Skip to main content
Image coming soon

SEC3238 Mastering CIS Controls for Managing Directors in Risk Leadership

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for Managing Directors in Risk Leadership

Strengthen your authority in risk governance with a complete implementation roadmap

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Managing Director in risk-focused leadership at a global insurance or risk advisory firm

Who this is not for

Individual contributors without decision stewardship, professionals outside risk governance or compliance leadership, or those seeking entry-level certification prep

What you walk away with

  • Own end-to-end CIS Controls implementation across business units
  • Demonstrate alignment with auditor and regulator expectations using standardized mappings
  • Drive consensus on control ownership without escalation delays
  • Document formal authority over policy updates and exception reviews
  • Extend influence into adjacent domains like cyber resilience and vendor risk

The 12 modules (with all 144 chapters)

Module 1. Foundations of CIS Controls v8
Understand the architecture, structure, and prioritization logic of the CIS Critical Security Controls.
12 chapters in this module
  1. What are CIS Controls
  2. How they differ from NIST CSF
  3. Control groups explained
  4. Implementation groups defined
  5. Mapping to MITRE ATT&CK
  6. Control baselines for different sizes
  7. Relationship to cyber insurance
  8. Adoption trends in financial services
  9. Regulatory recognition status
  10. Integration with ISO 27001
  11. Mapping to SOC 2 criteria
  12. Leveraging CIS RAM tool
Module 2. Governance and Leadership Alignment
Frame CIS Controls as a strategic initiative aligned with executive priorities.
12 chapters in this module
  1. Language for executive summaries
  2. Translating controls to business risk
  3. Securing leadership sponsorship
  4. Reporting progress to senior management
  5. Establishing accountability models
  6. Tying controls to loss prevention
  7. Aligning with ERM frameworks
  8. Budgeting for continuous improvement
  9. Defining success metrics
  10. Creating governance committees
  11. Documenting decision rights
  12. Managing policy exceptions
Module 3. Implementation Group 1: Basic Cyber Hygiene
Deploy foundational controls across endpoints, email, and network perimeters.
12 chapters in this module
  1. Inventory of authorized devices
  2. Inventory of software assets
  3. Secure configuration for hardware
  4. Secure configuration for servers
  5. Secure configuration for mobile
  6. Secure configuration for firewalls
  7. Email and web browser protections
  8. Malware defenses explained
  9. Limiting administrative privileges
  10. Multi-factor authentication rollout
  11. Data recovery controls
  12. Secure email gateway setup
Module 4. Implementation Group 2: Foundational Controls
Implement essential safeguards across systems, accounts, and data access.
12 chapters in this module
  1. Continuous vulnerability assessment
  2. Account monitoring and control
  3. Data protection mechanisms
  4. Limiting data access rights
  5. Encryption of sensitive data
  6. Security awareness training
  7. Email protections beyond gateway
  8. Application software management
  9. Control of network ports
  10. Boundary defense strategies
  11. Network monitoring capabilities
  12. Process for incident response
Module 5. Implementation Group 3: Organizational Controls
Scale controls across departments and third parties with consistency.
12 chapters in this module
  1. Penetration testing scope
  2. Red teaming integration
  3. Security skills assessment
  4. Partner configuration management
  5. Third party risk integration
  6. Service provider oversight
  7. Outsourced workforce policies
  8. Change management controls
  9. Vulnerability management process
  10. Endpoint detection and response
  11. Data loss prevention policies
  12. Application security testing
Module 6. Control Mapping to Regulatory Requirements
Align CIS Controls to compliance obligations across jurisdictions.
12 chapters in this module
  1. Mapping to NIST CSF
  2. Mapping to SOC 2 Trust Services
  3. Mapping to ISO 27001 clauses
  4. Mapping to GDPR Article 32
  5. Mapping to CCPA safeguards
  6. Mapping to HIPAA Security Rule
  7. Mapping to DORA resilience
  8. Mapping to NYDFS 23 NYCRR 500
  9. Mapping to CMMC levels
  10. Mapping to FISMA requirements
  11. Mapping to SOX ITGCs
