Skip to main content
Image coming soon

SEC9196 Mastering CIS Controls; A Step-by-Step Guide to Infrastructure Hardening

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering CIS Controls; A Step-by-Step Guide to Infrastructure Hardening

A proven path to bulletproof Z systems and infrastructure against evolving threats

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior infrastructure and compliance leader in regulated, large-scale IT environments focused on stability, audit readiness, and secure delivery

Who this is not for

Engineers looking for tool-specific training or introductory security concepts

What you walk away with

  • Ability to map CIS Controls directly to Z system configuration templates
  • Faster justification of control scope during infrastructure reviews
  • Reduced back-and-forth in audit preparation cycles
  • Stronger influence in cross-functional infrastructure design sessions
  • Clearer documentation trail for repeatable hardening playbooks

The 12 modules (with all 144 chapters)

Module 1. Understanding CIS Controls Framework Structure
Break down the layers of the CIS Controls, focusing on how Implementation Groups align with IBM Z infrastructure maturity levels and team ownership models.
12 chapters in this module
  1. Overview of CIS Controls version 8 changes
  2. Mapping controls to system types and tiers
  3. Implementation Groups explained with examples
  4. Prioritizing IG1 vs IG2 for hosting environments
  5. How CIS maps to NIST CSF and ISO 27001
  6. Integrating CIS into existing compliance workflows
  7. Control applicability for mainframe platforms
  8. Baseline expectations per environment type
  9. Defining scope boundaries for audit purposes
  10. Documenting control in-scope and out-of-scope
  11. Role-based ownership of control execution
  12. Maintaining version control of framework updates
Module 2. Inventory and Control of Hardware Assets
Establish comprehensive visibility over all infrastructure components, ensuring no unmanaged device enters the Z development or hosting pipeline.
12 chapters in this module
  1. Defining managed inventory for mainframe systems
  2. Automating discovery of connected hardware
  3. Maintaining accurate asset ownership records
  4. Tagging systems by criticality and function
  5. Tracking lifecycle from provisioning to decommission
  6. Integrating asset data with CMDB systems
  7. Validating inventory completeness monthly
  8. Detecting unauthorized hardware additions
  9. Using hardware fingerprints for consistency
  10. Reporting missing or rogue devices
  11. Synchronizing with virtualization layers
  12. Mapping assets to network zones
Module 3. Inventory and Control of Software Assets
Ensure only approved software runs in the environment with accurate tracking of versions, licenses, and dependencies.
12 chapters in this module
  1. Creating and maintaining software inventory
  2. Tracking software across development builds
  3. Identifying unauthorized software execution
  4. Managing licensing compliance for Z tools
  5. Version control of system software
  6. Integrating software lists with patch cycles
  7. Establishing baseline software configurations
  8. Enforcing software approval workflows
  9. Detecting shadow IT installations
  10. Reporting software drift from baseline
  11. Using automated tools for software audits
  12. Documenting exceptions and justifications
Module 4. Continuous Vulnerability Management
Implement proactive scanning and prioritization of vulnerabilities specific to IBM Z systems and supporting infrastructure.
12 chapters in this module
  1. Scheduling regular vulnerability scans
  2. Integrating scan results with Z monitoring
  3. Prioritizing findings by exploitability
  4. Mapping CVEs to system configurations
  5. Validating false positives manually
  6. Repairing or mitigating high-risk items
  7. Tracking remediation timelines
  8. Reporting status to compliance teams
  9. Using CVSS scores appropriately
  10. Assessing exposure windows
  11. Integrating threat intelligence feeds
  12. Automating patch validation steps
Module 5. Controlled Use of Administrative Privileges
Secure privileged access paths for Z system administration while maintaining operational agility.
12 chapters in this module
  1. Defining privileged accounts clearly
  2. Limiting local admin rights on systems
  3. Implementing time-bound access approvals
  4. Monitoring privileged session activity
  5. Segregating duties for root access
  6. Using just-in-time elevation tools
  7. Reviewing admin access quarterly
  8. Detecting privilege misuse patterns
  9. Enforcing multi-factor authentication
  10. Logging all admin-level commands
  11. Mapping admin roles to job functions
  12. Auditing access after personnel changes
Module 6. Secure Configuration for Hardware and Software
Build and enforce hardened configuration baselines for IBM Z and supporting infrastructure components.
12 chapters in this module
  1. Establishing secure configuration policies
  2. Using CIS Benchmarks as a starting point
  3. Hardening operating system defaults
  4. Disabling unnecessary services and ports
  5. Applying principle of least functionality
  6. Documenting configuration exceptions
  7. Automating configuration checks
  8. Validating settings across environments
  9. Integrating with change management
  10. Updating baselines after system changes
  11. Measuring compliance deviation rates
  12. Reporting configuration drift
Module 7. Boundary Defense and Network Security
Design and validate network segmentation and filtering rules tailored to IBM Z hosting environments.
12 chapters in this module
  1. Mapping network zones for Z systems
  2. Enforcing segmentation between tiers
  3. Configuring firewalls for mainframe traffic
  4. Monitoring for suspicious network flows
  5. Blocking unauthorized external access
  6. Validating encrypted tunnel usage
  7. Inspecting encrypted traffic safely
  8. Detecting lateral movement attempts
  9. Integrating with DDoS protection
  10. Reporting policy violations in real time
  11. Updating rules after topology changes
  12. Documenting firewall change history
Module 8. Data Protection and Encryption
Ensure sensitive data on IBM Z systems is identified, classified, and protected using strong encryption in transit and at rest.
12 chapters in this module
  1. Identifying data sensitivity levels
  2. Classifying data by compliance requirements
  3. Applying encryption to stored datasets
  4. Protecting data during transfers
  5. Managing encryption keys securely
  6. Auditing access to encrypted data
  7. Using hardware security modules effectively
  8. Enabling secure key rotation
  9. Validating encryption coverage reports
  10. Reporting data exposure risks
  11. Integrating with data governance tools
  12. Documenting decryption access controls
Module 9. Logging and Monitoring Infrastructure Activity
Build reliable logging pipelines for IBM Z and infrastructure components with clear detection and alerting rules.
12 chapters in this module
  1. Defining critical logging events
  2. Collecting logs from all system layers
  3. Ensuring log integrity and retention
  4. Centralizing logs in analysis platforms
  5. Setting up alert thresholds
  6. Automating log review processes
  7. Detecting anomalous behavior patterns
  8. Correlating events across systems
  9. Responding to security alerts
  10. Investigating incidents using logs
  11. Producing audit-ready log documentation
  12. Testing log recovery procedures
Module 10. Email and Web Browser Protections
Strengthen client-facing services used in infrastructure management to prevent entry points via phishing or drive-by exploits.
12 chapters in this module
  1. Hardening browser configurations
  2. Blocking malicious domains and URLs
  3. Filtering email attachments automatically
  4. Enabling anti-phishing protections
  5. Detecting impersonation attempts
  6. Securing web-based admin interfaces
  7. Using sandboxed browsing for risky sites
  8. Educating teams on safe habits
  9. Monitoring for credential theft
  10. Reporting phishing incidents quickly
  11. Updating filters based on threat feeds
  12. Validating browser patch levels
Module 11. Malware Defense and Endpoint Protection
Implement multi-layered defenses to detect and block malicious code execution across infrastructure endpoints.
12 chapters in this module
  1. Deploying host-based anti-malware tools
  2. Configuring real-time scanning schedules
  3. Blocking known malicious file types
  4. Preventing execution of unauthorized scripts
  5. Using behavior-based detection methods
  6. Maintaining up-to-date signature databases
  7. Quarantining infected systems automatically
  8. Analyzing malware samples safely
  9. Reporting outbreak patterns
  10. Validating clean-up procedures
  11. Integrating with SIEM for alerts
  12. Conducting periodic infection tests
Module 12. Incident Response and Recovery Planning
Prepare to respond to infrastructure-level incidents with clear playbooks, roles, and recovery validation.
12 chapters in this module
  1. Defining incident classification levels
  2. Activating response teams quickly
  3. Containing system-level breaches
  4. Eradicating persistent threats
  5. Restoring systems from clean backups
  6. Validating data integrity after recovery
  7. Documenting incident root causes
  8. Reporting outcomes to leadership
  9. Updating playbooks after each event
  10. Conducting tabletop exercises
  11. Measuring response effectiveness
  12. Ensuring recovery plans stay current

How this maps to your situation

  • Efficiency pressure increases scrutiny on infrastructure decisions
  • STI leadership requires stronger audit narratives
  • Infrastructure hosting teams need faster configuration validation
  • Cross-functional teams expect clearer control ownership

Before vs. after

Before
Spending extra time justifying control scope and reworking configurations during reviews
After
Confidently designing hardened baselines with clear, defensible rationale aligned to CIS Controls

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters total)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per week over three months, designed to fit around production cycles.

If nothing changes
Without structured mastery of the CIS Controls, infrastructure teams risk repeated audit findings, inefficient remediation cycles, and delayed delivery timelines, especially under current efficiency mandates.

How this compares to the alternatives

Unlike generic security frameworks or tool-specific training, this course focuses exclusively on applying CIS Controls to enterprise infrastructure hosting environments, giving you precise, actionable control mapping for IBM Z and similar platforms.

Frequently asked

Is this course specific to IBM Z environments?
While the framework is vendor-neutral, all examples and templates are tailored to mainframe and large-scale infrastructure hosting contexts like IBM Z.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will I receive practical tools with the course?
Yes, downloadable templates, sample configurations, and a custom-built implementation playbook are included.
$199 one-time. Approximately 90 minutes per week over three months, designed to fit around production cycles..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours