All Episodes
Framework: The Center for Internet Security (CIS) Top 18 Controls — 83 episodes
Welcome to the CIS 18 Control Framework
Episode 82 — Safeguard 18.2 – Internal and red team exercises
Episode 81 — Safeguard 18.1 – External testing programs
Episode 80 — Overview – Why penetration testing validates defenses
Episode 79 — Remaining safeguards summary (Control 17)
Episode 78 — Safeguard 17.2 – Tabletop exercises
Episode 77 — Safeguard 17.1 – IR plan and playbooks
Episode 76 — Overview – Incident response principles
Episode 75 — Remaining safeguards summary (Control 16)
Episode 74 — Safeguard 16.2 – Static and dynamic testing
Episode 73 — Safeguard 16.1 – Secure coding practices
Episode 72 — Overview – Secure software lifecycle
Episode 71 — Remaining safeguards summary (Control 15)
Episode 70 — Safeguard 15.2 – Security requirements in contracts
Episode 69 — Safeguard 15.1 – Inventory of service providers
Episode 68 — Overview – Third-party and vendor risks
Episode 67 — Remaining safeguards summary (Control 14)
Episode 66 — Safeguard 14.3 – Role-based training for admins and developers
Episode 65 — Safeguard 14.2 – Phishing simulations
Episode 64 — Safeguard 14.1 – Security awareness program
Episode 63 — Overview – Human factor in cyber defense
Episode 62 — Remaining safeguards summary (Control 13)
Episode 61 — Safeguard 13.3 – Anomaly detection
Episode 60 — Safeguard 13.2 – Segmentation and filtering
Episode 59 — Safeguard 13.1 – Intrusion detection and prevention
Episode 58 — Overview – Monitoring as the nervous system
Episode 57 — Remaining safeguards summary (Control 12)
Episode 56 — Safeguard 12.3 – Remove legacy and unused devices
Episode 55 — Safeguard 12.2 – Secure and configure devices
Episode 54 — Safeguard 12.1 – Maintain network diagrams
Episode 53 — Overview – Network devices and hygiene
Episode 52 — Remaining safeguards summary (Control 11)
Episode 51 — Safeguard 11.2 – Testing data recovery
Episode 50 — Safeguard 11.1 – Backup process design
Episode 49 — Overview – Planning for inevitable failures
Episode 48 — Remaining safeguards summary (Control 10)
Episode 47 — Safeguard 10.2 – Endpoint detection and response (EDR)
Episode 46 — Safeguard 10.1 – Anti-malware solutions
Episode 45 — Overview – Malware threats and defenses
Episode 44 — Remaining safeguards summary (Control 9)
Episode 43 — Safeguard 9.2 – Browser configuration and isolation
Episode 42 — Safeguard 9.1 – Spam and phishing defenses
Episode 41 — Overview – Email and browser as attack vectors
Episode 40 — Remaining safeguards summary (Control 8)
Episode 39 — Safeguard 8.2 – Centralized log collection and SIEM
Episode 38 — Safeguard 8.1 – Enable audit logging
Episode 37 — Overview – Logs as the backbone of detection
Episode 36 — Remaining safeguards summary (Control 7)
Episode 35 — Safeguard 7.3 – Integration with patch management
Episode 34 — Safeguard 7.2 – Remediation timelines and SLAs
Episode 33 — Safeguard 7.1 – Vulnerability scanning tools
Episode 32 — Overview – Why vulnerability management is continuous
Episode 31 — Remaining safeguards summary (Control 6)
Episode 30 — Safeguard 6.2 – Role-based access control (RBAC)
Episode 29 — Safeguard 6.1 – Access authorization processes
Episode 28 — Overview – Principles of least privilege
Episode 27 — Remaining safeguards summary (Control 5)
Episode 26 — Safeguard 5.3 – Disable dormant accounts
Episode 25 — Safeguard 5.2 – Centralized account management
Episode 24 — Safeguard 5.1 – Inventory of accounts
Episode 23 — Overview – Managing identity and accounts
Episode 22 — Remaining safeguards summary (Control 4)
Episode 21 — Safeguard 4.2 – Automated configuration management
Episode 20 — Safeguard 4.1 – Establish secure configuration baselines
Episode 19 — Overview – Why secure configs matter
Episode 18 — Remaining safeguards summary (Control 3)
Episode 17 — Safeguard 3.3 – Data encryption at rest and in transit
Episode 16 — Safeguard 3.2 – Data retention and disposal
Episode 15 — Safeguard 3.1 – Data classification and inventory
Episode 14 — Overview – Protecting sensitive data
Episode 13 — Remaining safeguards summary (Control 2)
Episode 12 — Safeguard 2.2 – Only allow authorized software
Episode 11 — Safeguard 2.1 – Maintain a software inventory
Episode 10 — Overview – Managing the software landscape
Episode 9 — Remaining safeguards summary (Control 1)
Episode 8 — Safeguard 1.2 – Address unauthorized assets
Episode 7 — Safeguard 1.1 – Inventory of assets
Episode 6 — Overview – Why asset management is foundational
Episode 5 — Glossary of common cybersecurity terms
Episode 4 — Glossary of common cybersecurity terms
Episode 3 — What is a “control” and what is a “safeguard”?
Episode 2 — How to use CIS 18 in your organization
Episode 1 — What are the CIS Critical Security Controls?