Jason Edwards
Framework: The Center for Internet Security (CIS) Top 18 Controls
The **CIS Critical Security Controls Audio Course** is a comprehensive, audio-first training series that guides listeners through all eighteen **CIS Controls**, transforming one of the world’s most respected cybersecurity frameworks into clear, actionable learning. Designed for professionals, students, and auditors alike, this series explains each control in practical, plain language—focusing on how to implement, assess, and sustain them in real environments. With eighty-three structured episodes, the course walks you step by step through the safeguards that define effective cybersecurity, hel...
Author
Jason Edwards
Category
Podcast website
Latest episode
Oct 18, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 33 — Safeguard 7.1 – Vulnerability scanning tools 18.10.2025 10:20
Safeguard 7.1 calls for organizations to establish and maintain a documented vulnerability management process supported by automated scanning tools. These tools form the technical backbone of the program, identifying security weaknesses across operating systems, applications, and network devices. Effective scanners leverage standardized frameworks like Common Vulnerabilities and Exposures (CVE) an...
Episode 32 — Overview – Why vulnerability management is continuous 18.10.2025 10:08
Control 7—Continuous Vulnerability Management—recognizes that no system remains secure indefinitely. Software evolves, new exploits emerge, and configurations drift over time. This control establishes the need for ongoing assessment, remediation, and verification to identify and correct vulnerabilities before attackers can exploit them. Unlike one-time scans or periodic audits, continuous vulnerab...
Episode 31 — Remaining safeguards summary (Control 6) 18.10.2025 11:00
The remaining safeguards under Control 6 complete the access control lifecycle by ensuring that privileges are continuously monitored, validated, and revoked when no longer required. These safeguards emphasize processes for deprovisioning accounts, enforcing Multi-Factor Authentication (MFA), and maintaining centralized authorization systems. Together, they ensure that identity and access manageme...
Episode 30 — Safeguard 6.2 – Role-based access control (RBAC) 18.10.2025 10:15
Safeguard 6.2 formalizes the implementation of Role-Based Access Control, or RBAC, which assigns permissions to predefined roles rather than individual users. This model enforces consistency, scalability, and least privilege across the enterprise. In RBAC, roles correspond to job functions—such as “HR analyst,” “database administrator,” or “developer”—and each role carries a specific set of permis...
Episode 29 — Safeguard 6.1 – Access authorization processes 18.10.2025 9:09
Safeguard 6.1 requires organizations to establish standardized, auditable processes for granting access to enterprise assets. Each new user, contractor, or service account must go through a formal authorization workflow that verifies identity, validates need, and documents approval. This process ensures that access is not granted informally or through personal discretion, which can lead to privile...
Episode 28 — Overview – Principles of least privilege 18.10.2025 11:07
Control 6 introduces the principle of least privilege, a core tenet of cybersecurity that restricts user and system access to only the permissions necessary for performing assigned tasks. This control moves beyond account creation to govern how those accounts are authorized to interact with enterprise assets and data. Over-privileged accounts are one of the most common and dangerous weaknesses in...
Episode 27 — Remaining safeguards summary (Control 5) 18.10.2025 10:38
The remaining safeguards in Control 5 complete the account management lifecycle by focusing on administrative segregation, service account oversight, and centralized control. Safeguard 5.4 mandates that administrative privileges be restricted to dedicated administrator accounts separate from normal user profiles. This prevents the compromise of personal credentials from granting excessive access....
Episode 26 — Safeguard 5.3 – Disable dormant accounts 18.10.2025 10:36
Safeguard 5.3 requires organizations to detect and disable dormant accounts—user identities that have not been used for an extended period, typically forty-five days or more. Dormant accounts are among the most overlooked attack vectors in enterprise environments. When active but unused, they retain system access rights and credentials that can be exploited by adversaries without immediate detecti...
Episode 25 — Safeguard 5.2 – Centralized account management 18.10.2025 8:47
Safeguard 5.2 emphasizes consolidating account administration through centralized identity services rather than isolated, system-specific credentials. Fragmented account management increases complexity, weakens control, and introduces inconsistencies in password enforcement and deactivation procedures. By centralizing authentication and authorization through a directory service or Identity and Acc...
Episode 24 — Safeguard 5.1 – Inventory of accounts 18.10.2025 9:20
Safeguard 5.1 requires organizations to maintain a comprehensive, accurate inventory of all accounts managed within the enterprise, covering user, administrator, and service identities. Each entry in the inventory should document key details such as the account holder’s name, role, department, creation date, and status. This visibility enables quick identification of unauthorized or dormant accoun...
Episode 23 — Overview – Managing identity and accounts 18.10.2025 9:29
Control 5, Account Management, addresses one of cybersecurity’s most exploited weaknesses—mismanaged credentials. Attackers often gain entry not through advanced exploits but through valid usernames and passwords left unprotected or unused. This control ensures that enterprises create, maintain, and monitor accounts responsibly across their lifecycle. It establishes clear processes for provisionin...
Episode 22 — Remaining safeguards summary (Control 4) 18.10.2025 9:40
The remaining safeguards under Control 4 extend the secure configuration principle into everyday system operation, ensuring that protections remain active and measurable. They include requirements for implementing host-based and network firewalls, managing default accounts, disabling unnecessary services, enforcing session locks, and maintaining secure management protocols. Together, these measure...
Episode 21 — Safeguard 4.2 – Automated configuration management 18.10.2025 9:46
Safeguard 4.2 builds upon the secure baseline concept by emphasizing automation as the means to enforce and maintain configurations consistently. Manual configuration is error-prone, slow, and unsustainable at enterprise scale, particularly in hybrid and cloud environments where systems are provisioned and decommissioned daily. Automation eliminates human drift by ensuring that every deployed asse...
Episode 20 — Safeguard 4.1 – Establish secure configuration baselines 18.10.2025 10:31
Safeguard 4.1 requires organizations to establish and maintain formal, secure configuration processes for all enterprise assets and software. This means defining standard settings that enforce the principles of least functionality and defense in depth. Each configuration baseline should specify security parameters such as user permissions, network services, authentication methods, and encryption r...
Episode 19 — Overview – Why secure configs matter 18.10.2025 9:37
Secure configuration management forms the backbone of system hardening and operational stability. Control 4—Secure Configuration of Enterprise Assets and Software—addresses the risks associated with default settings, open services, and weak baseline security. Out-of-the-box configurations prioritize usability and convenience rather than protection, often leaving unnecessary features enabled or out...
Episode 18 — Remaining safeguards summary (Control 3) 18.10.2025 10:18
The remaining safeguards under Control 3 extend data protection across its entire lifecycle, ensuring that sensitive information is both managed and monitored. These include establishing clear ownership of data, documenting data flows, segmenting storage environments by sensitivity, and deploying Data Loss Prevention (DLP) solutions. Data ownership assigns accountability—every dataset has a custod...
Episode 17 — Safeguard 3.3 – Data encryption at rest and in transit 18.10.2025 10:12
Safeguard 3.3 requires organizations to protect sensitive data through encryption, both when stored (at rest) and when moving across networks (in transit). Encryption transforms readable information into an unreadable form using cryptographic algorithms, ensuring that even if data is intercepted or stolen, it cannot be easily exploited. Encrypting data at rest protects information stored on server...
Episode 16 — Safeguard 3.2 – Data retention and disposal 18.10.2025 10:10
Safeguard 3.2 ensures that organizations implement structured, defensible practices for retaining and disposing of data. Every enterprise accumulates vast amounts of information—some vital for business continuity, and some obsolete or redundant. Retaining data indefinitely increases both storage costs and security exposure. Attackers often exploit forgotten archives and unsecured backups because t...
Episode 15 — Safeguard 3.1 – Data classification and inventory 18.10.2025 8:55
Safeguard 3.1 instructs organizations to establish and maintain a structured data management process, beginning with classification and inventory. This process determines what data exists, where it resides, who owns it, and how sensitive it is. Classification typically categorizes information as public, internal, confidential, or restricted, though labels may vary depending on industry or regulati...
Episode 14 — Overview – Protecting sensitive data 18.10.2025 8:33
Data protection is the third pillar of the CIS Controls, and it addresses one of the most critical aspects of cybersecurity: safeguarding the organization’s most valuable asset—its information. Control 3 emphasizes the need to identify, classify, and secure data throughout its entire lifecycle, from creation to destruction. Unlike purely technical controls, data protection requires coordination ac...
Episode 13 — Remaining safeguards summary (Control 2) 18.10.2025 8:36
The remaining safeguards under Control 2 emphasize automation, enforcement, and continuous verification of software integrity. Safeguards 2.3 through 2.7 outline the operational lifecycle for managing software once the inventory and authorization baselines are established. They include removing or documenting exceptions for unauthorized software, using automated tools to detect installations, and...
Episode 12 — Safeguard 2.2 – Only allow authorized software 18.10.2025 9:43
Safeguard 2.2 builds on inventory management by enforcing the principle that only approved and supported software should exist within the enterprise environment. Unauthorized or unmaintained applications can become significant liabilities, often introducing unpatched vulnerabilities or violating licensing and compliance obligations. This safeguard requires organizations to classify all software as...
Episode 11 — Safeguard 2.1 – Maintain a software inventory 18.10.2025 9:23
Safeguard 2.1 focuses on creating and maintaining a detailed, authoritative inventory of all software within an organization’s environment. This includes operating systems, applications, utilities, and any other programs capable of executing code or processing data. Each software entry should record its title, publisher, version, installation date, business purpose, and deployment mechanism. The i...
Episode 10 — Overview – Managing the software landscape 18.10.2025 8:57
Just as organizations must maintain visibility into their hardware, they must also control the software that runs on it. Control 2 of the CIS framework—Inventory and Control of Software Assets—addresses the risks introduced by unauthorized, outdated, or vulnerable applications. Every piece of software represents potential entry points for attackers, whether through unpatched flaws or malicious cod...
Episode 9 — Remaining safeguards summary (Control 1) 18.10.2025 9:54
The remaining safeguards under Control 1 build upon the foundation of asset inventory and unauthorized asset management by introducing proactive detection and continuous monitoring techniques. Safeguards 1.3 through 1.5 recommend using a combination of active, passive, and DHCP-based discovery methods to maintain a real-time view of connected assets. Active discovery tools periodically probe the n...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.