Skip to main content
Image coming soon

SEC1928 Mastering CIS Controls for IAM Directors in Zero-Trust Architecture

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for IAM Directors in Zero-Trust Architecture

Build unshakable identity governance frameworks with structured control mastery

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior IAM leader in a cloud-first, Zero-Trust environment with responsibility for control alignment, audit readiness, and cross-platform identity governance

Who this is not for

Entry-level security analysts, consultants without IAM program ownership, or teams focused solely on endpoint or network controls without identity integration

What you walk away with

  • Confidently map CIS Controls 1, 20 to identity-specific risks in hybrid environments
  • Draft audit-ready control narratives that stand up to internal and external review
  • Lead cross-functional risk discussions with pre-built templates and reference benchmarks
  • Deploy a repeatable CIS Controls implementation playbook tailored to cloud identity workflows
  • Maintain consistent control coverage across AWS, CIAM, and federated identity platforms

The 12 modules (with all 144 chapters)

Module 1. CIS Controls Overview and Identity Relevance
Establish the foundation of the CIS Critical Security Controls with a focus on identity-specific interpretation. Learn how controls map to IAM workflows and Zero-Trust Architecture maturity levels.
12 chapters in this module
  1. Introduction to CIS Controls v8
  2. Control groups and implementation groups
  3. Identity-centric control priorities
  4. Mapping to NIST 800-53 overlap
  5. Zero-Trust alignment principles
  6. Cloud identity scope definition
  7. Control ownership models
  8. Audit expectations by control
  9. Benchmarking maturity levels
  10. Vendor tool limitations
  11. Human process dependencies
  12. Documenting control rationale
Module 2. Inventory and Control of Enterprise Assets
Master asset inventory practices with identity-linked tracking, focusing on dynamic cloud workloads and federated devices used in CIAM environments.
12 chapters in this module
  1. Asset discovery methods
  2. Dynamic tagging in AWS
  3. Identity-linked device profiling
  4. Orphaned account detection
  5. Real-time synchronization
  6. Integration with Okta platforms
  7. Automated decommissioning
  8. Role-based ownership rules
  9. Device trust scoring
  10. API-accessible logging
  11. Control verification cadence
  12. Audit trail preservation
Module 3. Inventory and Control of Software
Apply software inventory controls to identity-related apps and integrations, including third-party connectors and cloud-native services.
12 chapters in this module
  1. Application whitelisting
  2. Privileged app identification
  3. Shadow IT detection
  4. OAuth integration tracking
  5. App-to-identity mapping
  6. Decommissioning workflows
  7. Version control alignment
  8. Vendor risk inputs
  9. Automated alerting
  10. User behavior correlation
  11. License compliance
  12. Audit package generation
Module 4. Data Protection
Enforce data-centric controls within identity systems, including PII handling, access logging, and consent tracking across CIAM platforms.
12 chapters in this module
  1. Data classification tiers
  2. PII detection in logs
  3. Encryption key ownership
  4. Consent lifecycle tracking
  5. Access request logging
  6. Data residency rules
  7. User data portability
  8. Right to be forgotten
  9. Audit trail completeness
  10. Regulatory overlap
  11. Cross-border handling
  12. Incident linkage procedures
Module 5. Secure Configuration for Enterprise Assets
Implement secure baseline configurations for identity infrastructure components, including federation servers and SSO gateways.
12 chapters in this module
  1. CIS Benchmarks overview
  2. Hardening identity servers
  3. SSO gateway tuning
  4. Certificate lifecycle
  5. Session timeout policies
  6. MFA enforcement
  7. Federation signing keys
  8. Access logging standards
  9. Change control integration
  10. Automated compliance checks
  11. Patch alignment
  12. Drift detection
Module 6. Account Management
Strengthen identity lifecycle processes from provisioning to deprovisioning, including privileged access and role transitions.
12 chapters in this module
  1. Provisioning workflows
  2. Role-based access control
  3. Privileged account classification
  4. Just-in-time access
  5. Access review cadence
  6. Delegated administration
  7. Emergency access
  8. Break-glass procedures
  9. Segregation of duties
  10. Orphaned account cleanup
  11. Automated certification
  12. Integration with HR systems
Module 7. Access Control
Enforce granular access policies across systems using identity attributes and context-aware rules aligned with Zero-Trust principles.
12 chapters in this module
  1. Policy decision points
  2. Attribute-based access control
  3. Contextual evaluation
  4. Risk-based step-up
  5. Zone boundary enforcement
  6. Cross-domain policies
  7. API access control
  8. Service account rules
  9. Temporary access
  10. Policy conflict resolution
  11. Audit of access changes
  12. Control logging
Module 8. Continuous Vulnerability Management
Integrate identity systems into vulnerability workflows, focusing on patch gaps and configuration drift in authentication services.
12 chapters in this module
  1. Vulnerability scanning scope
  2. Authentication service testing
  3. Patch prioritization
  4. Zero-day response
  5. Configuration drift alerts
  6. Third-party dependency checks
  7. Penetration test inclusion
  8. Log monitoring integration
  9. Remediation SLAs
  10. Escalation procedures
  11. Vendor coordination
  12. Reporting cadence
Module 9. Audit Log Management
Design comprehensive logging for identity events, ensuring retention, accessibility, and correlation with security monitoring systems.
12 chapters in this module
  1. Log collection scope
  2. Identity event types
  3. Retention policies
  4. Encryption at rest
  5. Immutable storage
  6. Cross-system correlation
  7. SIEM integration
  8. Query performance
  9. Incident response access
  10. Regulatory compliance
  11. Audit package automation
  12. Chain of custody
Module 10. Email and Web Browser Protection
Extend identity controls to email and browser-based threats using phishing resistance and session protection techniques.
12 chapters in this module
  1. Phishing-resistant MFA
  2. Session hijacking prevention
  3. Browser extension policies
  4. URL filtering integration
  5. Identity-based email rules
  6. Impersonation detection
  7. User reporting tools
  8. Training integration
  9. Incident triage
  10. Compromised account response
  11. Recovery workflows
  12. Forensic collection
Module 11. Malware Defenses
Strengthen endpoint detection and response through identity-linked behavior baselining and access revocation triggers.
12 chapters in this module
  1. Endpoint detection rules
  2. User behavior baselines
  3. Anomalous login detection
  4. Automated revocation
  5. Quarantine workflows
  6. Reputation scoring
  7. Fileless attack detection
  8. Memory scanning
  9. Network traffic analysis
  10. Integration with IAM
  11. User notification
  12. Remediation tracking
Module 12. Incident Response and Recognition
Turn proven control mastery into professional recognition through documented incident readiness, peer consultation, and leadership visibility.
12 chapters in this module
  1. Incident playbook structure
  2. Role assignment clarity
  3. Communication templates
  4. Regulator engagement
  5. Post-mortem documentation
  6. Lessons learned tracking
  7. Cross-functional coordination
  8. Executive briefings
  9. Control effectiveness reporting
  10. Peer consultation patterns
  11. Visibility best practices
  12. Recognition through consistency

How this maps to your situation

  • Before first audit cycle
  • After framework deployment
  • During vendor review
  • When leadership requests risk posture

Before vs. after

Before
Relies on ad-hoc control mapping and inconsistent documentation across teams
After
Deploys standardized, audit-ready CIS Controls implementation across identity systems with peer recognition

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-5 hours per module, with flexible pacing over 6-8 weeks

How this compares to the alternatives

Unlike generic compliance courses, this program focuses exclusively on CIS Controls as applied to identity and Zero-Trust Architecture, with templates and examples calibrated for cloud-first environments like AWS and Okta CIAM.

Frequently asked

Is this course focused on Okta-specific implementation?
No. The course avoids referencing Okta or Auth0 directly. It focuses on CIS Controls mastery within cloud identity and Zero-Trust Architecture frameworks, applicable across platforms.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does the course include certifications or exam prep?
No. This course builds practical implementation skills, not exam readiness for CISSP, CISM, or similar certifications.
$199 one-time. Approximately 3-5 hours per module, with flexible pacing over 6-8 weeks.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours