Artwork

المحتوى المقدم من David Bisson and Center for Internet Security. يتم تحميل جميع محتويات البودكاست بما في ذلك الحلقات والرسومات وأوصاف البودكاست وتقديمها مباشرة بواسطة David Bisson and Center for Internet Security أو شريك منصة البودكاست الخاص بهم. إذا كنت تعتقد أن شخصًا ما يستخدم عملك المحمي بحقوق الطبع والنشر دون إذنك، فيمكنك اتباع العملية الموضحة هنا https://ar.player.fm/legal.
Player FM - تطبيق بودكاست
انتقل إلى وضع عدم الاتصال باستخدام تطبيق Player FM !

Episode 156: How CIS Uses CIS Products and Services

37:02
 
مشاركة
 

Manage episode 512259532 series 3382533
المحتوى المقدم من David Bisson and Center for Internet Security. يتم تحميل جميع محتويات البودكاست بما في ذلك الحلقات والرسومات وأوصاف البودكاست وتقديمها مباشرة بواسطة David Bisson and Center for Internet Security أو شريك منصة البودكاست الخاص بهم. إذا كنت تعتقد أن شخصًا ما يستخدم عملك المحمي بحقوق الطبع والنشر دون إذنك، فيمكنك اتباع العملية الموضحة هنا https://ar.player.fm/legal.

In episode 156 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Stephanie Gass, Sr. Director of Information Security at Center for Internet Security® (CIS®), and Angelo Marcotullio, Chief Information Officer at CIS. Together, they explore how CIS practices what it preaches by using CIS products and services internally, which includes implementation of the CIS Critical Security Controls® (CIS Controls®) and CIS Benchmarks®, automation, and alignment to compliance frameworks. Their discussion highlights how CIS builds a strong cybersecurity foundation while adapting to evolving threats and regulatory requirements.

The conversation dives into practical applications, cultural alignment, and the importance of repeatable processes for scaling security across new products and services. It also touches on the role of privacy regulations, cyber risk quantification, and the community-driven approach that underpins CIS best practices. Here are some highlights from our episode:

  • 01:12. Why CIS “drinks its own champagne” when it comes to cybersecurity
  • 02:56. Three ways the CIS Controls help modern enterprises defend against threat actors
  • 04:02. The importance of pulling together security lessons learned in a way that's translatable
  • 10:03. Our use of the CIS Controls to align to SOC 2, ISO 27001, and other frameworks
  • 12:01. How governance, risk, and compliance (GRC) engineering works with automation to help build repeatable processes
  • 22:43. The role of collaboration and communication in building a cybersecurity program
  • 27:17. Privacy regulations as a catalyst for security innovation
  • 30:24. The CIS Community Defense Model and evidence-based practices
  • 32:40. How CIS leverages lessons learned to improve our security best practices

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

  continue reading

157 حلقات

Artwork
iconمشاركة
 
Manage episode 512259532 series 3382533
المحتوى المقدم من David Bisson and Center for Internet Security. يتم تحميل جميع محتويات البودكاست بما في ذلك الحلقات والرسومات وأوصاف البودكاست وتقديمها مباشرة بواسطة David Bisson and Center for Internet Security أو شريك منصة البودكاست الخاص بهم. إذا كنت تعتقد أن شخصًا ما يستخدم عملك المحمي بحقوق الطبع والنشر دون إذنك، فيمكنك اتباع العملية الموضحة هنا https://ar.player.fm/legal.

In episode 156 of Cybersecurity Where You Are, Sean Atkinson and Tony Sager are joined by Stephanie Gass, Sr. Director of Information Security at Center for Internet Security® (CIS®), and Angelo Marcotullio, Chief Information Officer at CIS. Together, they explore how CIS practices what it preaches by using CIS products and services internally, which includes implementation of the CIS Critical Security Controls® (CIS Controls®) and CIS Benchmarks®, automation, and alignment to compliance frameworks. Their discussion highlights how CIS builds a strong cybersecurity foundation while adapting to evolving threats and regulatory requirements.

The conversation dives into practical applications, cultural alignment, and the importance of repeatable processes for scaling security across new products and services. It also touches on the role of privacy regulations, cyber risk quantification, and the community-driven approach that underpins CIS best practices. Here are some highlights from our episode:

  • 01:12. Why CIS “drinks its own champagne” when it comes to cybersecurity
  • 02:56. Three ways the CIS Controls help modern enterprises defend against threat actors
  • 04:02. The importance of pulling together security lessons learned in a way that's translatable
  • 10:03. Our use of the CIS Controls to align to SOC 2, ISO 27001, and other frameworks
  • 12:01. How governance, risk, and compliance (GRC) engineering works with automation to help build repeatable processes
  • 22:43. The role of collaboration and communication in building a cybersecurity program
  • 27:17. Privacy regulations as a catalyst for security innovation
  • 30:24. The CIS Community Defense Model and evidence-based practices
  • 32:40. How CIS leverages lessons learned to improve our security best practices

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

  continue reading

157 حلقات

كل الحلقات

×
 
Loading …

مرحبًا بك في مشغل أف ام!

يقوم برنامج مشغل أف أم بمسح الويب للحصول على بودكاست عالية الجودة لتستمتع بها الآن. إنه أفضل تطبيق بودكاست ويعمل على أجهزة اندرويد والأيفون والويب. قم بالتسجيل لمزامنة الاشتراكات عبر الأجهزة.

 

دليل مرجعي سريع

حقوق الطبع والنشر 2025 | سياسة الخصوصية | شروط الخدمة | | حقوق النشر
استمع إلى هذا العرض أثناء الاستكشاف
تشغيل