Jason Edwards

Framework: The Center for Internet Security (CIS) Top 18 Controls

The **CIS Critical Security Controls Audio Course** is a comprehensive, audio-first training series that guides listeners through all eighteen **CIS Controls**, transforming one of the world’s most respected cybersecurity frameworks into clear, actionable learning. Designed for professionals, students, and auditors alike, this series explains each control in practical, plain language—focusing on how to implement, assess, and sustain them in real environments. With eighty-three structured episodes, the course walks you step by step through the safeguards that define effective cybersecurity, hel...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 18, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Welcome to the CIS 18 Control Framework 18.10.2025
Episode 82 — Safeguard 18.2 – Internal and red team exercises 18.10.2025

Safeguard 18.2 extends penetration testing to include internal assessments and red team exercises that emulate an attacker with initial access. Internal testing evaluates how far a threat could move laterally, escalate privileges, and access sensitive data once inside the network. Red team exercises simulate full-scale adversary campaigns, testing detection, containment, and response capabilities...

Episode 81 — Safeguard 18.1 – External testing programs 18.10.2025

Safeguard 18.1 requires organizations to establish and maintain a formal penetration testing program that includes recurring external assessments. External tests simulate real-world attackers operating from outside the enterprise perimeter, probing exposed systems, web applications, and cloud environments for exploitable weaknesses. Unlike automated vulnerability scans, these engagements apply hum...

Episode 80 — Overview – Why penetration testing validates defenses 18.10.2025

Control 18—Penetration Testing—closes the CIS framework by validating how well all other controls perform under real-world conditions. While vulnerability scanning identifies potential weaknesses, penetration testing goes further by exploiting them to assess the enterprise’s true exposure. These controlled attacks, conducted by skilled professionals, reveal how vulnerabilities chain together, how...

Episode 79 — Remaining safeguards summary (Control 17) 18.10.2025

The remaining safeguards in Control 17 reinforce the full lifecycle of incident response—spanning preparation, communication, testing, and continuous improvement. These include assigning key response roles, defining secure communication mechanisms, conducting post-incident reviews, and establishing thresholds that differentiate normal events from true incidents. Together, these steps ensure that t...

Episode 78 — Safeguard 17.2 – Tabletop exercises 18.10.2025

Safeguard 17.2 emphasizes the importance of testing the incident response plan through structured tabletop exercises. These simulations bring together key personnel—from technical teams to executives—to rehearse decision-making during hypothetical security events. Unlike full-scale technical drills, tabletop exercises focus on communication flow, role clarity, and coordination across departments....

Episode 77 — Safeguard 17.1 – IR plan and playbooks 18.10.2025

Safeguard 17.1 requires organizations to establish and maintain a comprehensive incident response process that defines scope, roles, responsibilities, and communication procedures. This process must include not only the technical elements of response—like containment and remediation—but also compliance reporting, legal coordination, and stakeholder communication. The plan should assign a primary i...

Episode 76 — Overview – Incident response principles 18.10.2025

Control 17—Incident Response Management—defines how an organization prepares for, detects, responds to, and learns from security incidents. Even the most robust defenses can be breached, and when that happens, success depends on disciplined, preplanned response rather than improvised reaction. The control requires formal policies, documented procedures, and assigned roles to ensure rapid coordinat...

Episode 75 — Remaining safeguards summary (Control 16) 18.10.2025

The remaining safeguards under this control expand beyond coding and testing to address the full ecosystem in which applications live. They include maintaining an inventory of third-party components (a software bill of materials), enforcing trusted and up-to-date libraries, applying secure design principles, separating production and non-production environments, leveraging vetted platform services...

Episode 74 — Safeguard 16.2 – Static and dynamic testing 18.10.2025

This safeguard advances assurance by requiring a structured process to accept and address reported vulnerabilities and by embedding testing that sees both code and behavior. Static analysis inspects source or bytecode without executing it, uncovering issues like injection points, insecure APIs, tainted data flows, or missing sanitization. Dynamic analysis executes the running application to identi...

Episode 73 — Safeguard 16.1 – Secure coding practices 18.10.2025

This safeguard directs organizations to formalize a secure application development process and set explicit standards for how code is designed, written, reviewed, and released. Secure coding practices begin with consistent patterns that remove entire classes of defects: input validation at all trust boundaries; strict output encoding; centralized, parameterized data access; safe file handling; and...

Episode 72 — Overview – Secure software lifecycle 18.10.2025

A secure software lifecycle integrates security activities into every stage of building and operating applications—planning, design, development, testing, deployment, and maintenance—so that weaknesses are prevented early and detected quickly when they occur. In this view, security is not a gate at the end of development but a set of habits and checks embedded alongside feature work. Threat modeli...

Episode 71 — Remaining safeguards summary (Control 15) 18.10.2025

The remaining safeguards in Control 15 round out a complete third-party risk program by adding structured assessment, continuous monitoring, and secure decommissioning. After building the inventory and embedding security in contracts, organizations must evaluate providers proportionally to their risk classifications, using recognized attestations such as SOC 2, PCI AoC, or ISO 27001 to reduce ques...

Episode 70 — Safeguard 15.2 – Security requirements in contracts 18.10.2025

Safeguard 15.2 ensures that contracts with service providers explicitly define security expectations and obligations, creating enforceable accountability. Every vendor relationship introduces risk, and legal agreements must formalize how those risks are managed. Security requirements within contracts should address data protection, incident notification, vulnerability disclosure, encryption standa...

Episode 69 — Safeguard 15.1 – Inventory of service providers 18.10.2025

Safeguard 15.1 requires organizations to establish and maintain a complete inventory of all service providers that store, process, or access enterprise data. This inventory must include vendor classification, assigned business owner, contact information, and review frequency. A clear, current list of service providers allows enterprises to assess cumulative risk exposure and prioritize oversight e...

Episode 68 — Overview – Third-party and vendor risks 18.10.2025

Control 15—Service Provider Management—addresses the growing reliance on third-party vendors and the risks that accompany it. In today’s interconnected ecosystems, external partners often handle sensitive data or manage critical business processes, making their security posture an extension of your own. A weak vendor can serve as an attacker’s gateway into the enterprise, as demonstrated by numero...

Episode 67 — Remaining safeguards summary (Control 14) 18.10.2025

The remaining safeguards under Control 14 extend awareness beyond general staff by emphasizing continuous reinforcement, contextual learning, and cultural integration. They include training employees to recognize and report missing updates, understand risks of insecure networks, and conduct role-specific awareness sessions. Each safeguard strengthens the organization’s ability to identify, report,...

Episode 66 — Safeguard 14.3 – Role-based training for admins and developers 18.10.2025

Safeguard 14.3 focuses on providing targeted, role-based training to employees whose responsibilities involve elevated privileges or specialized technical duties—such as system administrators, developers, and IT support staff. These roles have direct influence over critical systems and data, making them prime targets for attackers. Role-specific training ensures that individuals understand both ge...

Episode 65 — Safeguard 14.2 – Phishing simulations 18.10.2025

Safeguard 14.2 emphasizes the use of phishing simulations to test, measure, and improve employee awareness of social engineering attacks. Phishing remains the most prevalent method for initial compromise, exploiting human curiosity, urgency, or trust. Simulated phishing exercises expose employees to realistic scenarios in a controlled environment, allowing them to practice identifying and reportin...

Episode 64 — Safeguard 14.1 – Security awareness program 18.10.2025

Safeguard 14.1 requires organizations to establish and maintain a formal security awareness program that educates the workforce on secure behaviors and threat recognition. The program should define clear objectives, training frequency, and content scope. Awareness efforts must extend beyond one-time videos or checklists, evolving into continuous engagement that reinforces the importance of cyberse...

Episode 63 — Overview – Human factor in cyber defense 18.10.2025

Control 14—Security Awareness and Skills Training—addresses the most variable element in cybersecurity: human behavior. Technology can block many attacks, but user actions often determine whether defenses hold or fail. This control ensures that employees understand the threats they face and know how to respond appropriately. Effective awareness programs transform users from potential vulnerabiliti...

Episode 62 — Remaining safeguards summary (Control 13) 18.10.2025

The remaining safeguards under Control 13 enhance monitoring precision, response efficiency, and overall situational awareness. They include collecting network traffic flow logs, enforcing port-level access control, and tuning alert thresholds regularly. Collecting flow logs provides visibility into data movement and communication patterns, supporting both security analysis and capacity planning....

Episode 61 — Safeguard 13.3 – Anomaly detection 18.10.2025

Safeguard 13.3 focuses on detecting anomalies within network activity that may signal emerging threats or compromised systems. Traditional defenses rely on predefined signatures, but anomaly detection analyzes behavioral patterns—such as unexpected traffic spikes, irregular data transfers, or unusual login times—to identify suspicious deviations from normal operations. These systems use statistica...

Episode 60 — Safeguard 13.2 – Segmentation and filtering 18.10.2025

Safeguard 13.2 extends the principle of defense in depth by enforcing traffic segmentation and filtering between network zones. The goal is to limit unnecessary communication paths so that even if one area is compromised, attackers cannot easily move laterally. Segmentation divides the network into distinct trust zones—such as production, development, and user environments—while filtering defines...

Episode 59 — Safeguard 13.1 – Intrusion detection and prevention 18.10.2025

Safeguard 13.1 requires organizations to centralize security event alerting and deploy systems that can detect and, when appropriate, block malicious activity across enterprise networks and endpoints. Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) play complementary roles: IDS monitors traffic for suspicious behavior and generates alerts, while IPS actively blocks or quar...

Listen to the Framework: The Center for Internet Security (CIS) Top 18 Controls podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.