Critical Controls Certification (CCC)

Inquire now

Critical Controls Certification (CCC) equips cybersecurity professionals with the knowledge and practical skills to implement critical security controls, improve security posture, and prepare for the CCC certification.

 

Duration 3 Days – 21 hrs.

 

Overview

The Critical Controls Certification (CCC) Training Course is designed to provide cybersecurity professionals, IT managers, risk practitioners, auditors, and security leaders with the knowledge and practical skills necessary to implement, assess, and manage the CIS Critical Security Controls (CIS Controls). The course focuses on understanding the prioritized set of cybersecurity best practices developed by the Center for Internet Security to help organizations defend against the most common and impactful cyber threats.

Participants will learn how to apply the CIS Controls framework to improve cybersecurity posture, reduce organizational risk, prioritize security investments, and establish a practical roadmap for cyber defense. The course combines governance, risk management, technical controls, and operational security practices aligned with modern cybersecurity requirements.

 

Objectives

  • Understand the purpose and structure of the CIS Critical Security Controls.
  • Apply CIS Controls to strengthen organizational cybersecurity programs.
  • Align security initiatives with business objectives and risk management requirements.
  • Assess organizational cybersecurity maturity using CIS Controls.
  • Prioritize cybersecurity investments based on risk.
  • Implement technical, administrative, and operational security controls.
  • Develop cybersecurity improvement roadmaps.
  • Measure control effectiveness and security performance.
  • Prepare for Critical Controls Certification (CCC) examinations and assessments.

 

Target Audience

  • Cybersecurity Analysts
  • Security Engineers
  • Security Managers
  • Information Security Officers
  • Risk and Compliance Professionals
  • IT Managers
  • IT Auditors
  • SOC Managers
  • Security Consultants
  • Governance, Risk, and Compliance (GRC) Professionals

 

Prerequisites

  • Basic understanding of cybersecurity principles
  • Familiarity with IT infrastructure and networks
  • Knowledge of risk management concepts
  • Experience in IT, security, audit, or compliance is beneficial
  • No prior CIS Controls experience required

Course Outline

 

Day 1: Introduction to CIS Critical Security Controls

 

Module 1: Cybersecurity Frameworks and Standards

  • Overview of cybersecurity frameworks
  • Risk-based security management
  • CIS Controls and their evolution
  • Relationship with NIST, ISO 27001, and other frameworks

 

Module 2: Understanding CIS Controls

  • CIS Controls structure
  • Implementation Groups (IG1, IG2, IG3)
  • Prioritization methodology
  • Mapping controls to organizational risk

 

 Module 3: Foundational Security Controls

Control 1: Inventory and Control of Enterprise Assets

  • Asset discovery
  • Asset inventory management
  • Asset classification

Control 2: Inventory and Control of Software Assets

  • Software inventory
  • Unauthorized software management
  • Application governance

Control 3: Data Protection

  • Data classification
  • Data handling procedures
  • Data loss prevention concepts

Control 4: Secure Configuration of Enterprise Assets and Software

  • Configuration baselines
  • Hardening standards
  • Secure deployment practices

Hands-On Workshop

  • Asset inventory exercise
  • Data classification workshop
  • Security baseline assessment

 

Day 2: Operational Security Controls

 

Module 4: Access and Identity Management

Control 5: Account Management

  • User lifecycle management
  • Privileged account management
  • Account monitoring

Control 6: Access Control Management

  • Least privilege principles
  • Role-based access control
  • Identity governance

 

 Module 5: Vulnerability and Security Management

Control 7: Continuous Vulnerability Management

  • Vulnerability identification
  • Risk prioritization
  • Remediation strategies

Control 8: Audit Log Management

  • Log collection
  • Monitoring and retention
  • Security investigations

 

Module 6: Security Awareness and Email Security

Control 9: Email and Web Browser Protections

  • Phishing prevention
  • Browser security
  • Email security controls

Control 14: Security Awareness and Skills Training

  • Awareness programs
  • Security culture development
  • User education initiatives

Hands-On Workshop

  • Vulnerability assessment exercise
  • Access control review
  • Security awareness program planning

 

Day 3: Advanced Controls, Governance, and Certification Preparation

 

Module 7: Defensive and Detection Controls

 

Control 10: Malware Defenses

  • Endpoint protection
  • Anti-malware strategies
  • Detection capabilities

Control 12: Network Infrastructure Management

  • Secure network architecture
  • Network segmentation
  • Network monitoring

Control 13: Network Monitoring and Defense

  • Intrusion detection
  • Security monitoring
  • Threat detection strategies

 

Module 8: Incident Response and Recovery

 

Control 17: Incident Response Management

  • Incident response lifecycle
  • Playbooks and procedures
  • Crisis management

Control 11: Data Recovery

  • Backup strategies
  • Recovery testing
  • Business continuity support

 

Module 9: Governance, Metrics, and Continuous Improvement

 

Control 15: Service Provider Management

  • Third-party risk management
  • Vendor security assessments

Control 16: Application Software Security

  • Secure development practices
  • Application security testing

Control 18: Penetration Testing

  • Security validation
  • Red team activities
  • Continuous improvement

Certification Preparation

  • CIS Controls assessment methodologies
  • Security metrics and KPIs
  • Maturity assessments
  • Practice examination review
  • Certification preparation strategies

Hands-On Workshop

  • CIS Controls gap assessment
  • Security improvement roadmap development
  • Organizational maturity evaluation

 

Hands-On Labs and Practical Exercises

 

Throughout the course, participants will perform:

  • Asset Inventory Assessment
  • Software Asset Management Review
  • Data Classification Exercises
  • Security Baseline Assessment
  • Vulnerability Management Activities
  • Access Control Reviews
  • Security Awareness Program Development
  • Incident Response Simulations
  • Network Defense Planning
  • CIS Controls Gap Analysis
  • Security Maturity Assessments
  • Cybersecurity Roadmap Development

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy