SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions.
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.
Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.
Mandatory System Hardware Requirements
Mandatory Host Configuration And Software Requirements
If you have additional questions about the laptop specifications, please contact customer service.
SEC566 training is recommended for a diverse range of individuals, including:
The GIAC Critical Controls Certification (GCCC) certification is based on the CIS Critical Security Controls, a prioritized, risk-based approach to security. This certification ensures that candidates have the knowledge and skills to implement and execute the CIS Critical Controls recommended by the Center for Internet Security, and perform audits based on the standard.
Students should have a basic understanding of information security concepts and technologies, familiarity with common security tools, and an understanding of IT infrastructure components including networks, servers, and applications. SEC401: Security Essentials or equivalent knowledge is recommended.
This course equips individuals with the knowledge, skills and foundational components to build a strong security program, measure effectiveness, and meet security requirements by leveraging the CIS Controls. Throughout the course, we will dive deep into implementation details for each CIS Control and provide actionable measurements of results. Participants gain experience with CIS-Control-focused tools and techniques available in the CIS ecosystem. For any strong program, teams must measure successes and report to leadership. SEC566 ensures participants understand what to measure, how to measure, and how to practice building metrics to report.
SEC566 is part of the Cybersecurity Leadership curriculum and one of the three pillars of the SANS Operational Cybersecurity Executive Triad, alongside LDR516 and LDR551. SEC566 provides the foundational components for a strong program. LDR551 adds the Security Operations team components and LDR516 enhances the vulnerability program. Together, these courses form a comprehensive pathway designed to develop well-rounded security leaders who can build effective cyber defense teams, implement CIS Controls, measure program effectiveness, and design robust vulnerability management programs.
The CIS Critical Security Controls are a prioritized set of actions that collectively form a defense-in-depth approach to cybersecurity. They were developed by a community of IT security experts to address the most common attack patterns and provide organizations with concrete steps to improve their security posture.
SEC566 equips professionals with practical skills that are in demand across compliance, security operations, and leadership roles. Graduates of this CIS Controls training course are prepared to lead control implementation efforts, measure program success, and contribute to audit readiness and risk reduction initiatives. Achieving a CIS certification enhances your credibility and career opportunities in roles such as security architect, compliance officer, risk manager, or GRC professional.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources