Companion-course connectionCIS Critical Security Controls
The CIS Controls provide a prioritized set of safeguards that organizations can use to improve defensive capability and reduce common attack paths.
Open article →Companion-course connectionCIS Controls Crosswalks
CIS Controls crosswalks map safeguards to requirements or outcomes in other frameworks so organizations can reuse evidence and understand overlapping intent.
Open article →Companion-course connectionCIS Controls Implementation Groups
CIS Controls Implementation Groups organize safeguards into prioritized sets that reflect organizational resources, complexity, data sensitivity, and threat exposure.
Open article →Companion-course connectionAI Deployment Approval Gates
AI deployment approval gates require defined evidence and accountable authorization before models or AI-enabled features advance into higher-risk environments.
Open article →Companion-course connectionAsset Inventory Quality
Asset inventory quality evaluates completeness, accuracy, freshness, ownership, classification, and reconciliation across the systems that produce inventory data.
Open article →Companion-course connectionConfiguration Baseline Enforcement
Configuration baseline enforcement ensures systems remain within approved security and operational settings or have documented, time-bounded exceptions.
Open article →Companion-course connectionConfiguration Compliance Validation
Configuration compliance validation compares live settings against approved baselines and verifies that findings are corrected or explicitly accepted.
Open article →Companion-course connectionModel Risk Management
Model risk management establishes governance for selecting, approving, using, changing, challenging, and retiring models according to their impact and uncertainty.
Open article →Companion-course connectionPrivacy Audit Evidence Management
Privacy audit evidence management preserves relevant, reliable, traceable, and access-controlled records so an independent reviewer can reconstruct what a control did and when.
Open article →Companion-course connectionSecurity Baselines
A security baseline defines the minimum approved configuration and protection level for a class of systems, services, accounts, or devices.
Open article →Companion-course connectionUnauthorized Software Management
Unauthorized software management identifies, evaluates, removes, blocks, or formally approves software that is not permitted for the device or environment.
Open article →Companion-course connectionVulnerability Remediation Validation
Vulnerability remediation validation confirms that the weakness is actually removed or reduced, the correct asset was changed, and the fix did not create unacceptable side effects.
Open article →