A tailored course, built for your situation
Mastering CIS Controls for General Managers in Commercial Real Estate
Become the recognized authority on cybersecurity best practices within your organization
Who this is for
Senior operational leader in commercial real estate with cross-domain oversight and growing responsibility for vendor risk, cybersecurity posture, and internal stakeholder alignment.
Who this is not for
Entry-level IT staff, dedicated information security analysts, or consultants outside commercial real estate operations.
What you walk away with
- Lead cross-functional discussions using a standardized cybersecurity framework (CIS Controls) others respect and follow
- Produce documented risk assessments that align facilities, IT, and compliance teams without rework
- Respond to vendor security questionnaires with confidence and consistency
- Anticipate auditor requests by embedding control mapping into routine asset management
- Establish repeatable review rhythms that reduce last-minute scramble before compliance cycles
The 12 modules (with all 144 chapters)
- What CIS Controls are
- Why they matter in CRE
- Control family overview
- Mapping to physical assets
- Vendor risk linkage
- Regulatory alignment
- CRE-specific risks
- Control prioritization
- Integration with FM teams
- Documentation standards
- Audit readiness link
- Real-world examples
- Hardware inventory methods
- Software tracking tools
- IoT device classification
- Device ownership assignment
- Lifecycle tracking
- Patch status monitoring
- Remote asset visibility
- Lease-end reconciliation
- Automated discovery
- Integration with CMDB
- Rental space audits
- Monthly review process
- Vendor onboarding checklist
- Security questionnaire design
- Tiered vendor classification
- Contractual control clauses
- Ongoing monitoring
- Insurance review process
- Incident response coordination
- Access revocation timing
- SLA security metrics
- Subcontractor oversight
- Due diligence cadence
- Exit reviews
- Router configuration baseline
- Switch security settings
- Firewall rule hygiene
- Default credential removal
- Remote access controls
- Network segmentation
- Change approval process
- Firmware update schedule
- Encryption standards
- Monitoring setup
- Vulnerability scanning
- Compliance checking
- Scan scheduling
- Asset coverage scope
- Risk scoring method
- Criticality tiers
- Remediation SLAs
- Patch deployment workflow
- False positive handling
- Reporting to leadership
- Integration with ticketing
- Monthly review meeting
- Escalation paths
- Success metrics
- Role-based access design
- Privileged account tracking
- MFA rollout strategy
- Password policy enforcement
- Session timeout rules
- Access review frequency
- Vendor access limits
- Remote worker setup
- Emergency bypass process
- Audit logging
- Break-glass accounts
- Quarterly cleanup
- Log sources inventory
- Retention policy setup
- Centralized collection
- Encryption in transit
- Access controls
- Review frequency
- Anomaly detection
- Incident correlation
- Retention period
- Legal hold process
- Storage compliance
- Quarterly audit prep
- Email filtering setup
- URL rewriting
- Phishing simulation
- Browser hardening
- Extension policy
- User training rhythm
- Click reporting
- Quarantine review
- Spam threshold tuning
- Mobile email config
- Domain monitoring
- DMARC implementation
- Antivirus selection
- EDR integration
- Real-time scanning
- Automatic updates
- Quarantine workflow
- Threat intelligence feed
- Incident response steps
- Device isolation
- User alerting
- Monthly report review
- False positive tracking
- Policy exception process
- Data discovery tools
- Classification schema
- Encryption standards
- At-rest protection
- In-transit encryption
- Cloud storage settings
- Removable media policy
- DLP rules
- Legal requirements
- Tenant data handling
- Breach notification plan
- Annual review
- Incident types classification
- Response team roles
- Communication tree
- Evidence preservation
- Forensic access
- Legal coordination
- Tenant notification
- Regulator reporting
- Post-incident review
- Tabletop exercises
- Plan update cycle
- Insurance claims
- Training frequency
- Content localization
- Leadership involvement
- Posters and signage
- Recognition programs
- Phishing metrics
- Feedback collection
- Language accessibility
- New hire onboarding
- Tenant communications
- Monthly themes
- Yearly campaign
How this maps to your situation
- When onboarding a new property management vendor
- Preparing for annual SOC 2 or ISO audit
- Responding to a phishing attempt across offices
- Rolling out new building automation systems
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed for completion within 12 weeks with real-world application at each stage.
How this compares to the alternatives
Unlike generic cybersecurity courses, this focuses on the unique operational context of commercial real estate, linking CIS Controls directly to facilities, vendor management, and asset oversight.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.