Duration 3 Days – 21 hrs.
Overview
The Critical Controls Certification (CCC) Training Course is designed to provide cybersecurity professionals, IT managers, risk practitioners, auditors, and security leaders with the knowledge and practical skills necessary to implement, assess, and manage the CIS Critical Security Controls (CIS Controls). The course focuses on understanding the prioritized set of cybersecurity best practices developed by the Center for Internet Security to help organizations defend against the most common and impactful cyber threats.
Participants will learn how to apply the CIS Controls framework to improve cybersecurity posture, reduce organizational risk, prioritize security investments, and establish a practical roadmap for cyber defense. The course combines governance, risk management, technical controls, and operational security practices aligned with modern cybersecurity requirements.
Objectives
- Understand the purpose and structure of the CIS Critical Security Controls.
- Apply CIS Controls to strengthen organizational cybersecurity programs.
- Align security initiatives with business objectives and risk management requirements.
- Assess organizational cybersecurity maturity using CIS Controls.
- Prioritize cybersecurity investments based on risk.
- Implement technical, administrative, and operational security controls.
- Develop cybersecurity improvement roadmaps.
- Measure control effectiveness and security performance.
- Prepare for Critical Controls Certification (CCC) examinations and assessments.
Target Audience
- Cybersecurity Analysts
- Security Engineers
- Security Managers
- Information Security Officers
- Risk and Compliance Professionals
- IT Managers
- IT Auditors
- SOC Managers
- Security Consultants
- Governance, Risk, and Compliance (GRC) Professionals
Prerequisites
- Basic understanding of cybersecurity principles
- Familiarity with IT infrastructure and networks
- Knowledge of risk management concepts
- Experience in IT, security, audit, or compliance is beneficial
- No prior CIS Controls experience required
Course Outline
Day 1: Introduction to CIS Critical Security Controls
Module 1: Cybersecurity Frameworks and Standards
- Overview of cybersecurity frameworks
- Risk-based security management
- CIS Controls and their evolution
- Relationship with NIST, ISO 27001, and other frameworks
Module 2: Understanding CIS Controls
- CIS Controls structure
- Implementation Groups (IG1, IG2, IG3)
- Prioritization methodology
- Mapping controls to organizational risk
Module 3: Foundational Security Controls
Control 1: Inventory and Control of Enterprise Assets
- Asset discovery
- Asset inventory management
- Asset classification
Control 2: Inventory and Control of Software Assets
- Software inventory
- Unauthorized software management
- Application governance
Control 3: Data Protection
- Data classification
- Data handling procedures
- Data loss prevention concepts
Control 4: Secure Configuration of Enterprise Assets and Software
- Configuration baselines
- Hardening standards
- Secure deployment practices
Hands-On Workshop
- Asset inventory exercise
- Data classification workshop
- Security baseline assessment
Day 2: Operational Security Controls
Module 4: Access and Identity Management
Control 5: Account Management
- User lifecycle management
- Privileged account management
- Account monitoring
Control 6: Access Control Management
- Least privilege principles
- Role-based access control
- Identity governance
Module 5: Vulnerability and Security Management
Control 7: Continuous Vulnerability Management
- Vulnerability identification
- Risk prioritization
- Remediation strategies
Control 8: Audit Log Management
- Log collection
- Monitoring and retention
- Security investigations
Module 6: Security Awareness and Email Security
Control 9: Email and Web Browser Protections
- Phishing prevention
- Browser security
- Email security controls
Control 14: Security Awareness and Skills Training
- Awareness programs
- Security culture development
- User education initiatives
Hands-On Workshop
- Vulnerability assessment exercise
- Access control review
- Security awareness program planning
Day 3: Advanced Controls, Governance, and Certification Preparation
Module 7: Defensive and Detection Controls
Control 10: Malware Defenses
- Endpoint protection
- Anti-malware strategies
- Detection capabilities
Control 12: Network Infrastructure Management
- Secure network architecture
- Network segmentation
- Network monitoring
Control 13: Network Monitoring and Defense
- Intrusion detection
- Security monitoring
- Threat detection strategies
Module 8: Incident Response and Recovery
Control 17: Incident Response Management
- Incident response lifecycle
- Playbooks and procedures
- Crisis management
Control 11: Data Recovery
- Backup strategies
- Recovery testing
- Business continuity support
Module 9: Governance, Metrics, and Continuous Improvement
Control 15: Service Provider Management
- Third-party risk management
- Vendor security assessments
Control 16: Application Software Security
- Secure development practices
- Application security testing
Control 18: Penetration Testing
- Security validation
- Red team activities
- Continuous improvement
Certification Preparation
- CIS Controls assessment methodologies
- Security metrics and KPIs
- Maturity assessments
- Practice examination review
- Certification preparation strategies
Hands-On Workshop
- CIS Controls gap assessment
- Security improvement roadmap development
- Organizational maturity evaluation
Hands-On Labs and Practical Exercises
Throughout the course, participants will perform:
- Asset Inventory Assessment
- Software Asset Management Review
- Data Classification Exercises
- Security Baseline Assessment
- Vulnerability Management Activities
- Access Control Reviews
- Security Awareness Program Development
- Incident Response Simulations
- Network Defense Planning
- CIS Controls Gap Analysis
- Security Maturity Assessments
- Cybersecurity Roadmap Development

