Skip to main content
Image coming soon

SEC1471 Mastering CIS Controls for z/OS Infrastructure Engineers

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for z/OS Infrastructure Engineers

Strengthen compliance posture and cross-functional influence with battle-tested security frameworks.

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Most engineers rely on patchwork checklists that fail under cross-functional scrutiny.

The situation this course is for

Without a recognized control baseline, infrastructure decisions require constant revalidation across audit, security, and compliance teams, slowing deployment and diluting authority.

Who this is for

Mid-senior infrastructure engineer in regulated financial services, responsible for secure configuration and compliance alignment of mission-critical systems.

Who this is not for

Entry-level admins, auditors without technical implementation responsibilities, or consultants without access to production z/OS environments.

What you walk away with

  • Produce control-aligned configurations that satisfy auditors and security reviewers without rework
  • Lead cross-functional alignment sessions using a shared, industry-recognized control language
  • Reduce review cycles by referencing standardized CIS benchmarks in documentation
  • Become the internal reference for defensible, repeatable hardening practices
  • Extend influence beyond infrastructure teams into compliance, risk, and audit functions

The 12 modules (with all 144 chapters)

Module 1. Introduction to CIS Controls in Regulated Environments
Understand how the CIS Controls map to real-world compliance demands in financial services, including alignment with SOX, NIST CSF, and internal audit expectations for IBM z systems.
12 chapters in this module
  1. What the CIS Controls are and why they matter
  2. Key differences between CIS Level 1 and Level 2 safeguards
  3. How financial firms use CIS Controls in audit narratives
  4. Mapping CIS to IBM z operational constraints
  5. Role of baselines in automated compliance checks
  6. Relationship between CIS and NIST CSF frameworks
  7. Typical gaps in z/OS environments during CIS reviews
  8. How configuration drift impacts CIS compliance
  9. Vendor tools that support CIS benchmarking
  10. Integrating CIS into change control workflows
  11. Common misinterpretations of control 1.1 and 1.4
  12. Building credibility by citing CIS version 8.05
Module 2. z/OS System Hardening Using CIS Benchmarks
Apply CIS Controls directly to z/OS configurations, focusing on secure defaults, privileged access, and service-level hardening.
12 chapters in this module
  1. Default configuration risks in z/OS installations
  2. Secure setup of z/OS Unix System Services
  3. Applying CIS control 4.1 to system libraries
  4. Hardening TCP/IP stacks using CIS guidance
  5. Securing JES2 and JES3 subsystems
  6. Implementing CIS control 5.2 for file systems
  7. Audit logging configuration per CIS 6.1
  8. Restricting z/OS console access per CIS 7.1
  9. Configuring RACF per CIS control 11.1
  10. Managing APF-authorized libraries safely
  11. Controlling SSH daemon settings on z/OS
  12. Validating hardening with automated scanner rules
Module 3. Access Management and Privilege Control
Align user access and privilege models with CIS Controls 11 and 16, tailored to RACF and multi-tiered access models.
12 chapters in this module
  1. Mapping CIS control 11 to RACF profiles
  2. User provisioning workflows that meet CIS standards
  3. Implementing least privilege in z/OS environments
  4. Reviewing superuser access against CIS 11.2
  5. Segregation of duties for system programmers
  6. Automated review of RACF rule changes
  7. Time-bound access using RACF and TSO
  8. Auditing privileged command usage
  9. CIS control 16.1 for administrative sessions
  10. Session timeouts and idle disconnect rules
  11. Multi-factor authentication for admin access
  12. Handling break-glass accounts under CIS
Module 4. Network Security and Traffic Control
Enforce CIS Controls 9 and 10 on z/OS networks, including firewall rules, port management, and segmentation.
12 chapters in this module
  1. Mapping CIS control 9 to z/OS network layers
  2. Securing VTAM and TCP/IP configurations
  3. Default port exposure risks on z/OS
  4. Implementing network segmentation using CIS
  5. Firewall rule alignment with control 9.1
  6. CIS control 9.2 for router configurations
  7. Monitoring for unauthorized network listeners
  8. Securing FTP and SFTP services on z/OS
  9. Configuring TLS for z/OS applications
  10. DNS security per CIS control 10.2
  11. Blocking unnecessary protocols like Telnet
  12. Validating network posture with automated scans
Module 5. Audit Logging and Monitoring Configuration
Implement CIS Controls 6 and 8 to ensure complete, reliable logging and monitoring setups that satisfy auditors.
12 chapters in this module
  1. CIS control 6.1 for log retention policies
  2. Configuring SMF for CIS compliance
  3. Mapping audit events to CIS control 8.1
  4. Centralized logging strategies for z/OS
  5. Log rotation and archival per control 6.2
  6. Ensuring immutable logs per CIS 8.2
  7. Common logging gaps in z/OS environments
  8. Correlating SMF records with security events
  9. Alert thresholds based on CIS control 8.5
  10. Using Netcool for log monitoring
  11. Validating log integrity during audits
  12. Preparing for regulator log sampling
Module 6. Vulnerability Management on Mainframe
Integrate CIS Controls 2 and 3 into patching, scanning, and remediation workflows specific to z/OS.
12 chapters in this module
  1. CIS control 2.1 for vulnerability scanning
  2. Choosing scanners compatible with z/OS
  3. Scheduling regular scans without downtime
  4. Prioritizing patches using CIS benchmarks
  5. Managing PTFs and HIPER fixes securely
  6. Aligning scanners with CIS control 2.2
  7. Remediating high-risk findings per CIS
  8. Documenting patch exceptions appropriately
  9. CIS control 3.1 for secure configurations
  10. Automating configuration drift detection
  11. Reporting scan results to audit teams
  12. Integrating scans into CI/CD pipelines
Module 7. Change Control and Configuration Drift
Apply CIS Controls 1.4 and 1.5 to maintain compliance across system changes and upgrades.
12 chapters in this module
  1. CIS control 1.4 for secure configurations
  2. Change approval workflows aligned with CIS
  3. Using CARF for compliance tracking
  4. Automated baseline comparisons
  5. Detecting unauthorized changes to JCL
  6. CIS control 1.5 for secure updates
  7. Version control for z/OS configuration files
  8. Validating changes against CIS benchmarks
  9. Rollback procedures per control 1.5
  10. Documenting changes for auditors
  11. Integrating CIS checks into deployment gates
  12. Enforcing peer review per CIS standards
Module 8. Endpoint Protection for z/OS Attached Systems
Extend CIS Controls to desktop and mid-tier systems that interact with z/OS, ensuring end-to-end security.
12 chapters in this module
  1. CIS control 4 for secure workstation setup
  2. Antivirus configuration on connected systems
  3. Disk encryption compliance per CIS 5.1
  4. Securing ODBC and JDBC connections
  5. User training for social engineering risks
  6. Applying CIS control 8.12 for logs
  7. Managing USB access on client machines
  8. Browser security settings per CIS 9.2
  9. Email client hardening for z users
  10. Patch cadence for Windows and Linux clients
  11. Enforcing MFA for z access tools
  12. Remote access security using CIS guidance
Module 9. CIS Controls and Regulatory Alignment
Map CIS Controls to SOX, NIST, and internal audit requirements common in financial institutions.
12 chapters in this module
  1. Mapping CIS to SOX Section 404 controls
  2. CIS alignment with NIST CSF Identify function
  3. Using CIS in SOX documentation packets
  4. Supporting ISO 27001 with CIS benchmarks
  5. CIS mapping to GLBA security rules
  6. Internal audit checklists referencing CIS
  7. Presenting CIS alignment to regulators
  8. Crosswalking CIS to COBIT domains
  9. Using CIS for DORA readiness
  10. Defending control choices during reviews
  11. CIS as evidence for risk treatment plans
  12. Updating frameworks as CIS evolves
Module 10. Automation and Tooling for CIS Compliance
Leverage scripts, scanners, and orchestration tools to maintain CIS compliance at scale.
12 chapters in this module
  1. Automating CIS control validation checks
  2. Building REXX scripts for configuration audits
  3. Integrating CIS checks into Zowe CLI
  4. Using Ansible for z/OS compliance tasks
  5. Parsing SMF data for CIS reporting
  6. Dashboards for CIS compliance status
  7. Scheduled jobs for control verification
  8. Email alerts for control violations
  9. CI/CD integration with CIS gates
  10. Customizing scanner rules per CIS 8.5
  11. Logging automation actions for auditors
  12. Version control for compliance scripts
Module 11. Cross-Functional Communication Strategies
Translate technical CIS implementation into clear narratives for audit, risk, and leadership teams.
12 chapters in this module
  1. Explaining CIS to non-technical reviewers
  2. Building audit-ready documentation packets
  3. Creating executive summaries of control status
  4. Visualizing compliance with CIS heatmaps
  5. Responding to auditor questions on CIS
  6. Using CIS to justify infrastructure spend
  7. Presenting control maturity to leadership
  8. Training peers on CIS implementation
  9. Collaborating with InfoSec using CIS
  10. Documenting exceptions with CIS rationale
  11. Handling gaps during compliance cycles
  12. Sharing CIS playbooks across teams
Module 12. Sustaining CIS Compliance Over Time
Establish durable processes that keep z/OS environments in line with evolving CIS baselines.
12 chapters in this module
  1. Updating for new CIS benchmark versions
  2. Tracking control changes across releases
  3. Planning for CIS version 9 migration
  4. Integrating CIS into annual review cycles
  5. Training new engineers on CIS standards
  6. Maintaining internal CIS knowledge base
  7. Benchmarking against peer institutions
  8. Reporting CIS maturity to risk committees
  9. Involving vendors in CIS alignment
  10. Documenting compliance for M&A
  11. Surviving leadership transitions
  12. Scaling CIS practices to new workloads

How this maps to your situation

  • z/OS hardening in financial services
  • Cross-functional compliance alignment
  • Regulatory readiness with SOX and DORA
  • Automated control validation at scale

Before vs. after

Before
Siloed compliance efforts requiring manual revalidation across teams.
After
Standardized, defensible security posture that supports faster audit cycles and broader influence.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: 90 minutes total across self-paced reading and template implementation.

If nothing changes
Without a unified control framework, engineers face repeated scrutiny, delayed changes, and diminished influence in cross-functional risk discussions.

How this compares to the alternatives

Generic security courses lack z/OS-specific control mappings; public CIS documentation lacks implementation depth. This course bridges both with tailored examples.

Frequently asked

Is this course specific to IBM z and z/OS environments?
Yes, every module includes direct application to z/OS configuration, RACF, SMF, JES, and related subsystems.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this for audit preparation?
Yes, the course includes templates and documentation strategies used in real SOX and internal audits.
$199 one-time. 90 minutes total across self-paced reading and template implementation..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours