Group Purchasing
Group Purchasing

What Is the GCCC Certification?

The GIAC Critical Controls Certification (GCCC) validates a practitioner's command of the CIS Critical Security Controls, a prioritized, risk-based approach to security. Certification holders have the knowledge and skills to implement and execute the CIS Critical Controls recommended by the Center for Internet Security, and to perform audits based on the standard.

By the numbers

2 hrs

Exam duration

75

Questions

71%

Min. passing score

What GCCC Covers

The objectives group into five practical domains.

Foundations and Asset Inventory

CIS Controls background, standards, and governance; Inventory and Control of Enterprise Assets.

Data, Identity, and Access

Inventory and Control of Software Assets; Data Protection; Account Management; Access Control Management.

Configuration, Vulnerability, and Logging

Continuous Vulnerability Management; Secure Configuration of Enterprise Assets and Software; Audit Log Management; Email and Web Browser Protections.

Network and Malware Defense

Malware Defenses; Data Recovery; Network Infrastructure Management; Network Monitoring and Defense.

Governance and Operational Security

Security Awareness and Skills Training; Service Provider Management; Application Software Security; Incident Response Management; Penetration Testing.

Prepare With This Course

SEC566: Implementing and Auditing CIS Controls

How SEC566 Prepares You for GCCC

SEC566 is built around the exam objectives that make up the GCCC certification: 

  • Section 1, Introduction and Overview of the CIS Critical Controls builds skills tested under CIS Controls background, standards, and governance, and Inventory and Control of Enterprise Assets.
  • Section 2, Data Protection, Identity and Authentication aligns with Inventory and Control of Software Assets, Data Protection, Account Management, and Access Control Management.
  • Section 3, Server, Workstation, Network Protections aligns with Continuous Vulnerability Management, Secure Configuration of Enterprise Assets and Software, Audit Log Management, and Email and Web Browser Protections.
  • Section 4, Network Infrastructure and Defense aligns with Malware Defenses, Data Recovery, Network Infrastructure Management, and Network Monitoring and Defense.
  • Section 5, Governance and Operational Security aligns with Security Awareness and Skills Training, Service Provider Management, Application Software Security, Incident Response Management, and Penetration Testing.

Across all five sections, 23 hands-on labs and four rounds of Cyber42 leadership simulations give you the chance to apply each control in a live enterprise environment before you sit the exam. 

Read the full GCCC certification overview 

SEC566 Course Author

Brian Ventura
Brian Ventura

Brian Ventura

Partner at Cyverity

Brian Ventura is a Partner at Cyverity and lead instructor/author for SEC566: Implementing and Auditing CIS Controls. With over 30 years in systems and security, he helps organizations build measurable, business-aligned programs rooted in the CIS Controls.

Read more about Brian Ventura

Who Should Pursue GCCC

Security Professionals, Auditors, CIOs, and Risk Officers

Information Assurance Auditors and Compliance Analysts

System Implementers, Administrators, and IT Administrators

Network Security Engineers

DoD Personnel, Contractors, and Federal Agencies

Security Vendors and Consulting Groups

Frequently Asked Questions

The GIAC Critical Controls Certification (GCCC) proves you can implement, execute, and audit the CIS Critical Security Controls, the prioritized, risk-based set of safeguards recommended by the Center for Internet Security. Certification holders show they can put all 18 CIS Controls (Version 8) into practice, from asset inventory and access management through incident response and penetration testing, and that they understand how those controls map to standards like NIST, ISO, and PCI DSS. 

The GCCC exam is a single proctored test made up of 75 questions, with a 2-hour time limit and a minimum passing score of 71%. GIAC periodically reviews exam specifications, so candidates should confirm the current format in the Certification Information section of their GIAC account before sitting the exam. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GCCC is built for security professionals, auditors, CIOs, and risk officers, along with information assurance auditors, system implementers and administrators, network security engineers, IT administrators, and DoD personnel and contractors. It also fits compliance analysts and security vendors or consulting groups who need to stay current on control frameworks for clients. 

SEC566: Implementing and Auditing CIS Controls is the SANS course built to prepare you for the GCCC exam. Across five sections and 23 hands-on labs, it walks through every CIS Control the exam covers, plus four rounds of Cyber42 leadership simulations that put each control into practice, including expanded coverage of applying the controls to AI models, data, and pipelines. 

Ready to earn your GCCC certification?

Add the GCCC exam attempt when you register for SEC566.

Already trained? Register for the exam directly through GIAC here.