Framework: The Center for Internet Security (CIS) Top 18 Controls

By Jason Edwards

Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.

Image by Jason Edwards

Category: Technology

Open in Apple Podcasts


Open RSS feed


Open Website


Rate for this podcast

Subscribers: 0
Reviews: 0
Episodes: 83

Description

The **CIS Critical Security Controls Audio Course** is a comprehensive, audio-first training series that guides listeners through all eighteen **CIS Controls**, transforming one of the world’s most respected cybersecurity frameworks into clear, actionable learning. Designed for professionals, students, and auditors alike, this series explains each control in practical, plain language—focusing on how to implement, assess, and sustain them in real environments. With eighty-three structured episodes, the course walks you step by step through the safeguards that define effective cybersecurity, helping you understand not only what to do but why each measure matters. The **CIS Controls**, maintained by the Center for Internet Security, represent a globally recognized set of prioritized actions proven to reduce the most common and dangerous cyber risks. Organized across eighteen control families—from inventory and configuration management to incident response and data recovery—the framework provides a practical roadmap for building defensible, risk-aligned security programs. This course explores how organizations can adopt the controls incrementally, measure maturity over time, and map them to other standards such as NIST, ISO 27001, and PCI DSS for comprehensive alignment. Developed by **BareMetalCyber.com**, the CIS Critical Security Controls Audio Course delivers structured, exam-aligned instruction that bridges policy and practice. Each episode reinforces understanding through real-world context, helping listeners translate framework requirements into measurable actions that strengthen organizational resilience and long-term security maturity.

Episode Date
Welcome to the CIS 18 Control Framework
Oct 18, 2025
Episode 82 — Safeguard 18.2 – Internal and red team exercises
Oct 18, 2025
Episode 81 — Safeguard 18.1 – External testing programs
Oct 18, 2025
Episode 80 — Overview – Why penetration testing validates defenses
Oct 18, 2025
Episode 79 — Remaining safeguards summary (Control 17)
Oct 18, 2025
Episode 78 — Safeguard 17.2 – Tabletop exercises
Oct 18, 2025
Episode 77 — Safeguard 17.1 – IR plan and playbooks
Oct 18, 2025
Episode 76 — Overview – Incident response principles
Oct 18, 2025
Episode 75 — Remaining safeguards summary (Control 16)
Oct 18, 2025
Episode 74 — Safeguard 16.2 – Static and dynamic testing
Oct 18, 2025
Episode 73 — Safeguard 16.1 – Secure coding practices
Oct 18, 2025
Episode 72 — Overview – Secure software lifecycle
Oct 18, 2025
Episode 71 — Remaining safeguards summary (Control 15)
Oct 18, 2025
Episode 70 — Safeguard 15.2 – Security requirements in contracts
Oct 18, 2025
Episode 69 — Safeguard 15.1 – Inventory of service providers
Oct 18, 2025
Episode 68 — Overview – Third-party and vendor risks
Oct 18, 2025
Episode 67 — Remaining safeguards summary (Control 14)
Oct 18, 2025
Episode 66 — Safeguard 14.3 – Role-based training for admins and developers
Oct 18, 2025
Episode 65 — Safeguard 14.2 – Phishing simulations
Oct 18, 2025
Episode 64 — Safeguard 14.1 – Security awareness program
Oct 18, 2025
Episode 63 — Overview – Human factor in cyber defense
Oct 18, 2025
Episode 62 — Remaining safeguards summary (Control 13)
Oct 18, 2025
Episode 61 — Safeguard 13.3 – Anomaly detection
Oct 18, 2025
Episode 60 — Safeguard 13.2 – Segmentation and filtering
Oct 18, 2025
Episode 59 — Safeguard 13.1 – Intrusion detection and prevention
Oct 18, 2025
Episode 58 — Overview – Monitoring as the nervous system
Oct 18, 2025
Episode 57 — Remaining safeguards summary (Control 12)
Oct 18, 2025
Episode 56 — Safeguard 12.3 – Remove legacy and unused devices
Oct 18, 2025
Episode 55 — Safeguard 12.2 – Secure and configure devices
Oct 18, 2025
Episode 54 — Safeguard 12.1 – Maintain network diagrams
Oct 18, 2025
Episode 53 — Overview – Network devices and hygiene
Oct 18, 2025
Episode 52 — Remaining safeguards summary (Control 11)
Oct 18, 2025
Episode 51 — Safeguard 11.2 – Testing data recovery
Oct 18, 2025
Episode 50 — Safeguard 11.1 – Backup process design
Oct 18, 2025
Episode 49 — Overview – Planning for inevitable failures
Oct 18, 2025
Episode 48 — Remaining safeguards summary (Control 10)
Oct 18, 2025
Episode 47 — Safeguard 10.2 – Endpoint detection and response (EDR)
Oct 18, 2025
Episode 46 — Safeguard 10.1 – Anti-malware solutions
Oct 18, 2025
Episode 45 — Overview – Malware threats and defenses
Oct 18, 2025
Episode 44 — Remaining safeguards summary (Control 9)
Oct 18, 2025
Episode 43 — Safeguard 9.2 – Browser configuration and isolation
Oct 18, 2025
Episode 42 — Safeguard 9.1 – Spam and phishing defenses
Oct 18, 2025
Episode 41 — Overview – Email and browser as attack vectors
Oct 18, 2025
Episode 40 — Remaining safeguards summary (Control 8)
Oct 18, 2025
Episode 39 — Safeguard 8.2 – Centralized log collection and SIEM
Oct 18, 2025
Episode 38 — Safeguard 8.1 – Enable audit logging
Oct 18, 2025
Episode 37 — Overview – Logs as the backbone of detection
Oct 18, 2025
Episode 36 — Remaining safeguards summary (Control 7)
Oct 18, 2025
Episode 35 — Safeguard 7.3 – Integration with patch management
Oct 18, 2025
Episode 34 — Safeguard 7.2 – Remediation timelines and SLAs
Oct 18, 2025
Episode 33 — Safeguard 7.1 – Vulnerability scanning tools
Oct 18, 2025
Episode 32 — Overview – Why vulnerability management is continuous
Oct 18, 2025
Episode 31 — Remaining safeguards summary (Control 6)
Oct 18, 2025
Episode 30 — Safeguard 6.2 – Role-based access control (RBAC)
Oct 18, 2025
Episode 29 — Safeguard 6.1 – Access authorization processes
Oct 18, 2025
Episode 28 — Overview – Principles of least privilege
Oct 18, 2025
Episode 27 — Remaining safeguards summary (Control 5)
Oct 18, 2025
Episode 26 — Safeguard 5.3 – Disable dormant accounts
Oct 18, 2025
Episode 25 — Safeguard 5.2 – Centralized account management
Oct 18, 2025
Episode 24 — Safeguard 5.1 – Inventory of accounts
Oct 18, 2025
Episode 23 — Overview – Managing identity and accounts
Oct 18, 2025
Episode 22 — Remaining safeguards summary (Control 4)
Oct 18, 2025
Episode 21 — Safeguard 4.2 – Automated configuration management
Oct 18, 2025
Episode 20 — Safeguard 4.1 – Establish secure configuration baselines
Oct 18, 2025
Episode 19 — Overview – Why secure configs matter
Oct 18, 2025
Episode 18 — Remaining safeguards summary (Control 3)
Oct 18, 2025
Episode 17 — Safeguard 3.3 – Data encryption at rest and in transit
Oct 18, 2025
Episode 16 — Safeguard 3.2 – Data retention and disposal
Oct 18, 2025
Episode 15 — Safeguard 3.1 – Data classification and inventory
Oct 18, 2025
Episode 14 — Overview – Protecting sensitive data
Oct 18, 2025
Episode 13 — Remaining safeguards summary (Control 2)
Oct 18, 2025
Episode 12 — Safeguard 2.2 – Only allow authorized software
Oct 18, 2025
Episode 11 — Safeguard 2.1 – Maintain a software inventory
Oct 18, 2025
Episode 10 — Overview – Managing the software landscape
Oct 18, 2025
Episode 9 — Remaining safeguards summary (Control 1)
Oct 18, 2025
Episode 8 — Safeguard 1.2 – Address unauthorized assets
Oct 18, 2025
Episode 7 — Safeguard 1.1 – Inventory of assets
Oct 18, 2025
Episode 6 — Overview – Why asset management is foundational
Oct 18, 2025
Episode 5 — Glossary of common cybersecurity terms
Oct 18, 2025
Episode 4 — Glossary of common cybersecurity terms
Oct 18, 2025
Episode 3 — What is a “control” and what is a “safeguard”?
Oct 18, 2025
Episode 2 — How to use CIS 18 in your organization
Oct 18, 2025
Episode 1 — What are the CIS Critical Security Controls?
Oct 18, 2025