Cybersecurity Where You Are (video)

Episode 156: How CIS Uses CIS Products and Services


Listen Later

In episode 156 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Stephanie Gass, Sr. Director of Information Security at Center for Internet Security® (CIS®), and Angelo Marcotullio, Chief Information Officer at CIS. Together, they explore how CIS practices what it preaches by using CIS products and services internally, which includes implementation of the CIS Critical Security Controls® (CIS Controls®) and CIS Benchmarks®, automation, and alignment to compliance frameworks. Their discussion highlights how CIS builds a strong cybersecurity foundation while adapting to evolving threats and regulatory requirements.

The conversation dives into practical applications, cultural alignment, and the importance of repeatable processes for scaling security across new products and services. It also touches on the role of privacy regulations, cyber risk quantification, and the community-driven approach that underpins CIS best practices. Here are some highlights from our episode:

  • 01:12. Why CIS “drinks its own champagne” when it comes to cybersecurity
  • 02:56. Three ways the CIS Controls help modern enterprises defend against threat actors
  • 04:02. The importance of pulling together security lessons learned in a way that's translatable
  • 10:03. Our use of the CIS Controls to align to SOC 2, ISO 27001, and other frameworks
  • 12:01. How governance, risk, and compliance (GRC) engineering works with automation to help build repeatable processes
  • 22:43. The role of collaboration and communication in building a cybersecurity program
  • 27:17. Privacy regulations as a catalyst for security innovation
  • 30:24. The CIS Community Defense Model and evidence-based practices
  • 32:40. How CIS leverages lessons learned to improve our security best practices

Resources

  • Episode 146: What Security Looks Like for a Security Company
  • Implementation Guide for Small and Medium-Sized Enterprises CIS Controls IG1
  • How to Construct a Sustainable GRC Program in 8 Steps
  • Mapping and Compliance with the CIS Controls
  • CIS Completes SOC 2 Type II Audit Using CIS Best Practices
  • Episode 74: The Nexus of Cybersecurity & Privacy Legislation
  • CIS Community Defense Model 2.0
  • Episode 121: The Economics of Cybersecurity Decision-Making
  • Episode 77: Data's Value to Decision-Making in Cybersecurity
  • CIS Communities

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

...more
View all episodesView all episodes
Download on the App Store

Cybersecurity Where You Are (video)By Center for Internet Security

  • 5
  • 5
  • 5
  • 5
  • 5

5

13 ratings


More shows like Cybersecurity Where You Are (video)

View all
Hacked by Hacked

Hacked

181 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,003 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

370 Listeners

Risky Business by Patrick Gray

Risky Business

373 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

Smashing Security by Graham Cluley

Smashing Security

322 Listeners

Click Here by Recorded Future News

Click Here

415 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,001 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

Hacking Humans by N2K Networks

Hacking Humans

313 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners