What is the First 90 Days course about?
A step-by-step guide to building a security governance foundation in your first 90 days Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
What situation is the First 90 Days for?
New security leaders in financial services often spend their first 60-90 days assembling disjointed control evidence, chasing stakeholder inputs, and revising documentation under time pressure, especially when audit or regulator cycles converge. This delays strategic momentum and exposes early gaps in authority and traceability.
Who is the First 90 Days course for?
Head of Information Security in financial services, often holding CISA, CISSP, or CCSP credentials, responsible for standing up or refining security governance in a regulated environment within the first three months of role start or structural change.
What do you take away from the First 90 Days course?
Launch a fully traceable security governance framework within 90 days Produce regulator-ready control documentation that passes internal review on first submission Map stakeholder responsibilities and escalation paths before the first audit cycle Reduce rework in evidence collection by implementing pre-validated templates Establish clear ownership of control assertions and monitoring cycles from day one.
How does this map to your situation?
Onboarding as new Head of Information Security Responding to audit findings requiring governance overhaul Preparing for regulator examination under DORA-type rules Aligning security controls with executive risk appetite.
What's included with your purchase?
12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.
What does the First 90 Days cover on delivery and format?
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 90 minutes per week over 12 weeks, or 20 hours total, with flexible pacing.
How does this compare to the alternatives?
Unlike generic compliance courses, this program delivers a structured, week-by-week implementation plan tailored to financial services, with real-world templates and CISA-specific mappings used by practitioners in regulated environments.
Closely related courses: First 90 Days Evaluation and First 90 Days Evaluation Kit, First 90 Days Toolkit, First 100 Days Toolkit, First 90 Days Evaluation Toolkit.
More answers: what you get with every course, refund policy, all help answers.
A tailored course, built for your situation
First 90 Days: Building a Security Governance Foundation in Financial Services
A step-by-step guide to building a security governance foundation in your first 90 days
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
The situation this course is for
New security leaders in financial services often spend their first 60-90 days assembling disjointed control evidence, chasing stakeholder inputs, and revising documentation under time pressure, especially when audit or regulator cycles converge. This delays strategic momentum and exposes early gaps in authority and traceability.
Who this is for
Head of Information Security in financial services, often holding CISA, CISSP, or CCSP credentials, responsible for standing up or refining security governance in a regulated environment within the first three months of role start or structural change
Who this is not for
Security analysts, junior auditors, or IT support staff not responsible for end-to-end governance design or control ownership
What you walk away with
- Launch a fully traceable security governance framework within 90 days
- Produce regulator-ready control documentation that passes internal review on first submission
- Map stakeholder responsibilities and escalation paths before the first audit cycle
- Reduce rework in evidence collection by implementing pre-validated templates
- Establish clear ownership of control assertions and monitoring cycles from day one
The 12 modules (with all 144 chapters)
- Reviewing existing control inventories and policy documentation
- Mapping current compliance obligations to financial services regulations
- Identifying recent audit findings or control exceptions
- Determining scope of security governance ownership
- Engaging with legal and compliance for regulatory context
- Documenting jurisdictional and cross-border data handling rules
- Assessing alignment with CISA control objectives
- Cataloging known third-party vendor risks
- Identifying key internal stakeholders and decision owners
- Setting up governance documentation repository
- Defining thresholds for risk acceptance and escalation
- Creating the initial governance project charter
- Establishing RACI matrix for control ownership
- Defining roles: control owner, reviewer, operator, auditor
- Aligning with enterprise risk management structure
- Integrating with existing GRC or audit teams
- Setting up governance steering meetings cadence
- Documenting escalation paths for control failures
- Clarifying decision rights on policy exceptions
- Mapping to executive leadership reporting lines
- Onboarding committee structures for policy approval
- Designing communication plan for control updates
- Setting thresholds for incident vs. anomaly reporting
- Integrating with change management workflows
- Creating comprehensive IT asset inventory
- Classifying systems by criticality and data sensitivity
- Mapping data flows across internal and external systems
- Applying financial services-specific data categories
- Documenting data residency and跨境 storage rules
- Linking asset ownership to business units
- Tagging systems for regulatory reporting requirements
- Integrating with CMDB or configuration management tools
- Validating inventory completeness with network scans
- Establishing refresh cadence for asset records
- Handling shadow IT and undocumented systems
- Using classification to drive control applicability
- Selecting baseline control frameworks for financial services
- Mapping CISA control objectives to technical and operational controls
- Cross-walking controls to internal policies
- Identifying overlapping requirements to reduce duplication
- Documenting control implementation status per system
- Using control matrices for traceability
- Linking controls to risk register entries
- Establishing testing procedures for each control
- Defining evidence types: logs, screenshots, attestations
- Creating control ownership sign-off process
- Integrating with automated compliance monitoring tools
- Setting up version control for the control map
- Identifying required policies for financial services
- Drafting Information Security Policy with board alignment
- Creating Acceptable Use and Access Control Policies
- Documenting Incident Response and Breach Notification procedures
- Establishing BYOD and remote access rules
- Writing Data Handling and Encryption Standards
- Developing Third-Party Risk Management policy
- Aligning policy language with audit terminology
- Setting policy review and update cycles
- Obtaining legal and compliance sign-off
- Publishing policy to employee portals
- Tracking policy acknowledgments across workforce
- Defining evidence requirements per control
- Setting up centralized evidence repository
- Designing automated log collection processes
- Integrating with SIEM and endpoint detection tools
- Creating screenshot and configuration snapshot templates
- Standardizing attestation formats for manual controls
- Scheduling recurring evidence collection cycles
- Assigning evidence owners per control
- Implementing timestamp and integrity checks
- Validating completeness before audit cycles
- Using checklists for evidence readiness
- Reducing last-minute scrambles with pre-collection
- Defining KPIs and KRIs for security governance
- Creating monthly governance dashboard
- Setting up alerting for control deviations
- Scheduling quarterly control reviews
- Generating automated compliance status reports
- Preparing executive summaries for leadership
- Documenting trend analysis for recurring issues
- Linking findings to remediation backlogs
- Integrating with board-level risk reporting
- Using dashboards to drive accountability
- Benchmarking against industry peer performance
- Maintaining report archives for audit
- Scheduling internal control review meeting
- Distributing evidence packages in advance
- Facilitating cross-functional review session
- Capturing control exceptions and gaps
- Prioritizing findings by risk severity
- Assigning remediation owners and deadlines
- Tracking progress in issue register
- Updating control documentation based on feedback
- Validating remediation completion
- Producing internal review summary report
- Communicating outcomes to stakeholders
- Adjusting governance cadence based on findings
- Understanding external auditor expectations
- Mapping internal controls to audit requirements
- Preparing auditor access to systems and logs
- Compiling audit response package
- Creating auditor question response templates
- Conducting mock audit walkthrough
- Validating completeness of evidence trails
- Ensuring policy versions match implementation
- Scheduling auditor interviews with control owners
- Preparing supporting documentation for exceptions
- Finalizing control matrix for submission
- Setting up real-time query response process
- Prioritizing remediation based on risk and effort
- Assigning action items with clear deadlines
- Integrating fixes into change management process
- Validating implementation of corrective actions
- Updating control documentation post-fix
- Re-testing controls after remediation
- Documenting lessons learned from audit cycle
- Adjusting control thresholds based on findings
- Improving evidence collection workflows
- Training teams on updated procedures
- Scheduling follow-up reviews
- Closing audit findings formally
- Assessing governance readiness of new business units
- Onboarding acquired entities to central framework
- Tailoring controls for non-core functions
- Extending policy applicability across regions
- Integrating with DevOps and engineering teams
- Adapting governance for cloud migration projects
- Providing templates for local implementation
- Conducting governance awareness sessions
- Establishing local control owners
- Auditing compliance in extended areas
- Handling regional regulatory variations
- Creating scalable governance operating model
- Finalizing governance playbook for reuse
- Automating evidence collection and reporting
- Implementing version control for all documents
- Setting up annual governance refresh cycle
- Training backup control owners
- Documenting onboarding process for new leads
- Integrating with HR for role-based access reviews
- Creating self-service policy lookup system
- Establishing continuous compliance monitoring
- Reducing manual effort through workflow tools
- Benchmarking maturity against CISA objectives
- Planning next-phase enhancements
How this maps to your situation
- Onboarding as new Head of Information Security
- Responding to audit findings requiring governance overhaul
- Preparing for regulator examination under DORA-type rules
- Aligning security controls with executive risk appetite
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per week over 12 weeks, or 20 hours total, with flexible pacing.
How this compares to the alternatives
Unlike generic compliance courses, this program delivers a structured, week-by-week implementation plan tailored to financial services, with real-world templates and CISA-specific mappings used by practitioners in regulated environments.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.