  12. Mapping to PCI DSS
Module 7. Building the Implementation Playbook
Create a tailored, living document to guide your team’s execution.
12 chapters in this module
  1. Playbook structure overview
  2. Customizing control baselines
  3. Setting implementation timelines
  4. Assigning responsibility matrices
  5. Creating evidence templates
  6. Integrating with GRC tools
  7. Version control practices
  8. Stakeholder onboarding
  9. Status reporting formats
  10. Audit preparation workflows
  11. Continuous improvement loops
  12. Lessons learned documentation
Module 8. Stakeholder Engagement and Buy-In
Secure cooperation across IT, security, legal, and business units.
12 chapters in this module
  1. Identifying key stakeholders
  2. Tailoring messaging by role
  3. Overcoming resistance patterns
  4. Running alignment workshops
  5. Establishing feedback channels
  6. Creating cross-functional teams
  7. Managing competing priorities
  8. Leveraging peer influence
  9. Demonstrating early wins
  10. Tracking engagement metrics
  11. Sustaining momentum
  12. Celebrating milestones
Module 9. Metrics and Reporting Frameworks
Measure progress and communicate value effectively.
12 chapters in this module
  1. Defining maturity levels
  2. Quantifying control coverage
  3. Calculating risk reduction
  4. Benchmarking against peers
  5. Developing KPIs for IT teams
  6. Executive dashboard design
  7. Audit readiness scoring
  8. Regulatory response tracking
  9. Incident correlation analysis
  10. Third-party monitoring metrics
  11. Mean time to remediate
  12. Automated compliance scoring
Module 10. Integration with GRC Platforms
Operationalize CIS Controls in existing enterprise systems.
12 chapters in this module
  1. Integrating with ServiceNow
  2. Configuring in RSA Archer
  3. Using with MetricStream
  4. Aligning with OneTrust
  5. Feeding data to AuditBoard
  6. Automating with Drata
  7. Connecting to Vanta
  8. Customizing workflows
  9. Evidence collection automation
  10. Alerting on control drift
  11. Reporting from native tools
  12. Maintaining single source of truth
Module 11. Audit and Regulatory Readiness
Prepare confidently for internal and external assessments.
12 chapters in this module
  1. Preparing for SOC 2 audits
  2. Responding to ISO 27001 assessors
  3. Evidence package assembly
  4. Control narrative writing
  5. Gap assessment techniques
  6. Remediation tracking system
  7. Interview preparation guide
  8. Follow-up response templates
  9. Regulator communication plan
  10. Corrective action workflows
  11. Maintaining audit trails
  12. Continuous monitoring setup
Module 12. Sustaining and Scaling the Program
Ensure long-term success and organizational embedding.
12 chapters in this module
  1. Establishing center of excellence
  2. Succession planning
  3. Control ownership transitions
  4. Annual review cycles
  5. Updating for new threats
  6. Expanding to new business units
  7. Incorporating lessons learned
  8. Benchmarking updates
  9. Training new hires
  10. Budgeting for evolution
  11. Measuring program ROI
  12. Leadership transition planning

How this maps to your situation

  • After adopting CIS Controls baseline
  • While preparing for external audit
  • During third-party risk expansion
  • Ahead of leadership transition

Before vs. after

Before
Reactive control deployment, fragmented ownership, inconsistent audit outcomes
After
Proactive, unified control framework with recognized authority and repeatable processes

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 18-24 hours total, designed for completion over six weeks with two modules per week.

How this compares to the alternatives

Unlike generic compliance courses, this program is tailored to senior risk leaders who need to extend influence without a title change. It combines technical precision with executive credibility, focusing on implementation, not just theory.

Frequently asked

Who is this course designed for?
Managing Directors and senior risk leaders who steward governance programs and want to expand their remit within their current role.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does this cover mappings to other frameworks?
Yes, includes detailed mappings to SOC 2, ISO 27001, NIST CSF, and regulatory standards.
$199 one-time. Approximately 18-24 hours total, designed for completion over six weeks with two modules per week..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours