The reason it is suggested windows firewall is enough, is two fold. First, most average users are not going to know what to allow out bound on their systems with a firewall such as CFW set to custom. They will end up clicking allow everything just to stop the annoying pop ups "as that would be what those pop ups would be to them..
Secondly, the outbound ruleset is effective once the machine has become infected, would it not be better to focus on preventing these things to enter in the first place?
I have posted similar posts in the past, so im not bashing your post, or being a hypocrite. I have simply realized that not everyone is on the same level as some of us, and can not properly configure and use some of these products such as CIS. I have also come to realize over time, that a majority of the traffic on this site, are not registered members, but guest glancing through.