A tailored course, built for your situation
Mastering CIS Controls for z/OS Infrastructure Engineers
Strengthen compliance posture and cross-functional influence with battle-tested security frameworks.
The situation this course is for
Without a recognized control baseline, infrastructure decisions require constant revalidation across audit, security, and compliance teams, slowing deployment and diluting authority.
Who this is for
Mid-senior infrastructure engineer in regulated financial services, responsible for secure configuration and compliance alignment of mission-critical systems.
Who this is not for
Entry-level admins, auditors without technical implementation responsibilities, or consultants without access to production z/OS environments.
What you walk away with
- Produce control-aligned configurations that satisfy auditors and security reviewers without rework
- Lead cross-functional alignment sessions using a shared, industry-recognized control language
- Reduce review cycles by referencing standardized CIS benchmarks in documentation
- Become the internal reference for defensible, repeatable hardening practices
- Extend influence beyond infrastructure teams into compliance, risk, and audit functions
The 12 modules (with all 144 chapters)
- What the CIS Controls are and why they matter
- Key differences between CIS Level 1 and Level 2 safeguards
- How financial firms use CIS Controls in audit narratives
- Mapping CIS to IBM z operational constraints
- Role of baselines in automated compliance checks
- Relationship between CIS and NIST CSF frameworks
- Typical gaps in z/OS environments during CIS reviews
- How configuration drift impacts CIS compliance
- Vendor tools that support CIS benchmarking
- Integrating CIS into change control workflows
- Common misinterpretations of control 1.1 and 1.4
- Building credibility by citing CIS version 8.05
- Default configuration risks in z/OS installations
- Secure setup of z/OS Unix System Services
- Applying CIS control 4.1 to system libraries
- Hardening TCP/IP stacks using CIS guidance
- Securing JES2 and JES3 subsystems
- Implementing CIS control 5.2 for file systems
- Audit logging configuration per CIS 6.1
- Restricting z/OS console access per CIS 7.1
- Configuring RACF per CIS control 11.1
- Managing APF-authorized libraries safely
- Controlling SSH daemon settings on z/OS
- Validating hardening with automated scanner rules
- Mapping CIS control 11 to RACF profiles
- User provisioning workflows that meet CIS standards
- Implementing least privilege in z/OS environments
- Reviewing superuser access against CIS 11.2
- Segregation of duties for system programmers
- Automated review of RACF rule changes
- Time-bound access using RACF and TSO
- Auditing privileged command usage
- CIS control 16.1 for administrative sessions
- Session timeouts and idle disconnect rules
- Multi-factor authentication for admin access
- Handling break-glass accounts under CIS
- Mapping CIS control 9 to z/OS network layers
- Securing VTAM and TCP/IP configurations
- Default port exposure risks on z/OS
- Implementing network segmentation using CIS
- Firewall rule alignment with control 9.1
- CIS control 9.2 for router configurations
- Monitoring for unauthorized network listeners
- Securing FTP and SFTP services on z/OS
- Configuring TLS for z/OS applications
- DNS security per CIS control 10.2
- Blocking unnecessary protocols like Telnet
- Validating network posture with automated scans
- CIS control 6.1 for log retention policies
- Configuring SMF for CIS compliance
- Mapping audit events to CIS control 8.1
- Centralized logging strategies for z/OS
- Log rotation and archival per control 6.2
- Ensuring immutable logs per CIS 8.2
- Common logging gaps in z/OS environments
- Correlating SMF records with security events
- Alert thresholds based on CIS control 8.5
- Using Netcool for log monitoring
- Validating log integrity during audits
- Preparing for regulator log sampling
- CIS control 2.1 for vulnerability scanning
- Choosing scanners compatible with z/OS
- Scheduling regular scans without downtime
- Prioritizing patches using CIS benchmarks
- Managing PTFs and HIPER fixes securely
- Aligning scanners with CIS control 2.2
- Remediating high-risk findings per CIS
- Documenting patch exceptions appropriately
- CIS control 3.1 for secure configurations
- Automating configuration drift detection
- Reporting scan results to audit teams
- Integrating scans into CI/CD pipelines
- CIS control 1.4 for secure configurations
- Change approval workflows aligned with CIS
- Using CARF for compliance tracking
- Automated baseline comparisons
- Detecting unauthorized changes to JCL
- CIS control 1.5 for secure updates
- Version control for z/OS configuration files
- Validating changes against CIS benchmarks
- Rollback procedures per control 1.5
- Documenting changes for auditors
- Integrating CIS checks into deployment gates
- Enforcing peer review per CIS standards
- CIS control 4 for secure workstation setup
- Antivirus configuration on connected systems
- Disk encryption compliance per CIS 5.1
- Securing ODBC and JDBC connections
- User training for social engineering risks
- Applying CIS control 8.12 for logs
- Managing USB access on client machines
- Browser security settings per CIS 9.2
- Email client hardening for z users
- Patch cadence for Windows and Linux clients
- Enforcing MFA for z access tools
- Remote access security using CIS guidance
- Mapping CIS to SOX Section 404 controls
- CIS alignment with NIST CSF Identify function
- Using CIS in SOX documentation packets
- Supporting ISO 27001 with CIS benchmarks
- CIS mapping to GLBA security rules
- Internal audit checklists referencing CIS
- Presenting CIS alignment to regulators
- Crosswalking CIS to COBIT domains
- Using CIS for DORA readiness
- Defending control choices during reviews
- CIS as evidence for risk treatment plans
- Updating frameworks as CIS evolves
- Automating CIS control validation checks
- Building REXX scripts for configuration audits
- Integrating CIS checks into Zowe CLI
- Using Ansible for z/OS compliance tasks
- Parsing SMF data for CIS reporting
- Dashboards for CIS compliance status
- Scheduled jobs for control verification
- Email alerts for control violations
- CI/CD integration with CIS gates
- Customizing scanner rules per CIS 8.5
- Logging automation actions for auditors
- Version control for compliance scripts
- Explaining CIS to non-technical reviewers
- Building audit-ready documentation packets
- Creating executive summaries of control status
- Visualizing compliance with CIS heatmaps
- Responding to auditor questions on CIS
- Using CIS to justify infrastructure spend
- Presenting control maturity to leadership
- Training peers on CIS implementation
- Collaborating with InfoSec using CIS
- Documenting exceptions with CIS rationale
- Handling gaps during compliance cycles
- Sharing CIS playbooks across teams
- Updating for new CIS benchmark versions
- Tracking control changes across releases
- Planning for CIS version 9 migration
- Integrating CIS into annual review cycles
- Training new engineers on CIS standards
- Maintaining internal CIS knowledge base
- Benchmarking against peer institutions
- Reporting CIS maturity to risk committees
- Involving vendors in CIS alignment
- Documenting compliance for M&A
- Surviving leadership transitions
- Scaling CIS practices to new workloads
How this maps to your situation
- z/OS hardening in financial services
- Cross-functional compliance alignment
- Regulatory readiness with SOX and DORA
- Automated control validation at scale
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: 90 minutes total across self-paced reading and template implementation.
How this compares to the alternatives
Generic security courses lack z/OS-specific control mappings; public CIS documentation lacks implementation depth. This course bridges both with tailored examples.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.