Skip to main content
Image coming soon

SEC7749 Mastering CIS Controls for Cyber Security Specialists

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls for Cyber Security Specialists

Turn evolving threat landscapes into structured, enforceable security postures with confidence.

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Struggling to assert control over security decisions without executive buy-in?

The situation this course is for

Many security specialists are stuck reacting to directives instead of shaping them, despite being closest to the risks. Too often, they lack the structured authority to act decisively when threats shift.

Who this is for

Cyber Security Specialist at a major resource organization, responsible for implementing and maintaining security controls, with influence across IT and infrastructure teams.

Who this is not for

This is not for entry-level analysts, general IT staff, or executives seeking high-level overviews. It's specifically designed for practitioners who own control implementation and want greater autonomy.

What you walk away with

  • Own the prioritization and deployment of Tier 1 and Tier 2 CIS Controls without escalation
  • Produce documented mappings between CIS Controls and internal security policies
  • Lead internal validation exercises using CIS benchmarks as the standard
  • Confidently justify control exceptions with reference to framework guidance
  • Shape the security control narrative during audits and cross-functional reviews

The 12 modules (with all 144 chapters)

Module 1. Introduction to CIS Controls Framework
Establish foundational understanding of the CIS Controls structure, versioning, and applicability to large-scale resource operations.
12 chapters in this module
  1. Overview of CIS v8 structure
  2. Control families and prioritization
  3. Role of bench marking in security
  4. Mapping controls to NIST CSF
  5. Understanding implementation groups
  6. CIS vs ISO 27001 alignment
  7. How APRA CPS 234 maps to CIS
  8. Essential Eight overlap explained
  9. Control maturity levels
  10. Internal stakeholder expectations
  11. Audit readiness with CIS
  12. Version change tracking
Module 2. Inventory and Control of Hardware Assets
Ensure full visibility and management of all devices through automated, policy-enforced inventories.
12 chapters in this module
  1. Defining asset ownership
  2. Automated discovery methods
  3. Hardware lifecycle tracking
  4. Unauthorized device detection
  5. Endpoint compliance monitoring
  6. Integration with AD and MDM
  7. Asset classification tiers
  8. Decommissioning protocols
  9. Secure provisioning workflows
  10. BIOS/UEFI control standards
  11. Physical access logging
  12. Inventory reporting cadence
Module 3. Inventory and Control of Software Assets
Maintain accurate software ledgers and enforce approved execution policies.
12 chapters in this module
  1. Software inventory automation
  2. Whitelisting execution paths
  3. Unapproved software detection
  4. License compliance tracking
  5. Patch status visibility
  6. Signed software enforcement
  7. Application blacklisting
  8. Mobile app oversight
  9. Cloud software discovery
  10. SaaS usage monitoring
  11. Developer tool monitoring
  12. Shadow IT identification
Module 4. Data Protection
Classify, locate, and protect sensitive data across systems and storage layers.
12 chapters in this module
  1. Data classification schema
  2. Discovery of PII and sensitive data
  3. Encryption at rest and in transit
  4. DLP rule design
  5. Cloud storage protection
  6. Endpoint data leakage control
  7. Database activity monitoring
  8. Backup encryption standards
  9. Access logging for data stores
  10. Retention policy enforcement
  11. Data sovereignty considerations
  12. Cross-border transfer controls
Module 5. Secure Configuration of Enterprise Assets and Software
Enforce hardened baselines across devices and applications.
12 chapters in this module
  1. Benchmark development process
  2. CIS Benchmarks usage
  3. GPO enforcement strategies
  4. OS hardening templates
  5. Browser security settings
  6. Server configuration standards
  7. Cloud instance hardening
  8. Configuration drift detection
  9. Change approval workflows
  10. Automated compliance scanning
  11. Remediation playbooks
  12. Audit logging for changes
Module 6. Account Management
Implement least privilege and enforce identity lifecycle policies.
12 chapters in this module
  1. User provisioning standards
  2. Role-based access control
  3. Privileged account oversight
  4. Emergency access controls
  5. Shared account policies
  6. Multi-factor adoption
  7. Password policy enforcement
  8. Identity lifecycle automation
  9. Orphaned account detection
  10. Access review cycles
  11. Just-in-time elevation
  12. Service account security
Module 7. Access Control Management
Enforce network and application access based on policy and role.
12 chapters in this module
  1. Network segmentation design
  2. Firewall rule management
  3. Zero Trust principles
  4. VPN access controls
  5. Wireless access security
  6. Remote access logging
  7. Application-level access
  8. API authentication
  9. Time-bound access grants
  10. Geolocation-based restrictions
  11. Session timeout enforcement
  12. Privileged session monitoring
Module 8. Continuous Vulnerability Management
Identify, prioritize, and remediate vulnerabilities in a structured workflow.
12 chapters in this module
  1. Vulnerability scanning frequency
  2. CVSS scoring interpretation
  3. Patch prioritization logic
  4. Automated patch deployment
  5. Critical system exceptions
  6. Threat intelligence integration
  7. Zero-day response planning
  8. Third-party risk assessment
  9. Cloud workload patching
  10. OT and ICS considerations
  11. Escalation protocols
  12. Monthly reporting templates
Module 9. Audit Log and Monitoring
Centralize, protect, and analyze logs for detection and response.
12 chapters in this module
  1. Log source identification
  2. SIEM integration
  3. Log retention duration
  4. Encryption of log data
  5. Immutable storage setup
  6. User behavior analytics
  7. Threat detection rules
  8. Incident alerting
  9. Log review cadence
  10. Retention compliance
  11. Cross-system correlation
  12. Regulator-facing reporting
Module 10. Email and Web Browser Protections
Secure primary threat vectors used in phishing and exploit delivery.
12 chapters in this module
  1. Phishing simulation setup
  2. URL filtering
  3. Email attachment scanning
  4. DMARC policy enforcement
  5. Browser extension control
  6. HTTPS inspection
  7. Pop-up and redirect blocking
  8. Credential harvesting detection
  9. Web reputation services
  10. Click-time analysis
  11. User training integration
  12. Incident response integration
Module 11. Malware Defenses
Deploy layered anti-malware protections across endpoints and networks.
12 chapters in this module
  1. EDR solution selection
  2. Signature-based detection
  3. Behavioral analysis
  4. Sandboxing integration
  5. Ransomware-specific controls
  6. Boot-time scanning
  7. Fileless malware detection
  8. Macro execution blocking
  9. USB device control
  10. Quarantine protocols
  11. Threat hunting with EDR
  12. Incident isolation workflows
Module 12. Incident Response and Management
Prepare for, detect, and respond to security events using CIS-aligned playbooks.
12 chapters in this module
  1. Incident classification
  2. Response team activation
  3. Containment strategies
  4. Forensic data collection
  5. Legal and regulatory reporting
  6. Communication templates
  7. Post-incident review
  8. Playbook documentation
  9. Simulation exercises
  10. Stakeholder notification
  11. Regulator liaison process
  12. Lessons learned integration

How this maps to your situation

  • When implementing a new control baseline
  • During audit preparation cycles
  • After detection of configuration drift
  • Before onboarding new cloud services

Before vs. after

Before
Reactive approach to control changes, frequent escalations, delayed responses to audit findings
After
Proactive ownership of control decisions, direct authority over implementation choices, trusted advisor status across IT teams

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for integration into active control cycles.

If nothing changes
Without structured authority over control decisions, even strong practitioners remain reactive, delaying response, increasing audit friction, and missing opportunities to shape security direction.

How this compares to the alternatives

Unlike generic compliance courses, this program is built specifically for practitioners in resource-sector environments who need to act decisively within their current scope, not wait for approval.

Frequently asked

Is this focused on CIS v7 or v8?
The course covers CIS Controls v8 with mapping guidance to prior versions for continuity.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does it cover APRA CPS 234 alignment?
Yes, direct mappings between CIS Controls and CPS 234 requirements are included in relevant modules.
$199 one-time. Approximately 3 hours per module, designed for integration into active control cycles..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours