A tailored course, built for your situation
Mastering CIS Controls for Managing Directors in Risk Leadership
Strengthen your authority in risk governance with a complete implementation roadmap
Who this is for
Managing Director in risk-focused leadership at a global insurance or risk advisory firm
Who this is not for
Individual contributors without decision stewardship, professionals outside risk governance or compliance leadership, or those seeking entry-level certification prep
What you walk away with
- Own end-to-end CIS Controls implementation across business units
- Demonstrate alignment with auditor and regulator expectations using standardized mappings
- Drive consensus on control ownership without escalation delays
- Document formal authority over policy updates and exception reviews
- Extend influence into adjacent domains like cyber resilience and vendor risk
The 12 modules (with all 144 chapters)
- What are CIS Controls
- How they differ from NIST CSF
- Control groups explained
- Implementation groups defined
- Mapping to MITRE ATT&CK
- Control baselines for different sizes
- Relationship to cyber insurance
- Adoption trends in financial services
- Regulatory recognition status
- Integration with ISO 27001
- Mapping to SOC 2 criteria
- Leveraging CIS RAM tool
- Language for executive summaries
- Translating controls to business risk
- Securing leadership sponsorship
- Reporting progress to senior management
- Establishing accountability models
- Tying controls to loss prevention
- Aligning with ERM frameworks
- Budgeting for continuous improvement
- Defining success metrics
- Creating governance committees
- Documenting decision rights
- Managing policy exceptions
- Inventory of authorized devices
- Inventory of software assets
- Secure configuration for hardware
- Secure configuration for servers
- Secure configuration for mobile
- Secure configuration for firewalls
- Email and web browser protections
- Malware defenses explained
- Limiting administrative privileges
- Multi-factor authentication rollout
- Data recovery controls
- Secure email gateway setup
- Continuous vulnerability assessment
- Account monitoring and control
- Data protection mechanisms
- Limiting data access rights
- Encryption of sensitive data
- Security awareness training
- Email protections beyond gateway
- Application software management
- Control of network ports
- Boundary defense strategies
- Network monitoring capabilities
- Process for incident response
- Penetration testing scope
- Red teaming integration
- Security skills assessment
- Partner configuration management
- Third party risk integration
- Service provider oversight
- Outsourced workforce policies
- Change management controls
- Vulnerability management process
- Endpoint detection and response
- Data loss prevention policies
- Application security testing
- Mapping to NIST CSF
- Mapping to SOC 2 Trust Services
- Mapping to ISO 27001 clauses
- Mapping to GDPR Article 32
- Mapping to CCPA safeguards
- Mapping to HIPAA Security Rule
- Mapping to DORA resilience
- Mapping to NYDFS 23 NYCRR 500
- Mapping to CMMC levels
- Mapping to FISMA requirements
- Mapping to SOX ITGCs
- Mapping to PCI DSS
- Playbook structure overview
- Customizing control baselines
- Setting implementation timelines
- Assigning responsibility matrices
- Creating evidence templates
- Integrating with GRC tools
- Version control practices
- Stakeholder onboarding
- Status reporting formats
- Audit preparation workflows
- Continuous improvement loops
- Lessons learned documentation
- Identifying key stakeholders
- Tailoring messaging by role
- Overcoming resistance patterns
- Running alignment workshops
- Establishing feedback channels
- Creating cross-functional teams
- Managing competing priorities
- Leveraging peer influence
- Demonstrating early wins
- Tracking engagement metrics
- Sustaining momentum
- Celebrating milestones
- Defining maturity levels
- Quantifying control coverage
- Calculating risk reduction
- Benchmarking against peers
- Developing KPIs for IT teams
- Executive dashboard design
- Audit readiness scoring
- Regulatory response tracking
- Incident correlation analysis
- Third-party monitoring metrics
- Mean time to remediate
- Automated compliance scoring
- Integrating with ServiceNow
- Configuring in RSA Archer
- Using with MetricStream
- Aligning with OneTrust
- Feeding data to AuditBoard
- Automating with Drata
- Connecting to Vanta
- Customizing workflows
- Evidence collection automation
- Alerting on control drift
- Reporting from native tools
- Maintaining single source of truth
- Preparing for SOC 2 audits
- Responding to ISO 27001 assessors
- Evidence package assembly
- Control narrative writing
- Gap assessment techniques
- Remediation tracking system
- Interview preparation guide
- Follow-up response templates
- Regulator communication plan
- Corrective action workflows
- Maintaining audit trails
- Continuous monitoring setup
- Establishing center of excellence
- Succession planning
- Control ownership transitions
- Annual review cycles
- Updating for new threats
- Expanding to new business units
- Incorporating lessons learned
- Benchmarking updates
- Training new hires
- Budgeting for evolution
- Measuring program ROI
- Leadership transition planning
How this maps to your situation
- After adopting CIS Controls baseline
- While preparing for external audit
- During third-party risk expansion
- Ahead of leadership transition
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 18-24 hours total, designed for completion over six weeks with two modules per week.
How this compares to the alternatives
Unlike generic compliance courses, this program is tailored to senior risk leaders who need to extend influence without a title change. It combines technical precision with executive credibility, focusing on implementation, not just theory.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.