Framework: The Center for Internet Security (CIS) Top 18 Controls

Framework: The Center for Internet Security (CIS) Top 18 Controls

Jason Edwards

Episodes 83
Avg. Duration 10m
Activity Dormant
Since Oct 2025
Latest Episode Oct 2025

Publishing Details

Schedule
Hourly
Format
Serial
Hosting
feeds.transistor.fm

Contact & Outreach

About This Podcast

The **CIS Critical Security Controls Audio Course** is a comprehensive, audio-first training series that guides listeners through all eighteen **CIS Controls**, transforming one of the world’s most respected cybersecurity frameworks into clear, actionable learning. Designed for professionals, students, and auditors alike, this series explains each control in practical, plain language—focusing on how to implement, assess, and sustain them in real environments. With eighty-three structured episodes, the course walks you step by step through the safeguards that define effective cybersecurity, helping you understand not only what to do but why each measure matters. The **CIS Controls**, maintained by the Center for Internet Security, represent a globally recognized set of prioritized actions proven to reduce the most common and dangerous cyber risks. Organized across eighteen control families—from inventory and configuration management to incident response and data recovery—the framework provides a practical roadmap for building defensible, risk-aligned security programs. This course explores how organizations can adopt the controls incrementally, measure maturity over time, and map them to other standards such as NIST, ISO 27001, and PCI DSS for comprehensive alignment. Developed by **BareMetalCyber.com**, the CIS Critical Security Controls Audio Course delivers structured, exam-aligned instruction that bridges policy and practice. Each episode reinforces understanding through real-world context, helping listeners translate framework requirements into measurable actions that strengthen organizational resilience and long-term security maturity.

Podcasting 2.0 Features

episode podping podroll remoteItem trailer transcript

Explore Statistics

Recent Episodes

Welcome to the CIS 18 Control Framework

Oct 18, 2025 1m Trailer Transcript

Episode 82 — Safeguard 18.2 – Internal and red team exercises

Oct 18, 2025 12m Transcript

Safeguard 18.2 extends penetration testing to include internal assessments and red team exercises that emulate an attacker with initial access. Internal testing evaluates how far a threat could move…

Episode 81 — Safeguard 18.1 – External testing programs

Oct 18, 2025 10m Transcript

Safeguard 18.1 requires organizations to establish and maintain a formal penetration testing program that includes recurring external assessments. External tests simulate real-world attackers…

Episode 80 — Overview – Why penetration testing validates defenses

Oct 18, 2025 10m Transcript

Control 18—Penetration Testing—closes the CIS framework by validating how well all other controls perform under real-world conditions. While vulnerability scanning identifies potential weaknesses,…

Episode 79 — Remaining safeguards summary (Control 17)

Oct 18, 2025 9m Transcript

The remaining safeguards in Control 17 reinforce the full lifecycle of incident response—spanning preparation, communication, testing, and continuous improvement. These include assigning key response…

Episode 78 — Safeguard 17.2 – Tabletop exercises

Oct 18, 2025 10m Transcript

Safeguard 17.2 emphasizes the importance of testing the incident response plan through structured tabletop exercises. These simulations bring together key personnel—from technical teams to…

Episode 77 — Safeguard 17.1 – IR plan and playbooks

Oct 18, 2025 10m Transcript

Safeguard 17.1 requires organizations to establish and maintain a comprehensive incident response process that defines scope, roles, responsibilities, and communication procedures. This process must…

Episode 76 — Overview – Incident response principles

Oct 18, 2025 11m Transcript

Control 17—Incident Response Management—defines how an organization prepares for, detects, responds to, and learns from security incidents. Even the most robust defenses can be breached, and when…

Episode 75 — Remaining safeguards summary (Control 16)

Oct 18, 2025 11m Transcript

The remaining safeguards under this control expand beyond coding and testing to address the full ecosystem in which applications live. They include maintaining an inventory of third-party components…

Episode 74 — Safeguard 16.2 – Static and dynamic testing

Oct 18, 2025 12m Transcript

This safeguard advances assurance by requiring a structured process to accept and address reported vulnerabilities and by embedding testing that sees both code and behavior. Static analysis inspects…

Episode 73 — Safeguard 16.1 – Secure coding practices

Oct 18, 2025 12m Transcript

This safeguard directs organizations to formalize a secure application development process and set explicit standards for how code is designed, written, reviewed, and released. Secure coding…

Episode 72 — Overview – Secure software lifecycle

Oct 18, 2025 11m Transcript

A secure software lifecycle integrates security activities into every stage of building and operating applications—planning, design, development, testing, deployment, and maintenance—so that…

Episode 71 — Remaining safeguards summary (Control 15)

Oct 18, 2025 12m Transcript

The remaining safeguards in Control 15 round out a complete third-party risk program by adding structured assessment, continuous monitoring, and secure decommissioning. After building the inventory…

Episode 70 — Safeguard 15.2 – Security requirements in contracts

Oct 18, 2025 10m Transcript

Safeguard 15.2 ensures that contracts with service providers explicitly define security expectations and obligations, creating enforceable accountability. Every vendor relationship introduces risk,…

Episode 69 — Safeguard 15.1 – Inventory of service providers

Oct 18, 2025 11m Transcript

Safeguard 15.1 requires organizations to establish and maintain a complete inventory of all service providers that store, process, or access enterprise data. This inventory must include vendor…

Episode 68 — Overview – Third-party and vendor risks

Oct 18, 2025 12m Transcript

Control 15—Service Provider Management—addresses the growing reliance on third-party vendors and the risks that accompany it. In today’s interconnected ecosystems, external partners often handle…

Episode 67 — Remaining safeguards summary (Control 14)

Oct 18, 2025 10m Transcript

The remaining safeguards under Control 14 extend awareness beyond general staff by emphasizing continuous reinforcement, contextual learning, and cultural integration. They include training employees…

Episode 66 — Safeguard 14.3 – Role-based training for admins and developers

Oct 18, 2025 11m Transcript

Safeguard 14.3 focuses on providing targeted, role-based training to employees whose responsibilities involve elevated privileges or specialized technical duties—such as system administrators,…

Episode 65 — Safeguard 14.2 – Phishing simulations

Oct 18, 2025 10m Transcript

Safeguard 14.2 emphasizes the use of phishing simulations to test, measure, and improve employee awareness of social engineering attacks. Phishing remains the most prevalent method for initial…

Episode 64 — Safeguard 14.1 – Security awareness program

Oct 18, 2025 10m Transcript

Safeguard 14.1 requires organizations to establish and maintain a formal security awareness program that educates the workforce on secure behaviors and threat recognition. The program should define…

Frequently Asked Questions

How many episodes does Framework: The Center for Internet Security (CIS) Top 18 Controls have?

Framework: The Center for Internet Security (CIS) Top 18 Controls has published 83 episodes since October 2025, covering topics in Courses, Education.

Is Framework: The Center for Internet Security (CIS) Top 18 Controls still active?

Framework: The Center for Internet Security (CIS) Top 18 Controls is currently dormant with new episodes hourly. Average episode length is 10m.

How do I contact Framework: The Center for Internet Security (CIS) Top 18 Controls for sponsorship or guest appearances?

Sign up on Grep.FM to access contact details for Framework: The Center for Internet Security (CIS) Top 18 Controls, including email and social media links.

Similar Podcasts