SEC536: Adversarial AI - Penetration Testing AI Systems


The GIAC Critical Controls Certification (GCCC) proves you can implement, execute, and audit the CIS Critical Security Controls, the prioritized, risk-based set of safeguards recommended by the Center for Internet Security. Certification holders show they can put all 18 CIS Controls (Version 8) into practice, from asset inventory and access management through incident response and penetration testing, and that they understand how those controls map to standards like NIST, ISO, and PCI DSS.
The GCCC exam is a single proctored test made up of 75 questions, with a 2-hour time limit and a minimum passing score of 71%. GIAC periodically reviews exam specifications, so candidates should confirm the current format in the Certification Information section of their GIAC account before sitting the exam.
GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page.
GCCC is built for security professionals, auditors, CIOs, and risk officers, along with information assurance auditors, system implementers and administrators, network security engineers, IT administrators, and DoD personnel and contractors. It also fits compliance analysts and security vendors or consulting groups who need to stay current on control frameworks for clients.
SEC566: Implementing and Auditing CIS Controls is the SANS course built to prepare you for the GCCC exam. Across five sections and 23 hands-on labs, it walks through every CIS Control the exam covers, plus four rounds of Cyber42 leadership simulations that put each control into practice, including expanded coverage of applying the controls to AI models, data, and pipelines.