A tailored course, built for your situation
Mastering CIS Controls; A Step-by-Step Guide to Infrastructure Hardening
A proven path to bulletproof Z systems and infrastructure against evolving threats
Who this is for
Senior infrastructure and compliance leader in regulated, large-scale IT environments focused on stability, audit readiness, and secure delivery
Who this is not for
Engineers looking for tool-specific training or introductory security concepts
What you walk away with
- Ability to map CIS Controls directly to Z system configuration templates
- Faster justification of control scope during infrastructure reviews
- Reduced back-and-forth in audit preparation cycles
- Stronger influence in cross-functional infrastructure design sessions
- Clearer documentation trail for repeatable hardening playbooks
The 12 modules (with all 144 chapters)
- Overview of CIS Controls version 8 changes
- Mapping controls to system types and tiers
- Implementation Groups explained with examples
- Prioritizing IG1 vs IG2 for hosting environments
- How CIS maps to NIST CSF and ISO 27001
- Integrating CIS into existing compliance workflows
- Control applicability for mainframe platforms
- Baseline expectations per environment type
- Defining scope boundaries for audit purposes
- Documenting control in-scope and out-of-scope
- Role-based ownership of control execution
- Maintaining version control of framework updates
- Defining managed inventory for mainframe systems
- Automating discovery of connected hardware
- Maintaining accurate asset ownership records
- Tagging systems by criticality and function
- Tracking lifecycle from provisioning to decommission
- Integrating asset data with CMDB systems
- Validating inventory completeness monthly
- Detecting unauthorized hardware additions
- Using hardware fingerprints for consistency
- Reporting missing or rogue devices
- Synchronizing with virtualization layers
- Mapping assets to network zones
- Creating and maintaining software inventory
- Tracking software across development builds
- Identifying unauthorized software execution
- Managing licensing compliance for Z tools
- Version control of system software
- Integrating software lists with patch cycles
- Establishing baseline software configurations
- Enforcing software approval workflows
- Detecting shadow IT installations
- Reporting software drift from baseline
- Using automated tools for software audits
- Documenting exceptions and justifications
- Scheduling regular vulnerability scans
- Integrating scan results with Z monitoring
- Prioritizing findings by exploitability
- Mapping CVEs to system configurations
- Validating false positives manually
- Repairing or mitigating high-risk items
- Tracking remediation timelines
- Reporting status to compliance teams
- Using CVSS scores appropriately
- Assessing exposure windows
- Integrating threat intelligence feeds
- Automating patch validation steps
- Defining privileged accounts clearly
- Limiting local admin rights on systems
- Implementing time-bound access approvals
- Monitoring privileged session activity
- Segregating duties for root access
- Using just-in-time elevation tools
- Reviewing admin access quarterly
- Detecting privilege misuse patterns
- Enforcing multi-factor authentication
- Logging all admin-level commands
- Mapping admin roles to job functions
- Auditing access after personnel changes
- Establishing secure configuration policies
- Using CIS Benchmarks as a starting point
- Hardening operating system defaults
- Disabling unnecessary services and ports
- Applying principle of least functionality
- Documenting configuration exceptions
- Automating configuration checks
- Validating settings across environments
- Integrating with change management
- Updating baselines after system changes
- Measuring compliance deviation rates
- Reporting configuration drift
- Mapping network zones for Z systems
- Enforcing segmentation between tiers
- Configuring firewalls for mainframe traffic
- Monitoring for suspicious network flows
- Blocking unauthorized external access
- Validating encrypted tunnel usage
- Inspecting encrypted traffic safely
- Detecting lateral movement attempts
- Integrating with DDoS protection
- Reporting policy violations in real time
- Updating rules after topology changes
- Documenting firewall change history
- Identifying data sensitivity levels
- Classifying data by compliance requirements
- Applying encryption to stored datasets
- Protecting data during transfers
- Managing encryption keys securely
- Auditing access to encrypted data
- Using hardware security modules effectively
- Enabling secure key rotation
- Validating encryption coverage reports
- Reporting data exposure risks
- Integrating with data governance tools
- Documenting decryption access controls
- Defining critical logging events
- Collecting logs from all system layers
- Ensuring log integrity and retention
- Centralizing logs in analysis platforms
- Setting up alert thresholds
- Automating log review processes
- Detecting anomalous behavior patterns
- Correlating events across systems
- Responding to security alerts
- Investigating incidents using logs
- Producing audit-ready log documentation
- Testing log recovery procedures
- Hardening browser configurations
- Blocking malicious domains and URLs
- Filtering email attachments automatically
- Enabling anti-phishing protections
- Detecting impersonation attempts
- Securing web-based admin interfaces
- Using sandboxed browsing for risky sites
- Educating teams on safe habits
- Monitoring for credential theft
- Reporting phishing incidents quickly
- Updating filters based on threat feeds
- Validating browser patch levels
- Deploying host-based anti-malware tools
- Configuring real-time scanning schedules
- Blocking known malicious file types
- Preventing execution of unauthorized scripts
- Using behavior-based detection methods
- Maintaining up-to-date signature databases
- Quarantining infected systems automatically
- Analyzing malware samples safely
- Reporting outbreak patterns
- Validating clean-up procedures
- Integrating with SIEM for alerts
- Conducting periodic infection tests
- Defining incident classification levels
- Activating response teams quickly
- Containing system-level breaches
- Eradicating persistent threats
- Restoring systems from clean backups
- Validating data integrity after recovery
- Documenting incident root causes
- Reporting outcomes to leadership
- Updating playbooks after each event
- Conducting tabletop exercises
- Measuring response effectiveness
- Ensuring recovery plans stay current
How this maps to your situation
- Efficiency pressure increases scrutiny on infrastructure decisions
- STI leadership requires stronger audit narratives
- Infrastructure hosting teams need faster configuration validation
- Cross-functional teams expect clearer control ownership
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters total)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per week over three months, designed to fit around production cycles.
How this compares to the alternatives
Unlike generic security frameworks or tool-specific training, this course focuses exclusively on applying CIS Controls to enterprise infrastructure hosting environments, giving you precise, actionable control mapping for IBM Z and similar platforms.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.