Group Purchasing
Group Purchasing
AI SKILLSMAJOR UPDATES

SEC566: Implementing and Auditing CIS Controls

SEC566Cybersecurity Leadership, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 30 Hours (Self-Paced)
Course authored by:
Brian Ventura
Brian Ventura
SEC566: Implementing and Auditing CIS Controls
Course authored by:
Brian Ventura
Brian Ventura
  • GIAC Critical Controls Certification (GCCC)
  • 30 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 23 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Transform the CIS Controls into a defensible roadmap that strengthens security, ensures compliance, and prepares your organization for the future.

Course Overview

Learn to put the CIS Critical Security Controls v8.1 into action across IT, cloud, third-party, and emerging environments. This hands-on course shows you how to stop attacks mapped in the MITRE ATT&CK framework, strengthen programs through automation, and align security with compliance frameworks. Through 23 practical labs and 4 rounds of Cyber42 leadership simulations, you’ll gain the skills to build resilient, defensible cybersecurity programs that stand up to both threats and scrutiny.

Implementing and Auditing CIS Critical Controls

Cyber threats are constantly evolving, but the fundamentals of defense remain the same: organizations need a practical roadmap that cuts through complexity and prioritizes the actions that reduce the most risk. The CIS Controls provide exactly that — a proven, prioritized set of safeguards designed to stop the attacks that matter most and build lasting resilience.

SEC566 gives practitioners, auditors, and risk leaders the knowledge and hands-on experience to put the CIS Controls into practice with confidence. You will learn to design, implement, and audit safeguards across traditional IT, cloud, hybrid, and third-party ecosystems, with expanded coverage for AI-related technologies and workflows. We must keep our skills sharp as organizations adopt machine learning, automation, and intelligent decision-making systems — SEC566 provides a controls-focused foundation for securing AI models, protecting data, applying guardrails, and ensuring accountability to advanced and merging technology adoptions.

Students will learn how to apply the CIS Controls to AI model development and deployment, ensuring that security is integrated throughout the lifecycle of AI systems. You will learn through practical use cases how to safeguard training data, protect against model tampering, and maintain accountability in AI-driven decisions. This AI coverage builds on the core strengths of the course, giving students a holistic view of how the Controls defend both established systems and next-generation technologies. Through hands-on labs, practical tools, and Cyber42 leadership simulations, you will practice not only implementing the Controls but also measuring their effectiveness, automating coverage, and reporting outcomes in ways that resonate with executives and regulators. Learning mappings to frameworks such as NIST, ISO, and PCI-DSS ensures your work strengthens both compliance and security.

Whether your challenge is defending today’s enterprise from pervasive attacks or preparing for tomorrow’s AI-driven threat landscape, this course equips you to apply the CIS Controls with clarity, to prove effectiveness, and to build a resilient cybersecurity program.

Author Statement

"Understanding the threat landscape is complex. Understanding what to do next in addressing threats can be overwhelming when faced with the myriads of technologies and tools available. To further complicate the program, organizations must meet additional Compliance and Framework requirements. These competing approaches raise the questions: Are we doing the right thing to protect our organization? What is the most important thing to do next?

In SEC566: Implementing and Auditing CIS Controls, we aim to teach you how to answer those questions on a regular basis. The CIS Controls are a prioritized list of the most important, foundational safeguards to address the attacks occurring today and expected in the future. We hope to help students defend their information systems by implementing foundational safeguards. Students will learn how to align with and map CIS Controls directly into compliance and framework requirements. Students will also be able to measure control implementation and effectiveness, then report back to leadership at each level."

- Brian Ventura

What You'll Learn

  • Design and implement CIS Controls across IT, cloud, hybrid, and AI environments
  • Build metrics and risk scores to measure effectiveness and communicate residual risk
  • Streamline configuration, coverage, and compliance with automation and orchestration
  • Apply strong identity and access controls to secure users, services, and AI workflows
  • Enforce endpoint, network, and cloud defenses and extend to AI pipelines and training data
  • Establish a culture of continuous improvement through vulnerability management, secure configurations, and forward-looking defense

Business Takeaways

  • Reduce attack surface with a prioritized set of CIS Controls
  • Maximize ROI by focusing on safeguards with the highest risk reduction
  • Create a consistent, measurable security posture across systems, partners, and AI workflows
  • Demonstrate regulatory compliance and industry standard alignment through CIS mappings and measurable reporting
  • Strengthen detection and response against real-world and AI-enabled threats
  • Show measurable improvements with metrics, scoring, and automation
  • Build a sustainable, business-aligned program that earns executive support

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC566: Implementing and Auditing CIS Controls.

Section 1Introduction and Overview of the CIS Critical Controls

Learn the foundations of the CIS Controls framework, its evolution, and implementation strategies. Focus on enterprise asset inventory as the cornerstone of security, exploring tools and techniques to maintain accurate device tracking across complex networks.

Topics covered

  • CIS Critical Controls
  • Resources and tools of the CIS Controls
  • Mitre ATT&CK for common threats
  • Control assessments practice
  • CIS Control #1

Labs

  • Use the CIS Self-Assessment Tool (CSAT) for control assessment
  • Bonus Lab: Use Excel-based tools for control assessment
  • Inventory assets, software and user accounts with MS PowerShell

Overview

Students will learn the background and context for Version 8.1 of the CIS Controls. In addition, students will learn about the ecosystem of tools and resources to implement, measure, assess and report on the security program. These foundational concepts are key to prioritizing implementation of controls to address the ever-changing threat landscape. Focus will be placed on the evolving network landscape and how to apply the CIS Controls in modern environments, including in cloud and IoT technologies. Students will learn how to prioritize control implementation based on CIS Implementation Groups.

In this first course section, we will establish baseline knowledge of key terms used in the defensive domains. In addition, we will take a deep dive into Control #1, the Inventory and Control of Enterprise Assets. Any time a new device is installed on a network, there are risks of exposing the network to unknown vulnerabilities or even hampering its operation. Malicious code can take advantage of new hardware that is not configured and patched with appropriate security updates at the time of installation. Attackers can use these vulnerable systems to install backdoors before they are hardened. In automating CIS Control #1, it is critical that all devices be included in an accurate and up-to-date inventory control system. Devices include physical and logical devices, including cloud resources, virtualization, and containers. Any device not in the database should not be allowed to be connected to the network. Some organizations maintain asset inventories by using specific large-scale enterprise commercial products or by using free solutions to periodically track and sweep the network.

Full Topics Details

  • Understanding the CIS Critical Controls
  • Understanding the resources and tools related to the CIS Controls
  • Understanding control effectiveness against common threats leveraging Mitre ATT&CK
  • Understanding and practicing control assessments
  • CIS Control #1: Inventory and Control of Enterprise Assets

Full Lab Details

  • Preparing Student Laptops for Class
  • Performing a Gap Analysis: CSAT
  • Bonus Lab: Performing a Gap Analysis: Excel-based tools
  • Automating device, software and user account inventories with Powershell
  • Cyber42: leadership simulation game

Section 2Data Protection, Identity and Authentication

Become proficient in the defensive domains of software control, data protection, and identity management. Learn implementation techniques for secure configurations, privileged access controls, and effective account management systems.

Topics covered

  • Software asset management
  • Data protection strategies
  • Identity and access management (IAM) best practices
  • Secure access control implementation

Labs

  • Enforce application control with AppLocker
  • Bonus Lab: Use an inventory scanning tool
  • Encrypt data at rest with Veracrypt
  • Simulate privilege abuse with Mimikatz
  • Scenario-based leadership simulation game

Overview

During Section 2, the course will cover the defensive domains of software control, data protection, identification and authentication, and access control management. Students will learn how identity and access management (IAM) promotes data protection. Specifically, in Section 2 of the course students will learn the following defensive domains:

Inventory and Control of Software Assets

An organization without the ability to inventory and control the programs installed on its computer has more vulnerable systems and is more likely to be attacked. Furthermore, poorly managed machines are more likely to be outdated and to have needless software that introduces potential security flaws. Compromised systems become a staging point for attackers to collect sensitive information. In order to combat this threat, an organization should scan its network and identify known or responding applications. Commercial software and asset inventory tools are widely available. The best tools provide an inventory check of hundreds of common applications by leveraging standardized application names like those found in the Common Platform Enumeration (CPE) specification. These inventory tools pull the latest version of the application as well as pull information about the patch level of each installed program. In addition to inventory checks, tools that implement allow lists and deny lists of programs are included in many modern end-point protection security suites.

Data Protection

The loss of protected and sensitive data is a serious threat to business operations. consumer privacy, and potentially, national security. While some data is leaked or lost as a result of theft or espionage, the vast majority of these problems result from poorly understood data practices, including a lack of effective policy architectures and user error. The term "Data Loss Prevention" (DLP) refers to a comprehensive approach covering the people, processes, and systems that identify, monitor, and protect data in use (e.g., endpoint actions), data in motion (e.g., network actions), and data at rest (e.g., data storage) through deep content inspection and with a centralized management framework. For an effective DLP implementation, data management is crucial. Identifying, classifying and tagging data build a comprehensive data protection environment. The system must be capable of identifying unauthorized data that leaves the organization's systems whether via network file transfers or removable media.

Account Management

The most common method attackers use to infiltrate a target enterprise is through misuse of account privileges, whether those of a normal business user or privileged account. An attacker can easily convince a workstation user to open a malicious e-mail attachment, download and open a file from a malicious site, or surf to a site that automatically downloads malicious content. If the user is logged in as an administrator, the attacker has full access to the system. Built-in operating system features can extract lists of accounts with super-user privileges, both locally on individual systems and on overall domain controllers. These accounts should be monitored and tracked very closely.

Access Control Management

Some organizations do not carefully identify and separate sensitive data from less sensitive data and publicly available information within an internal network. In many environments, internal users have access to all or most of the information on the network. Once attackers have penetrated such a network, they can easily find and exfiltrate important information with little resistance. The Access Management Control is often implemented using the built-in separation of administrator accounts from non-administrator accounts. Further separation is needed based on need to know and least privilege concepts. The system must be able to detect all attempts by users to access files without the appropriate privileges and must generate an alert or e-mail for administrative personnel. This includes information on local systems or network accessible file shares.

Full Topics Details

  • CIS Control #2: Inventory and Control of Software Assets
  • CIS Control #3: Data Protection
  • CIS Control #5: Account Management
  • CIS Control #6: Access Control Management

Full Topic Details

  • Use Microsoft AppLocker to enforce application control
  • Bonus Lab: Stand-Alone Inventory Scanner
  • Bonus Lab: Building an Inventory
  • Use Veracrypt to Encrypt Data at Rest
  • Use Mimikatz to Abuse Privileged Access
  • Leverage Fleet and OSQuery to automate inventory and configuration compliance
  • Cyber42: leadership simulation game

Section 3Server, Workstation, Network Protections

Discover the inner workings of vulnerability management, secure configurations, and audit logging implementation. Gain proficiency in techniques to protect email and web browsing while maintaining comprehensive security baselines.

Topics covered

  • CIS Controls 4, 7, 8, and 9
  • Secure configuration frameworks
  • Vulnerability management systems
  • Audit logging implementation
  • Email protections

Labs

  • Use CIS-CAT tool for auditing configurations
  • Bonus Lab: Performing additional scans with CIS-CAT
  • Bonus Lab: Parse Nmap output with PowerShell for automated analysis and reporting
  • Explore Security Incident and Event Management (SIEM) solutions using ELK
  • Execute a vulnerability scan of AI models using Garak

Overview

During Section 3, the course will cover the defensive domains of configuration management, email and web browser integrity, vulnerability management, and audit and accountability. Specifically, students will learn the following defensive domains:

Continuous Vulnerability Management

Soon after security researchers and vendors discover and report new vulnerabilities, attackers create or update exploit code and launch it against targets of interest. Any significant delay in finding or fixing software with critical vulnerabilities provides ample opportunity for persistent attackers to break through and gain control of vulnerable machines. A large number of vulnerability scanning tools are available to evaluate the security configuration of systems. The most effective vulnerability scanning tools compare the results of the current scan with previous scans to determine how the vulnerabilities in the environment have changed over time. All machines and software identified by the asset inventory system must be scanned for vulnerabilities.

The discussion extends into AI and machine learning environments, where new attack surfaces—such as exposed model endpoints, poisoned datasets, or insecure pipeline dependencies—require specialized scanning and validation.

Learners are introduced to AI model vulnerability assessment using tools such as Garak, a framework designed to probe model interfaces for common security and privacy flaws (e.g., prompt injection, data leakage, and insecure output handling). By applying these techniques, organizations can integrate AI security testing directly into their broader vulnerability management lifecycle, ensuring consistent visibility across both traditional and intelligent systems.

Secure Configuration of Enterprise Assets and Software

Default configurations of software are often geared to ease-of-deployment and ease-of-use and not security, leaving some systems exploitable in their default state. Attackers attempt to exploit both network-accessible services and client software using various forms of malware. Without the ability to inventory and control installed and running software, enterprises make their systems more vulnerable. Organizations can implement this control by developing a series of images and secure storage servers for hosting these standard images. Configuration management tools can be employed to measure the settings of the installed software and to look for deviations from the standard image configurations used by the organization.

This topic also introduces secure configuration management for AI infrastructure, including containerized environments, model-serving platforms, and data preprocessing systems. Students review the risks of unsecured APIs, excessive permissions, and unmonitored dependencies that may exist in ML pipelines.

Discussions emphasize automation through orchestration tools and policy-as-code frameworks, ensuring that configuration security extends seamlessly across cloud, edge, and AI compute environments.

By reinforcing standardized baselines and automated validation, organizations can sustain security posture even as infrastructure evolves at machine speed.

Audit Log Management

At times, audit logs provide the only evidence of a successful attack. Many organizations keep audit records for compliance purposes but rarely review them. When audit logs are not reviewed, organizations do not know their systems have been compromised. Attackers rely on this. Most free and commercial operating systems, network services, and firewall technologies offer logging capabilities. Such logging should be activated, and logs should be sent to centralized logging servers. The system must be capable of logging all events across the network. The logging must be validated across both network and host-based systems.

Email and Web Browser Protections

Web browsers and email clients are very common points of entry and attack because of their high technical complexity and flexibility, and their direct interaction with users and within the other systems and websites. Content can be crafted to entice users into taking actions that greatly increase risk and allow for introduction of malicious code, loss of valuable data, and other attacks. Organizations must minimize the attack surface and the opportunities for attackers to manipulate human behavior through their interaction with web browsers and email systems.

Full Topics Details

  • CIS Control #7: Continuous Vulnerability Management
  • CIS Control #4: Secure Configuration of Enterprise Assets and Software
  • CIS Control #8: Audit Log Management
  • CIS Control #9: Email and Web Browser Protections

Full Lab Details

  • Perform a vulnerability scan
  • Compare a vulnerability report with patching services to identify gaps
  • Use the CIS-CAT Tool to Audit Configurations
  • Apply secure configuration via Group Policy and compare results
  • Parse Nmap Output with PowerShell
  • Cyber42: leadership simulation game

Section 4Network Infrastructure and Defense

Delve into advanced system protections: malware defenses, data recovery, and network infrastructure security. Learn to monitor network traffic and detect malicious activities using practical tools.

Topics covered

  • Malware defense implementation and automation
  • Applying CIS Controls to AI Workflows
  • Data recovery strategies and testing
  • Network infrastructure hardening and management
  • Network monitoring and intrusion detection

Labs

  • Building Secure Configurations for AI workflows using Amazon Bedrock Guardrails
  • Use CIS Navigator to map controls across frameworks and compliance standards
  • Use CIS Navigator mapping and model control mappings in a sample GRC system
  • Audit network devices with Nipper for misconfiguration and rule-set consistency
  • Scenario-based leadership simulation game

Overview

Section 4 will cover the defensive domains of system integrity, system and communications protection, configuration management, and media protection. Specifically, during this section of the course, students will learn the following cybersecurity controls: malware defense, network and endpoint detection and response, data recovery, and network device management

Malware Defenses

Malicious software is a fundamental and dangerous aspect of Internet threats because it targets end users and organizations via web browsing, e-mail attachments, mobile devices, and other vectors. Malicious code may tamper with a system's components, capture sensitive data, and spread infected code to other systems. To ensure anti-virus signatures are up to date, effective organizations use automation including the built-in administrative features of enterprise endpoint security suites to verify that anti-virus, anti-spyware, and host-based Intrusion Detection Systems (IDS) features are active on every managed system. They also run automated assessments daily and review the results to find and mitigate systems that have deactivated such protections or do not have the latest malware definitions. The system must identify any attempted or successful installation or execution of malicious software on a computer system.

Data Recovery

When attackers compromise machines, they often make significant changes to configurations and software. Sometimes attackers also make subtle alterations of data stored on compromised machines, potentially jeopardizing organizational effectiveness with polluted information. Once per quarter, a testing team should evaluate a random sample of system backups by attempting to restore full systems onto a test bed environment. The restored systems should be verified to ensure that the operating system, application, and data from the backup are all intact and functional.

Network Infrastructure Management

Attackers penetrate defenses by searching for electronic holes and misconfigurations in firewalls, routers, and switches. Once these network devices have been exploited, attackers can gain access to target networks, redirect traffic to a malicious system masquerading as a trusted system, and intercept and alter data while in transmission. Organizations can use commercial tools that will evaluate the rule set of network filtering devices in order to determine whether they are consistent or in conflict and to provide an automated check of network filters. Additionally, these commercial tools search for errors in rule sets. Such tools should be run each time significant changes are made to firewall rule sets, router access control lists, or other filtering technologies.

Network Monitoring and Defense

By attacking Internet-facing systems, attackers can create a relay point or bridgehead to break into other networks or internal systems. Automated tools can be used to exploit vulnerable entry points into a network. To control the flow of traffic through network borders and to look for attacks and evidence of compromised machines, boundary defenses should be multi-layered. These boundaries should consist of firewalls, proxies, DMZ perimeter networks, and network-based intrusion prevention systems and intrusion detection systems. Organizations should regularly test these sensors by launching vulnerability-scanning tools. These tools verify that the scanner traffic triggers an appropriate alert. The captured packets of the Intrusion Detection Systems (IDS) sensors should be reviewed using an automated script each day to ensure that log volumes are within expected parameters, are formatted properly, and have not been corrupted.

Full Topics Details

  • CIS Control #10: Malware Defenses
  • CIS Control #11: Data Recovery
  • CIS Control #12: Network Infrastructure Management
  • CIS Control #13: Network Monitoring and Defense

Full Lab Details

  • Building Secure Configurations for AI workflows using Amazon Bedrock Guardrails
  • Use CIS Navigator to map controls across frameworks and compliance standards
  • Use CIS Navigator mapping and model control mappings in a sample GRC system
  • Audit network devices with Nipper for misconfiguration and rule-set consistency
  • Use Wireshark and ngrep to emulate Data Loss Prevention (DLP) techniques
  • Cyber42: leadership simulation game

Section 5Governance and Operational Security

Develop skills in governance domains including security awareness, service provider management, and incident response. Discover techniques for app security, effective security management, and penetration testing.

Topics covered

  • Security awareness training
  • Service provider management
  • Application security implementation
  • Incident response frameworks
  • Penetration testing

Labs

  • Build robust tabletop exercises
  • Use CIS-RAM for risk assessment
  • Assess an organization, then prioritize and report on residual risk
  • Develop security program metrics
  • Scenario-based leadership simulation game

Overview

Section 5 will cover the defensive domains of security awareness, service provider management, application development security, incident management, and penetration testing. Specifically, during this section of the course, students will learn about the following cybersecurity domains:

Security Awareness and Skills Training

An organization hoping to effectively identify and respond to attacks effectively relies on its employees and contractors to find the gaps and fill them. A solid security skills assessment program can provide actionable information to decision-makers about where security awareness needs to be improved. It can also help determine proper allocation of limited resources to improve security practices. The key to upgrading skills is measurement–not with certification examinations, but with assessments that show both the employee and the employer where knowledge is sufficient and where there are gaps. Once the gaps have been identified, those employees who have the requisite knowledge can be called upon to mentor the employees who do not. The organization can also develop training programs that directly maintain employee readiness.

Service Provider Management

More and more organizations use third-party service providers to supplement their technology needs or services. Examples of service providers include outsourced consultants, IT providers, payroll providers, electronic billing providers, manufacturers, hardware and software providers, and more. Third parties can introduce additional risks to the security posture of organizations through remote connections, business-to-business networks, and the sharing and processing of data.

Special emphasis is placed on third parties providing AI or data processing services, as these introduce additional risks such as data exposure, model tampering, and unauthorized reuse of training data. By combining strong contractual governance with continuous monitoring, organizations can maintain trust and accountability across complex digital ecosystems.

Application Software Security

Criminal organizations frequently attack vulnerabilities in both web-based and non-web-based application software. In fact, this is a top priority for criminals. Application software is vulnerable to remote compromise in three ways:

  • It does not properly check the size of user input
  • It fails to sanitize user input by filtering out potentially malicious character sequences
  • It does not properly initialize and clear variables

To avoid attacks, internally-developed and third-party application software must be carefully tested to find security flaws. Source code testing tools, web application security scanning tools, and object code testing tools have proven useful in securing application software. Another useful tool is manual penetration testing of application security by testers who have extensive programming knowledge and application penetration testing expertise. The system must be capable of detecting and blocking an application-level software attack and must generate an alert or send e-mail to enterprise administrative personnel.

A significant update introduces AI and machine learning security within application development—emphasizing the unique risks associated with model-driven systems.

This content references both the OWASP Top 10 for Large Language Models (LLMs) and Google’s Secure AI Framework (SAIF) to guide secure AI system design. Students will learn about building security into AI development, like:

  • Protecting against prompt injection, data leakage, and model manipulation.
  • Securing model supply chains, dependencies, and APIs.
  • Implementing secure data handling for training and inference environments.
  • Applying SAIF principles such as “secure the AI supply chain” and “automate defenses.”

By aligning traditional application security with AI-specific frameworks, learners develop a holistic understanding of how to safeguard both code and intelligence systems in production environments.

Incident Response Management

Without an incident response plan, an organization may not discover an attack in the first place. Even if the attack is detected, the organization may not follow proper procedures to contain damage, eradicate the attacker's presence, and recover securely. Thus, the attacker may have a major impact even when detected, causing more damage, infecting more systems, and possibly exfiltrating more sensitive data than would otherwise be possible. After defining detailed incident response procedures, the incident response team should engage in periodic scenario-based training, including working through a series of attack scenarios that are fine-tuned to the threats and vulnerabilities the organization faces.

Penetration Testing

Attackers penetrate networks and systems through social engineering and by exploiting vulnerable software and hardware. Penetration testing involves mimicking the actions of computer attackers and exploiting vulnerabilities to determine what kind of access an attacker can gain. Each organization should define a clear scope and the rules of engagement for penetration testing and red team analyses. The scope of such projects should include, at a minimum, systems with the highest-value information and production processing functionality.

Modern testing now extends to AI-enabled applications and APIs, with red teams evaluating model exposures, adversarial input handling, and data poisoning resilience. By simulating real-world attack conditions, organizations can proactively identify weaknesses before adversaries exploit them.

Full Topic Details

  • CIS Control #14: Security Awareness and Skills Training
  • CIS Control #15: Service Provider Management
  • CIS Control #16: Application Software Security
  • CIS Control #17: Incident Response Management
  • CIS Control #18: Penetration Testing

Full Lab Details

  • Performing phishing tests with GoPhish
  • Build robust Incident Response Tabletop Exercises
  • Use CIS Risk Assessment Model (CIS-RAM) to identify, prioritize and report on residual risk
  • Document next steps in the CIS Control journey
  • Cyber42: Leadership simulation game

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • The lab range requires the ability to run Remote Desktop Protocol (RDP), called "Windows App" on MacOS. Also the student must be able to install OpenVPN and successfully make a VPN connection. Corporate machines may have corporate VPN, intercepting proxy, or egress firewall filter that causes connection issues establishing OpenVPN connections and running Remote Desktop/Windows App.
  • Optionally, having a portable external monitor helps to view the online workbook and perform labs on separate screens.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10 or Windows 11.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Local Administrator Access is required. (Yes, this is absolutely required. Do not let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • You should ensure that antivirus or endpoint protection software is disabled or fully removed, or that you have the administrative privileges to do so. Many of our courses require full administrative access to the operating system, and these products can prevent you from completing the labs.
  • Any filtering of egress traffic may prevent you from accomplishing the labs in your course. Firewalls should be disabled, or you must have the administrative privileges to disable it.
  • Microsoft Office (any version) or OpenOffice must be installed on your host. Note that you can download Office Trial Software online (free for 30 days).
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

If you have additional questions about the laptop specifications, please contact customer service.

SEC566 training is recommended for a diverse range of individuals, including:

  • Information Assurance Auditors
  • System Implementers or Administrators
  • Compliance Analysts
  • IT Administrators
  • Department of Defense (DoD) personnel or contractors
  • Federal agencies or clients
  • Private sector organizations looking to improve information assurance processes and secure their systems
  • Security vendors and consulting groups looking to stay current with frameworks for information assurance

The GIAC Critical Controls Certification (GCCC) certification is based on the CIS Critical Security Controls, a prioritized, risk-based approach to security. This certification ensures that candidates have the knowledge and skills to implement and execute the CIS Critical Controls recommended by the Center for Internet Security, and perform audits based on the standard.

  • Background, purpose, implementation, and auditing of the 18 CIS Critical Security Controls (Version 8).
  • Defenses, implementation groups, control sensors, policies, cloud guidance, tools, automation, control measures, and standards mapping for each CIS Critical Security Control.

More Certification Details

  • Printed and electronic courseware
  • MP3 audio files of the complete course lecture
  • Access to the Cyber42 web app

Students should have a basic understanding of information security concepts and technologies, familiarity with common security tools, and an understanding of IT infrastructure components including networks, servers, and applications. SEC401: Security Essentials or equivalent knowledge is recommended.

This course equips individuals with the knowledge, skills and foundational components to build a strong security program, measure effectiveness, and meet security requirements by leveraging the CIS Controls. Throughout the course, we will dive deep into implementation details for each CIS Control and provide actionable measurements of results. Participants gain experience with CIS-Control-focused tools and techniques available in the CIS ecosystem. For any strong program, teams must measure successes and report to leadership. SEC566 ensures participants understand what to measure, how to measure, and how to practice building metrics to report.

SEC566 is part of the Cybersecurity Leadership curriculum and one of the three pillars of the SANS Operational Cybersecurity Executive Triad, alongside LDR516 and LDR551. SEC566 provides the foundational components for a strong program. LDR551 adds the Security Operations team components and LDR516 enhances the vulnerability program. Together, these courses form a comprehensive pathway designed to develop well-rounded security leaders who can build effective cyber defense teams, implement CIS Controls, measure program effectiveness, and design robust vulnerability management programs.

The CIS Critical Security Controls are a prioritized set of actions that collectively form a defense-in-depth approach to cybersecurity. They were developed by a community of IT security experts to address the most common attack patterns and provide organizations with concrete steps to improve their security posture. 

SEC566 equips professionals with practical skills that are in demand across compliance, security operations, and leadership roles. Graduates of this CIS Controls training course are prepared to lead control implementation efforts, measure program success, and contribute to audit readiness and risk reduction initiatives. Achieving a CIS certification enhances your credibility and career opportunities in roles such as security architect, compliance officer, risk manager, or GRC professional.

Relevant Job Roles

Cybersecurity Auditor Training, Salary, and Career Path

European Cybersecurity Skills Framework

Perform cybersecurity audits on the organisation’s ecosystem. Ensuring compliance with statutory, regulatory, policy information, security requirements, industry standards and best practices.

Explore learning path

Operational Cybersecurity Executive

Cybersecurity Leadership

Lead operational teams from the point of view of an adversary in order to protect your most sensitive assets.

Explore learning path

Cybersecurity Research & Development

SCyWF: Cybersecurity Architecture, Research And Development

This role conducts conducts cybersecurity research and development. Find the SANS courses that map to the Cybersecurity Research & Development SCyWF Work Role.

Explore learning path

Cyber Legal, Policy & Compliance Officer

European Cybersecurity Skills Framework

Manages compliance with cybersecurity-related standards, legal and regulatory frameworks based on the organisation’s strategy and legal requirements.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Risk Management (BURM)

Skills Framework for the Information Age

Analysis of threats, vulnerabilities, and potential impacts to support prioritised risk mitigation. Outputs inform investment decisions and align cyber risk with business tolerance levels.

Explore learning path

Defensive Cybersecurity (OPM 511)

NICE: Protection and Defense

Responsible for analyzing data collected from various cybersecurity defense tools to mitigate risks.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 11

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources