Building Your First Security Program
For the person who just became responsible for security — officially or otherwise. Stand up a small, defensible program on the platforms you already pay for, and prove it works.
Security responsibility usually arrives before security resources. One day the questionnaire lands, the insurance form asks hard questions, or leadership simply decides it is time — and the job is yours, alongside everything else.
This path is built for that moment. It deliberately avoids the two failure modes of first programs: buying tools before basics, and drafting forty policies nobody follows. Instead it walks the foundation controls in dependency order — inventory and identity first, because everything else references them — and builds the evidence habit from day one, so the program you stand up can be shown, not just described.
Modules marked available are open now as articles, labs, and working templates. The remaining modules ship as guided lessons in the next release; the full arc is listed so you can plan the quarter, not just the week.
Module sequence
Modules marked “Open now” link to working material. The rest arrive as guided lessons in the next release.
- 01
What a "program" actually is
Coming in the next releaseControls, owners, cadence, and evidence — the four-part definition that separates a program from a pile of good intentions.
- 02
The first seven controls
Open nowThe foundation set, sequenced for real organizations, mapped to CIS Implementation Group 1.
- 03
Building and maintaining asset and SaaS inventories — start with the Toolkit template and make it yours.
- 04
Identity, MFA, and the leaver checklist
Coming in the next releaseCentral identity, enforced multifactor authentication, and the lifecycle process that fails most often.
- 05
Backups you have actually restored
Coming in the next releaseCoverage decisions, SaaS data, and the restore test that turns hope into a control.
- 06
Incident readiness for small teams
Open nowThe one-page plan, the contact tree, and a walkthrough using the Toolkit incident-response checklist.
- 07
Policies that fit on real paper
Coming in the next releaseAcceptable use, access control, and data handling — short, honest documents staff will actually read.
- 08
Measuring and reporting progress
Coming in the next releaseA quarterly review rhythm and a leadership report that earns the program continued support.
What you will produce
- A populated asset inventory with owners assigned
- A sequenced 12-month security roadmap using the Toolkit template
- A one-page incident response plan with a real contact tree
- A quarterly program-review agenda you can reuse