A tailored course, built for your situation
Sources and Specific Examples on Hand When Peers Push Back with CIS Controls
Build defensible, source-backed positions in high-stakes governance conversations using the CIS Controls framework
The situation this course is for
Even senior practitioners face pushback when proposing controls, especially when the justification feels procedural rather than rooted in incident data, real-world breaches, or authoritative sources. Without concrete reasoning, decisions get delayed, diluted, or overruled.
Who this is for
Senior security and governance leaders who own framework decisions and must defend them across technical and executive audiences
Who this is not for
Entry-level analysts, auditors looking for checklist training, or teams seeking automated tooling integration
What you walk away with
- Cite breach incidents and attacker behaviors that directly inform each CIS Control
- Explain control priorities using documented examples from real organizations
- Map CIS Controls to attacker kill chains with precision
- Reference authoritative sources like MITRE ATT&CK, CISA alerts, and FBI IC3 reports
- Walk step-by-step through 'why this, not that' decisions in control selection and implementation
The 12 modules (with all 144 chapters)
- Origins of the CIS Controls in actual breach investigations
- How Oracle applications align with common attack paths
- The shift from checklist to evidence-based control selection
- Connecting control decisions to MITRE ATT&CK techniques
- Using CISA Known Exploited Vulnerabilities as input
- Mapping controls to pre-compromise, post-compromise stages
- Why 18 controls cover 80 percent of observed attacks
- Prioritizing controls by exploit likelihood, not just severity
- Differentiating baseline vs. defense-in-depth controls
- Control overlap with NIST CSF and ISO 27001
- How cloud-native applications change control interpretation
- Documenting the 'why' behind each control adoption
- Defining scope using known application attack surfaces
- Excluding systems with documented compensating controls
- Using asset criticality to weight control application
- Citing examples from healthcare vs financial sectors
- When to defer controls based on architecture constraints
- How containerization affects scope boundaries
- Documenting exceptions with attacker behavior context
- Linking scope decisions to incident response findings
- Using CISA alerts to justify boundary changes
- Justifying phased rollouts with attack trend data
- Mapping exceptions to MITRE ATT&CK coverage gaps
- Building a living rationale document for audits
- Why unmanaged devices enabled Colonial Pipeline breach
- Documenting asset discovery methods with tool outputs
- Using NetBIOS vs SNMP data to defend coverage claims
- How stale DNS records create blind spots
- Examples of shadow IT bypassing security controls
- Linking asset completeness to ATT&CK technique TA0007
- Using Microsoft Defender data to validate completeness
- When virtual assets count as 'managed'
- Defending thresholds like '99 percent coverage'
- Justifying scan frequency with ransomware timelines
- How cloud workloads change asset definitions
- Sourcing examples from ISACA and CISA reports
- How default credentials enabled the the current cycle SolarWinds breach
- Using CIS Benchmarks vs vendor baselines
- Mapping insecure settings to ATT&CK technique TA0005
- Examples of credential exposure from logs
- Justifying configuration frequency with exploit cycles
- Using Shodan data to defend hardening scope
- When custom configurations are better than defaults
- Documenting exceptions with compensating controls
- Sourcing examples from FBI IC3 reports
- Linking patch cycles to ransomware delivery windows
- Hardening criteria for third-party SaaS connectors
- How container images change secure config practices
- Why unpatched systems led to the Kaseya breach
- Using CISA Known Exploited Vulnerabilities list
- Mapping scan frequency to exploit availability
- Prioritizing by exploit maturity, not just CVSS
- Defending seven-day patch SLA with real data
- Examples of vulnerabilities exploited within hours
- Linking to MITRE ATT&CK technique TA0001
- Using VulnDB vs NVD for exploit timing
- Sourcing from Google Project Zero disclosures
- When zero-day risk changes patch urgency
- Documenting patch delays with operational context
- Creating defensible risk acceptance templates
- How excessive privileges enabled the Target breach
- Mapping to ATT&CK technique TA0030
- Justifying JIT access with incident data
- Examples of credential theft via admin sessions
- Using PAM logs to defend access policies
- When service accounts break privilege rules
- Documenting exceptions with session monitoring
- Sourcing from Verizon DBIR privilege misuse cases
- Linking to CISA guidance on credential hygiene
- Defending role-based access with breach examples
- How cloud IAM roles change admin definitions
- Creating defensible admin rotation templates
- How flat networks enabled the Marriott breach
- Mapping to ATT&CK technique TA0008
- Using network flow data to defend segmentation
- Examples of unmonitored VLANs leading to exfiltration
- Justifying ACL review frequency with attack dwell time
- Sourcing from CISA network hygiene advisories
- Documenting exceptions with monitoring compensators
- When cloud VPCs replace traditional segmentation
- Linking to MITRE D3-NETFW for rule validation
- Defending microsegmentation scope with breach logic
- How DNS tunneling changes device trust
- Creating defensible rule change templates
- How Cobalt Strike was used in the the current cycle REvil attack
- Mapping to ATT&CK technique TA0002
- Using EDR data to justify blocking rules
- Examples of DNS tunneling in breach investigations
- Sourcing from CISA alerts on common command tools
- Justifying IP blacklists with threat intel feeds
- When encrypted traffic breaks boundary rules
- Documenting exceptions with session decryption
- Linking to MITRE D3-DMZ for rule validation
- Defending outbound connection policies
- How cloud egress changes boundary definitions
- Creating defensible allowlist templates
- How unencrypted databases led to the the firm breach
- Mapping to ATT&CK technique TA0010
- Using data flow diagrams to defend scope
- Examples of PII exposure in app logs
- Justifying DLP rules with breach timelines
- Sourcing from FTC enforcement actions
- When tokenization replaces encryption
- Documenting unencrypted data with compensators
- Linking to NIST 800-122 for data handling
- Defending classification thresholds
- How cloud storage changes data boundaries
- Creating defensible data retention templates
- Why missing logs delayed the Uber breach discovery
- Mapping to ATT&CK technique TA0011
- Using SIEM coverage to defend detection rules
- Examples of log gaps enabling lateral movement
- Justifying retention with investigation needs
- Sourcing from CISA log retention guidance
- When cloud-native logs replace traditional sources
- Documenting log exclusions with compensators
- Linking to MITRE D3-LA for visibility validation
- Defending correlation rules with attack patterns
- How serverless changes logging practices
- Creating defensible log review templates
- How phishing led to the the current cycle MOVEit compromise
- Mapping to ATT&CK technique TA0001
- Using URL filtering logs to defend blocklists
- Examples of malicious macros in breach chains
- Justifying script blocking with exploit data
- Sourcing from CISA phishing alerts
- When SaaS email changes protection rules
- Documenting exceptions with user training
- Linking to DMARC enforcement levels
- Defending browser isolation policies
- How zero-trust browsers change the model
- Creating defensible email exception templates
- How Emotet spread in the the current cycle healthcare attacks
- Mapping to ATT&CK technique TA0002
- Using YARA rules to defend detection logic
- Examples of fileless malware evading controls
- Justifying EDR coverage with attack surface
- Sourcing from MITRE CAR analytics repository
- When cloud workloads change malware profiles
- Documenting disabled features with compensators
- Linking to CISA malware analysis reports
- Defending behavioral blocking rules
- How memory-resident malware changes detection
- Creating defensible override templates
How this maps to your situation
- When a peer questions your control scope
- During design review with infrastructure leads
- Before audit validation with compliance teams
- When onboarding new cloud services
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per module, designed to fit within executive schedules. Total course time: around 18 hours.
How this compares to the alternatives
Unlike generic compliance courses, this program focuses exclusively on building defensible, source-backed reasoning for control decisions, giving you the concrete examples and frameworks needed to win high-stakes discussions.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.