Skip to main content
Image coming soon

SEC1776 Mastering CIS Controls for General Managers in Commercial Real Estate

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for General Managers in Commercial Real Estate

Become the recognized authority on cybersecurity best practices within your organization

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior operational leader in commercial real estate with cross-domain oversight and growing responsibility for vendor risk, cybersecurity posture, and internal stakeholder alignment.

Who this is not for

Entry-level IT staff, dedicated information security analysts, or consultants outside commercial real estate operations.

What you walk away with

  • Lead cross-functional discussions using a standardized cybersecurity framework (CIS Controls) others respect and follow
  • Produce documented risk assessments that align facilities, IT, and compliance teams without rework
  • Respond to vendor security questionnaires with confidence and consistency
  • Anticipate auditor requests by embedding control mapping into routine asset management
  • Establish repeatable review rhythms that reduce last-minute scramble before compliance cycles

The 12 modules (with all 144 chapters)

Module 1. Understanding CIS Controls in Real Estate Contexts
An introduction to the 20 CIS Controls with emphasis on applicability to property operations, tenant services, and asset management teams. Focuses on translating technical controls into operational actions.
12 chapters in this module
  1. What CIS Controls are
  2. Why they matter in CRE
  3. Control family overview
  4. Mapping to physical assets
  5. Vendor risk linkage
  6. Regulatory alignment
  7. CRE-specific risks
  8. Control prioritization
  9. Integration with FM teams
  10. Documentation standards
  11. Audit readiness link
  12. Real-world examples
Module 2. Asset Inventory and Device Management
Establish a reliable foundation for security by maintaining accurate, up-to-date records of all hardware and software across portfolios, including IoT devices and building systems.
12 chapters in this module
  1. Hardware inventory methods
  2. Software tracking tools
  3. IoT device classification
  4. Device ownership assignment
  5. Lifecycle tracking
  6. Patch status monitoring
  7. Remote asset visibility
  8. Lease-end reconciliation
  9. Automated discovery
  10. Integration with CMDB
  11. Rental space audits
  12. Monthly review process
Module 3. Vendor Risk and Third-Party Oversight
Apply CIS Controls to manage security across service providers, contractors, and technology vendors, ensuring alignment with organizational risk posture.
12 chapters in this module
  1. Vendor onboarding checklist
  2. Security questionnaire design
  3. Tiered vendor classification
  4. Contractual control clauses
  5. Ongoing monitoring
  6. Insurance review process
  7. Incident response coordination
  8. Access revocation timing
  9. SLA security metrics
  10. Subcontractor oversight
  11. Due diligence cadence
  12. Exit reviews
Module 4. Secure Configuration for Network Devices
Ensure all network infrastructure components meet hardened baselines, reducing attack surface across buildings and remote offices.
12 chapters in this module
  1. Router configuration baseline
  2. Switch security settings
  3. Firewall rule hygiene
  4. Default credential removal
  5. Remote access controls
  6. Network segmentation
  7. Change approval process
  8. Firmware update schedule
  9. Encryption standards
  10. Monitoring setup
  11. Vulnerability scanning
  12. Compliance checking
Module 5. Continuous Vulnerability Management
Implement a predictable rhythm for identifying, prioritizing, and remediating security weaknesses across systems and assets.
12 chapters in this module
  1. Scan scheduling
  2. Asset coverage scope
  3. Risk scoring method
  4. Criticality tiers
  5. Remediation SLAs
  6. Patch deployment workflow
  7. False positive handling
  8. Reporting to leadership
  9. Integration with ticketing
  10. Monthly review meeting
  11. Escalation paths
  12. Success metrics
Module 6. Account Access Control and MFA Enforcement
Strengthen identity management across employees, vendors, and systems by enforcing least privilege and multi-factor authentication.
12 chapters in this module
  1. Role-based access design
  2. Privileged account tracking
  3. MFA rollout strategy
  4. Password policy enforcement
  5. Session timeout rules
  6. Access review frequency
  7. Vendor access limits
  8. Remote worker setup
  9. Emergency bypass process
  10. Audit logging
  11. Break-glass accounts
  12. Quarterly cleanup
Module 7. Audit Log Management and Review
Collect, protect, and analyze logs from key systems to support investigations and compliance demonstrations.
12 chapters in this module
  1. Log sources inventory
  2. Retention policy setup
  3. Centralized collection
  4. Encryption in transit
  5. Access controls
  6. Review frequency
  7. Anomaly detection
  8. Incident correlation
  9. Retention period
  10. Legal hold process
  11. Storage compliance
  12. Quarterly audit prep
Module 8. Email and Web Browser Protections
Reduce phishing and web-based threats by applying CIS-recommended configurations and training to widely used endpoints.
12 chapters in this module
  1. Email filtering setup
  2. URL rewriting
  3. Phishing simulation
  4. Browser hardening
  5. Extension policy
  6. User training rhythm
  7. Click reporting
  8. Quarantine review
  9. Spam threshold tuning
  10. Mobile email config
  11. Domain monitoring
  12. DMARC implementation
Module 9. Malware Defense and Endpoint Protection
Deploy and maintain effective protections across all devices accessing corporate and building systems.
12 chapters in this module
  1. Antivirus selection
  2. EDR integration
  3. Real-time scanning
  4. Automatic updates
  5. Quarantine workflow
  6. Threat intelligence feed
  7. Incident response steps
  8. Device isolation
  9. User alerting
  10. Monthly report review
  11. False positive tracking
  12. Policy exception process
Module 10. Data Protection and Encryption
Ensure sensitive data is identified, classified, and protected in storage and transit across locations and teams.
12 chapters in this module
  1. Data discovery tools
  2. Classification schema
  3. Encryption standards
  4. At-rest protection
  5. In-transit encryption
  6. Cloud storage settings
  7. Removable media policy
  8. DLP rules
  9. Legal requirements
  10. Tenant data handling
  11. Breach notification plan
  12. Annual review
Module 11. Incident Response Planning
Prepare for security events with clear roles, communication plans, and evidence preservation steps tailored to real estate operations.
12 chapters in this module
  1. Incident types classification
  2. Response team roles
  3. Communication tree
  4. Evidence preservation
  5. Forensic access
  6. Legal coordination
  7. Tenant notification
  8. Regulator reporting
  9. Post-incident review
  10. Tabletop exercises
  11. Plan update cycle
  12. Insurance claims
Module 12. Security Awareness and Culture Building
Foster a culture of security awareness across non-technical teams and frontline staff through consistent messaging and engagement.
12 chapters in this module
  1. Training frequency
  2. Content localization
  3. Leadership involvement
  4. Posters and signage
  5. Recognition programs
  6. Phishing metrics
  7. Feedback collection
  8. Language accessibility
  9. New hire onboarding
  10. Tenant communications
  11. Monthly themes
  12. Yearly campaign

How this maps to your situation

  • When onboarding a new property management vendor
  • Preparing for annual SOC 2 or ISO audit
  • Responding to a phishing attempt across offices
  • Rolling out new building automation systems

Before vs. after

Before
Security discussions are fragmented, requiring repeated context-setting across teams, and reliance on ad hoc vendor responses.
After
You lead from a position of recognized expertise, with standardized references and documented processes others follow.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for completion within 12 weeks with real-world application at each stage.

If nothing changes
Without a structured framework, security efforts remain reactive and siloed, increasing exposure and reducing leadership trust in operational resilience.

How this compares to the alternatives

Unlike generic cybersecurity courses, this focuses on the unique operational context of commercial real estate, linking CIS Controls directly to facilities, vendor management, and asset oversight.

Frequently asked

Is this course technical?
No. It's designed for operational leaders who need to understand and apply cybersecurity principles without being IT specialists.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me with audits?
Yes. You'll build documented, repeatable processes that auditors recognize and accept.
$199 one-time. Approximately 3 hours per module, designed for completion within 12 weeks with real-world application at each stage..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours