Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by David Bisson and Center for Internet Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by David Bisson and Center for Internet Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 165: An In-Depth Look at CIS Controls Implementation

51:31
 
Share
 

Manage episode 523556605 series 3382533
Content provided by David Bisson and Center for Internet Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by David Bisson and Center for Internet Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In Episode 165 of Cybersecurity Where You Are, Tony Sager sits down with Valecia Stocchetti, Senior Cybersecurity Engineer at the Center for Internet Security® (CIS®), and Charity Otwell, Director of Critical Security Controls at CIS. Together, they take an in-depth look at implementing the CIS Critical Security Controls® (CIS Controls®), including what you need to know to begin your own CIS Controls implementation efforts.

Here are some highlights from our episode:

  • 00:53. Introductions to Valecia and Charity
  • 02:48. How the CIS Controls ecosystem answers the deeper question of how to implement
  • 06:42. The importance of clear strategy, business priorities, and a realistic timeline
  • 09:56. How the CIS Community Defense Model (CDM) clarifies cyber defense priorities
  • 13:01. The use of calculations around costing to make a security program achievable
  • 15:31. Bringing IT and the Board of Directors together through governance
  • 20:36. "Herding cats" as a metaphor for navigating different compliance frameworks
  • 23:17. Why one prescriptive ask per CIS Safeguard starts cybersecurity workflows
  • 25:30. "Why" vs. "how" communication, accountability, staffing, budget, and continuous improvement as keys to success for CIS Controls implementation
  • 42:03. CIS Controls Assessment Specification as an answer to implementation subjectivity
  • 47:21. Parting thoughts around team effort, change, and CIS Controls Accreditation

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

  continue reading

165 episodes

Artwork
iconShare
 
Manage episode 523556605 series 3382533
Content provided by David Bisson and Center for Internet Security. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by David Bisson and Center for Internet Security or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In Episode 165 of Cybersecurity Where You Are, Tony Sager sits down with Valecia Stocchetti, Senior Cybersecurity Engineer at the Center for Internet Security® (CIS®), and Charity Otwell, Director of Critical Security Controls at CIS. Together, they take an in-depth look at implementing the CIS Critical Security Controls® (CIS Controls®), including what you need to know to begin your own CIS Controls implementation efforts.

Here are some highlights from our episode:

  • 00:53. Introductions to Valecia and Charity
  • 02:48. How the CIS Controls ecosystem answers the deeper question of how to implement
  • 06:42. The importance of clear strategy, business priorities, and a realistic timeline
  • 09:56. How the CIS Community Defense Model (CDM) clarifies cyber defense priorities
  • 13:01. The use of calculations around costing to make a security program achievable
  • 15:31. Bringing IT and the Board of Directors together through governance
  • 20:36. "Herding cats" as a metaphor for navigating different compliance frameworks
  • 23:17. Why one prescriptive ask per CIS Safeguard starts cybersecurity workflows
  • 25:30. "Why" vs. "how" communication, accountability, staffing, budget, and continuous improvement as keys to success for CIS Controls implementation
  • 42:03. CIS Controls Assessment Specification as an answer to implementation subjectivity
  • 47:21. Parting thoughts around team effort, change, and CIS Controls Accreditation

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

  continue reading

165 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play