 chapters in this module
  1. Defining KPIs and KRIs for security governance
  2. Creating monthly governance dashboard
  3. Setting up alerting for control deviations
  4. Scheduling quarterly control reviews
  5. Generating automated compliance status reports
  6. Preparing executive summaries for leadership
  7. Documenting trend analysis for recurring issues
  8. Linking findings to remediation backlogs
  9. Integrating with board-level risk reporting
  10. Using dashboards to drive accountability
  11. Benchmarking against industry peer performance
  12. Maintaining report archives for audit
Module 8. Week 8: Conducting First Internal Review Cycle
Run the first end-to-end validation of your governance framework.
12 chapters in this module
  1. Scheduling internal control review meeting
  2. Distributing evidence packages in advance
  3. Facilitating cross-functional review session
  4. Capturing control exceptions and gaps
  5. Prioritizing findings by risk severity
  6. Assigning remediation owners and deadlines
  7. Tracking progress in issue register
  8. Updating control documentation based on feedback
  9. Validating remediation completion
  10. Producing internal review summary report
  11. Communicating outcomes to stakeholders
  12. Adjusting governance cadence based on findings
Module 9. Week 9: Preparing for External Audit
Align documentation and evidence for regulator or external auditor.
12 chapters in this module
  1. Understanding external auditor expectations
  2. Mapping internal controls to audit requirements
  3. Preparing auditor access to systems and logs
  4. Compiling audit response package
  5. Creating auditor question response templates
  6. Conducting mock audit walkthrough
  7. Validating completeness of evidence trails
  8. Ensuring policy versions match implementation
  9. Scheduling auditor interviews with control owners
  10. Preparing supporting documentation for exceptions
  11. Finalizing control matrix for submission
  12. Setting up real-time query response process
Module 10. Week 10: Driving Remediation and Continuous Improvement
Turn findings into sustained governance maturity.
12 chapters in this module
  1. Prioritizing remediation based on risk and effort
  2. Assigning action items with clear deadlines
  3. Integrating fixes into change management process
  4. Validating implementation of corrective actions
  5. Updating control documentation post-fix
  6. Re-testing controls after remediation
  7. Documenting lessons learned from audit cycle
  8. Adjusting control thresholds based on findings
  9. Improving evidence collection workflows
  10. Training teams on updated procedures
  11. Scheduling follow-up reviews
  12. Closing audit findings formally
Module 11. Week 11: Scaling Governance Across Functions
Extend the governance model to new teams, systems, or acquisitions.
12 chapters in this module
  1. Assessing governance readiness of new business units
  2. Onboarding acquired entities to central framework
  3. Tailoring controls for non-core functions
  4. Extending policy applicability across regions
  5. Integrating with DevOps and engineering teams
  6. Adapting governance for cloud migration projects
  7. Providing templates for local implementation
  8. Conducting governance awareness sessions
  9. Establishing local control owners
  10. Auditing compliance in extended areas
  11. Handling regional regulatory variations
  12. Creating scalable governance operating model
Module 12. Week 12: Locking In and Automating the Foundation
Make the governance framework repeatable, resilient, and low-maintenance.
12 chapters in this module
  1. Finalizing governance playbook for reuse
  2. Automating evidence collection and reporting
  3. Implementing version control for all documents
  4. Setting up annual governance refresh cycle
  5. Training backup control owners
  6. Documenting onboarding process for new leads
  7. Integrating with HR for role-based access reviews
  8. Creating self-service policy lookup system
  9. Establishing continuous compliance monitoring
  10. Reducing manual effort through workflow tools
  11. Benchmarking maturity against CISA objectives
  12. Planning next-phase enhancements

How this maps to your situation

  • Onboarding as new Head of Information Security
  • Responding to audit findings requiring governance overhaul
  • Preparing for regulator examination under DORA-type rules
  • Aligning security controls with executive risk appetite

Before vs. after

Before
Starting a new security leadership role with fragmented policies, unclear ownership, and reactive evidence collection during audit crunch.
After
Operating with a clear, CISA-aligned governance model, pre-validated documentation, and stakeholder alignment, ready for regulator review at any time.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per week over 12 weeks, or 20 hours total, with flexible pacing.

If nothing changes
Without a structured foundation, security leaders risk delayed authority establishment, repeated audit findings, and reliance on last-minute documentation that undermines credibility.

How this compares to the alternatives

Unlike generic compliance courses, this program delivers a structured, week-by-week implementation plan tailored to financial services, with real-world templates and CISA-specific mappings used by practitioners in regulated environments.

Frequently asked

Is this course focused on CISA certification prep?
No, this course is not a certification exam prep program. It uses CISA control objectives as a practical implementation framework for building security governance in financial services.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I access the templates without completing the course?
All downloadable templates and the implementation playbook are included with course access and can be used independently once delivered.
$199 one-time. Approximately 90 minutes per week over 12 weeks, or 20 hours total, with flexible pacing..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours