#
Title
1

Welcome to the CIS 18 Control Framework

2

Episode 82 — Safeguard 18.2 – Internal and red team exercises

3

Episode 81 — Safeguard 18.1 – External testing programs

4

Episode 80 — Overview – Why penetration testing validates defenses

5

Episode 79 — Remaining safeguards summary (Control 17)

6

Episode 78 — Safeguard 17.2 – Tabletop exercises

7

Episode 77 — Safeguard 17.1 – IR plan and playbooks

8

Episode 76 — Overview – Incident response principles

9

Episode 75 — Remaining safeguards summary (Control 16)

10

Episode 74 — Safeguard 16.2 – Static and dynamic testing

11

Episode 73 — Safeguard 16.1 – Secure coding practices

12

Episode 72 — Overview – Secure software lifecycle

13

Episode 71 — Remaining safeguards summary (Control 15)

14

Episode 70 — Safeguard 15.2 – Security requirements in contracts

15

Episode 69 — Safeguard 15.1 – Inventory of service providers

16

Episode 68 — Overview – Third-party and vendor risks

17

Episode 67 — Remaining safeguards summary (Control 14)

18

Episode 66 — Safeguard 14.3 – Role-based training for admins and developers

19

Episode 65 — Safeguard 14.2 – Phishing simulations

20

Episode 64 — Safeguard 14.1 – Security awareness program

21

Episode 63 — Overview – Human factor in cyber defense

22

Episode 62 — Remaining safeguards summary (Control 13)

23

Episode 61 — Safeguard 13.3 – Anomaly detection

24

Episode 60 — Safeguard 13.2 – Segmentation and filtering

25

Episode 59 — Safeguard 13.1 – Intrusion detection and prevention

26

Episode 58 — Overview – Monitoring as the nervous system

27

Episode 57 — Remaining safeguards summary (Control 12)

28

Episode 56 — Safeguard 12.3 – Remove legacy and unused devices

29

Episode 55 — Safeguard 12.2 – Secure and configure devices

30

Episode 54 — Safeguard 12.1 – Maintain network diagrams

31

Episode 53 — Overview – Network devices and hygiene

32

Episode 52 — Remaining safeguards summary (Control 11)

33

Episode 51 — Safeguard 11.2 – Testing data recovery

34

Episode 50 — Safeguard 11.1 – Backup process design

35

Episode 49 — Overview – Planning for inevitable failures

36

Episode 48 — Remaining safeguards summary (Control 10)

37

Episode 47 — Safeguard 10.2 – Endpoint detection and response (EDR)

38

Episode 46 — Safeguard 10.1 – Anti-malware solutions

39

Episode 45 — Overview – Malware threats and defenses

40

Episode 44 — Remaining safeguards summary (Control 9)

41

Episode 43 — Safeguard 9.2 – Browser configuration and isolation

42

Episode 42 — Safeguard 9.1 – Spam and phishing defenses

43

Episode 41 — Overview – Email and browser as attack vectors

44

Episode 40 — Remaining safeguards summary (Control 8)

45

Episode 39 — Safeguard 8.2 – Centralized log collection and SIEM

46

Episode 38 — Safeguard 8.1 – Enable audit logging

47

Episode 37 — Overview – Logs as the backbone of detection

48

Episode 36 — Remaining safeguards summary (Control 7)

49

Episode 35 — Safeguard 7.3 – Integration with patch management

50

Episode 34 — Safeguard 7.2 – Remediation timelines and SLAs

51

Episode 33 — Safeguard 7.1 – Vulnerability scanning tools

52

Episode 32 — Overview – Why vulnerability management is continuous

53

Episode 31 — Remaining safeguards summary (Control 6)

54

Episode 30 — Safeguard 6.2 – Role-based access control (RBAC)

55

Episode 29 — Safeguard 6.1 – Access authorization processes

56

Episode 28 — Overview – Principles of least privilege

57

Episode 27 — Remaining safeguards summary (Control 5)

58

Episode 26 — Safeguard 5.3 – Disable dormant accounts

59

Episode 25 — Safeguard 5.2 – Centralized account management

60

Episode 24 — Safeguard 5.1 – Inventory of accounts

61

Episode 23 — Overview – Managing identity and accounts

62

Episode 22 — Remaining safeguards summary (Control 4)

63

Episode 21 — Safeguard 4.2 – Automated configuration management

64

Episode 20 — Safeguard 4.1 – Establish secure configuration baselines

65

Episode 19 — Overview – Why secure configs matter

66

Episode 18 — Remaining safeguards summary (Control 3)

67

Episode 17 — Safeguard 3.3 – Data encryption at rest and in transit

68

Episode 16 — Safeguard 3.2 – Data retention and disposal

69

Episode 15 — Safeguard 3.1 – Data classification and inventory

70

Episode 14 — Overview – Protecting sensitive data

71

Episode 13 — Remaining safeguards summary (Control 2)

72

Episode 12 — Safeguard 2.2 – Only allow authorized software

73

Episode 11 — Safeguard 2.1 – Maintain a software inventory

74

Episode 10 — Overview – Managing the software landscape

75

Episode 9 — Remaining safeguards summary (Control 1)

76

Episode 8 — Safeguard 1.2 – Address unauthorized assets

77

Episode 7 — Safeguard 1.1 – Inventory of assets

78

Episode 6 — Overview – Why asset management is foundational

79

Episode 5 — Glossary of common cybersecurity terms

80

Episode 4 — Glossary of common cybersecurity terms

81

Episode 3 — What is a “control” and what is a “safeguard”?

82

Episode 2 — How to use CIS 18 in your organization

83

Episode 1 — What are the CIS Critical Security Controls?