A tailored course, built for your situation
Mastering CIS Controls for Hosting Operations Analysts
Build repeatable security configurations that scale across infrastructure units
The situation this course is for
Without standardized baselines, infrastructure teams waste cycles reinventing controls, fail audits unnecessarily, and delay deployments waiting for security alignment.
Who this is for
Senior Hosting and Infrastructure Analysts responsible for secure, repeatable deployment patterns across regions
Who this is not for
Junior admins learning basics, executives seeking summaries, or auditors focused solely on compliance checklists
What you walk away with
- Deploy CIS-aligned configurations that pass audit without rework
- Standardize secure baselines across Windows, Linux, and cloud platforms
- Reduce misconfiguration incidents by 60% using automated validation templates
- Gain recognition as the go-to practitioner for cross-unit security consistency
- Influence infrastructure design choices before deployment cycles begin
The 12 modules (with all 144 chapters)
- What CIS Controls Are
- Structure of CIS Benchmarks
- Level 1 vs Level 2 Controls
- Mapping to Hosting Infrastructure
- CIS vs NIST CSF Overview
- CIS and UK GDPR Alignment
- Role of Automation in Implementation
- Benchmark Update Cycle
- Vendor-Specific Benchmarks
- Cloud Configuration Baselines
- Operating System Coverage
- Industrial Control Systems Add-On
- Hardware Asset Discovery Methods
- Automated Inventory Tools
- Device Ownership Tracking
- Unauthorized Device Detection
- Decommissioning Workflow
- Hardware Refresh Cycles
- Virtual Machine Tracking
- Cloud Instance Monitoring
- Agent-Based vs Agentless
- Integration with ServiceNow
- Alerting on New Devices
- Reporting to Leadership
- Software Discovery Techniques
- Approved Software List
- Unapproved Software Removal
- Version Lifecycle Tracking
- Patch Compatibility Checks
- Software Ownership Model
- Virtualized Application Monitoring
- Container Image Tracking
- License Compliance Integration
- Cloud-Native Binary Oversight
- Automated Reporting
- Integration with Jira
- Data Classification Framework
- Discovery of Sensitive Data
- Encryption Standards Mapping
- Database Encryption
- File Share Protection
- Cloud Storage Encryption
- Key Management Basics
- Data Loss Prevention Overview
- Access Control Integration
- Audit Logging Setup
- Breach Detection Signals
- Data Flow Diagramming
- Baseline Configuration Design
- CIS Benchmark Profiles
- Windows Hardening
- Linux Hardening
- Cloud Platform Settings
- Configuration Drift Detection
- Automated Remediation
- Group Policy Integration
- Change Management Sync
- Pre-Deployment Validation
- Post-Deployment Scanning
- Audit Readiness Checks
- User Role Definition
- Privileged Account Inventory
- Just-In-Time Access
- Service Account Management
- Password Policy Enforcement
- Multi-Factor Authentication
- Account Lockout Policies
- Remote Access Controls
- Shared Account Tracking
- Break-Glass Account Setup
- Access Review Cycles
- Integration with Azure AD
- Role-Based Access Design
- Permission Review Process
- Access Request Workflow
- Segregation of Duties
- Emergency Access Controls
- Cloud IAM Policies
- File System Permissions
- Database Access Rights
- Application Access Levels
- Remote Worker Access
- Vendor Access Management
- Access Recertification
- Vulnerability Scanning Schedule
- CVSS Scoring Basics
- Patch Prioritization Framework
- Automated Patch Deployment
- Zero-Day Response
- Cloud Vulnerability Tools
- Third-Party Component Risks
- Software Bill of Materials
- Remediation SLA Setup
- Integration with Jira
- Reporting to Management
- Post-Remediation Validation
- Log Source Identification
- Centralized Logging Setup
- Log Retention Policy
- SIEM Integration
- Event Correlation
- Anomaly Detection
- Log Integrity Protection
- Cloud Log Export
- User Activity Monitoring
- Security Alert Thresholds
- Incident Response Support
- Audit Readiness
- Browser Security Settings
- Phishing Protection
- Email Attachment Filtering
- URL Filtering
- Web Proxy Integration
- Content Disarm and Reconstruction
- Browser Extension Controls
- Pop-Up Blocker Setup
- HTTPS Enforcement
- DNS Filtering
- User Training Integration
- Reporting Suspicious Messages
- Antivirus Configuration
- Host-Based Firewall
- Behavioral Analysis
- Ransomware Protection
- Endpoint Detection and Response
- Threat Intelligence Feeds
- Malware Sandbox
- Zero-Trust Integration
- Quarantine Procedures
- Incident Escalation
- Backup Integration
- Recovery Testing
- Change Management Strategy
- Stakeholder Engagement
- Pilot Deployment
- Feedback Collection
- Regional Adaptation
- Documentation Standards
- Training Rollout
- Executive Reporting
- Cross-Team Collaboration
- Lessons Learned
- Continuous Improvement
- Certification Preparation
How this maps to your situation
- When launching new hosting zones
- Before audit cycles begin
- After a security incident
- During cloud migration
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters total)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3-4 hours per module, designed to fit around operational demands.
How this compares to the alternatives
Unlike generic security courses, this program delivers actionable, role-specific implementation playbooks grounded in CIS Controls and tailored to hosting operations in multi-region environments.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.