Jason Edwards

Framework: The Center for Internet Security (CIS) Top 18 Controls

The **CIS Critical Security Controls Audio Course** is a comprehensive, audio-first training series that guides listeners through all eighteen **CIS Controls**, transforming one of the world’s most respected cybersecurity frameworks into clear, actionable learning. Designed for professionals, students, and auditors alike, this series explains each control in practical, plain language—focusing on how to implement, assess, and sustain them in real environments. With eighty-three structured episodes, the course walks you step by step through the safeguards that define effective cybersecurity, hel...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 18, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 58 — Overview – Monitoring as the nervous system 18.10.2025

Control 13—Network Monitoring and Defense—represents the organization’s sensory system for detecting, analyzing, and responding to cyber threats. Even the best preventive controls can fail, making continuous monitoring essential for timely detection and containment. This control requires enterprises to collect and analyze network telemetry to identify anomalies, intrusions, and suspicious behavior...

Episode 57 — Remaining safeguards summary (Control 12) 18.10.2025

The remaining safeguards under Control 12 reinforce disciplined management of network infrastructure by combining secure management, centralized authentication, and dedicated administrative environments. They require enforcing secure network protocols such as SSH and HTTPS, centralizing authentication through AAA (Authentication, Authorization, and Accounting) services, and establishing separate s...

Episode 56 — Safeguard 12.3 – Remove legacy and unused devices 18.10.2025

Safeguard 12.3 requires organizations to identify, isolate, and remove legacy or unused network devices that no longer serve operational or security purposes. Outdated hardware and abandoned configurations pose a hidden but significant risk—they often lack vendor support, remain unpatched, and may still provide active network connections that attackers can exploit. These devices can also create bo...

Episode 55 — Safeguard 12.2 – Secure and configure devices 18.10.2025

Safeguard 12.2 focuses on the secure configuration and segmentation of network infrastructure, ensuring that devices operate within controlled, least-privilege boundaries. Secure network architecture begins with clear separation between critical and general-purpose segments—isolating administrative networks, production systems, and user environments to limit lateral movement. The safeguard also ma...

Episode 54 — Safeguard 12.1 – Maintain network diagrams 18.10.2025

Safeguard 12.1 requires organizations to establish and maintain accurate network architecture diagrams, ensuring complete visibility of how assets and data connect across the enterprise. These diagrams should depict physical, virtual, and cloud components, including routers, switches, firewalls, wireless access points, and external service connections. By visualizing these relationships, administr...

Episode 53 — Overview – Network devices and hygiene 18.10.2025

Control 12—Network Infrastructure Management—ensures that the systems responsible for connecting, routing, and protecting enterprise communications are securely configured, maintained, and monitored. Network infrastructure includes routers, switches, firewalls, wireless access points, and virtual gateways—components that form the backbone of connectivity and data flow. Because these devices sit at...

Episode 52 — Remaining safeguards summary (Control 11) 18.10.2025

The remaining safeguards within Control 11 establish a comprehensive framework for secure, reliable data recovery. They include protecting recovery data with equivalent security controls as production data, maintaining an isolated instance of backups, and ensuring encryption and access control mechanisms safeguard stored copies. These measures guarantee that recovery repositories themselves do not...

Episode 51 — Safeguard 11.2 – Testing data recovery 18.10.2025

Safeguard 11.2 requires organizations to test their data recovery capabilities on a regular basis, validating that backup systems and restoration procedures function as intended. Backups only hold value if they can be successfully restored when needed. Testing confirms data integrity, verifies procedural accuracy, and reveals gaps in both technology and human readiness. The safeguard calls for qua...

Episode 50 — Safeguard 11.1 – Backup process design 18.10.2025

Safeguard 11.1 directs organizations to establish and maintain a documented data recovery process that defines how, where, and when critical information is backed up. The process must specify scope, recovery priorities, and the security of backup data. It also outlines responsibilities, schedules, and verification procedures. Automated backup solutions ensure that important data is captured regula...

Episode 49 — Overview – Planning for inevitable failures 18.10.2025

Control 11—Data Recovery—acknowledges an unavoidable truth in cybersecurity: failures, whether caused by attacks, accidents, or system errors, are inevitable. The focus of this control is to ensure that organizations can restore critical assets and operations to a trusted state after an incident. Recovery is not only about backup copies; it is about the ability to rebuild functionality and confide...

Episode 48 — Remaining safeguards summary (Control 10) 18.10.2025

The remaining safeguards under Control 10 reinforce malware defense through layered, automated protection and proactive monitoring. These include automatic signature updates, disabling autorun and autoplay on removable media, scanning all external storage upon connection, enabling anti-exploitation features, and centralizing anti-malware management. Each measure addresses a different stage of the...

Episode 47 — Safeguard 10.2 – Endpoint detection and response (EDR) 18.10.2025

Safeguard 10.2 expands traditional anti-malware defenses by introducing Endpoint Detection and Response (EDR)—a technology designed to detect, analyze, and contain threats that bypass signature-based systems. EDR platforms monitor endpoint behavior in real time, capturing telemetry such as process creation, registry changes, and network connections. This data enables security analysts to identify...

Episode 46 — Safeguard 10.1 – Anti-malware solutions 18.10.2025

Safeguard 10.1 directs organizations to deploy and maintain anti-malware software on all enterprise assets to provide a frontline defense against malicious code. This includes endpoints, servers, and mobile devices that connect to corporate networks. Anti-malware solutions serve as the first detection and containment layer against viruses, ransomware, and spyware, inspecting files and processes fo...

Episode 45 — Overview – Malware threats and defenses 18.10.2025

Control 10—Malware Defenses—addresses the ongoing challenge of detecting, preventing, and mitigating malicious code across the enterprise. Malware encompasses a broad spectrum of threats, including viruses, Trojans, ransomware, and fileless attacks that exploit legitimate processes. These threats evolve continuously, often leveraging automation, obfuscation, and artificial intelligence to evade de...

Episode 44 — Remaining safeguards summary (Control 9) 18.10.2025

The remaining safeguards under Control 9 expand email and web browser protection into a comprehensive strategy against social engineering and content-based attacks. They include implementing DNS filtering services, maintaining URL filters, restricting unauthorized extensions, deploying DMARC authentication, blocking unnecessary file types, and maintaining email server anti-malware defenses. Each o...

Episode 43 — Safeguard 9.2 – Browser configuration and isolation 18.10.2025

Safeguard 9.2 focuses on securing web browsers—the most widely used and simultaneously most exposed application within any organization. Because browsers connect directly to external content, they are frequent delivery channels for malware, malicious scripts, and credential theft. This safeguard mandates the use of fully supported browsers with current security updates and the implementation of co...

Episode 42 — Safeguard 9.1 – Spam and phishing defenses 18.10.2025

Safeguard 9.1 requires organizations to ensure that only fully supported and up-to-date email clients are used and that layered spam and phishing defenses are in place. Attackers frequently exploit vulnerabilities in outdated email clients or manipulate users through convincing phishing campaigns that mimic trusted entities. To counter this, enterprises must combine technical controls with user aw...

Episode 41 — Overview – Email and browser as attack vectors 18.10.2025

Control 9—Email and Web Browser Protections—targets the entry points most frequently exploited by attackers: users’ inboxes and browsers. These applications are gateways between trusted internal systems and the untrusted external world. Malicious links, attachments, and scripts routinely bypass basic defenses by exploiting human behavior rather than technical vulnerabilities. Phishing remains the...

Episode 40 — Remaining safeguards summary (Control 8) 18.10.2025

The remaining safeguards under Control 8 expand audit logging into a fully mature detection capability that supports real-time defense, forensic analysis, and compliance reporting. Safeguards 8.3 through 8.12 include maintaining adequate log storage, synchronizing system clocks, logging detailed user activities, and collecting specialized records such as DNS, URL, and command-line logs. They also...

Episode 39 — Safeguard 8.2 – Centralized log collection and SIEM 18.10.2025

Safeguard 8.2 builds upon basic log activation by requiring centralized log collection and correlation through Security Information and Event Management (SIEM) or equivalent platforms. Centralization solves one of the biggest challenges in security operations—fragmentation. When logs remain dispersed across servers, applications, and network devices, it is nearly impossible to detect complex attac...

Episode 38 — Safeguard 8.1 – Enable audit logging 18.10.2025

Safeguard 8.1 requires organizations to establish and maintain a documented process for audit log management, defining the collection, review, and retention of event data across enterprise assets. This safeguard ensures that every system capable of generating logs has logging features enabled and configured according to policy. Logging should capture significant security events such as authenticat...

Episode 37 — Overview – Logs as the backbone of detection 18.10.2025

Control 8—Audit Log Management—focuses on one of the most essential yet underutilized capabilities in cybersecurity: the power of audit logs. Logs are the digital footprints of system activity, recording events such as logins, file access, configuration changes, and network connections. When properly collected, analyzed, and retained, they provide the evidence needed to detect, investigate, and re...

Episode 36 — Remaining safeguards summary (Control 7) 18.10.2025

The remaining safeguards under Control 7 complete the vulnerability management cycle by ensuring that discovery, remediation, and verification operate as an ongoing, measurable process. Safeguards 7.4 through 7.7 require enterprises to automate both operating system and application patching, perform internal and external vulnerability scans, and validate remediation results. These steps close the...

Episode 35 — Safeguard 7.3 – Integration with patch management 18.10.2025

Safeguard 7.3 connects vulnerability management directly to patch management, ensuring that identified issues lead to timely, verifiable fixes. Vulnerability scanning without patching creates awareness but not improvement; patching without visibility risks misalignment and wasted effort. By integrating the two, enterprises establish a closed feedback loop where discovered vulnerabilities trigger a...

Episode 34 — Safeguard 7.2 – Remediation timelines and SLAs 18.10.2025

Safeguard 7.2 establishes the requirement for formal remediation timelines, often codified as Service Level Agreements (SLAs), to ensure that identified vulnerabilities are addressed promptly and consistently. Without clear deadlines, patching and remediation can slip behind operational priorities, leaving systems exposed for extended periods. This safeguard mandates defining risk-based timeframes...

Listen to the Framework: The Center for Internet Security (CIS) Top 18 Controls podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.