
CIS Training Course
Master the CIS Controls and Benchmarks framework from the ground up and apply it across your entire organisation. This course covers everything from asset inventory and secure configuration to incident response and security governance. You will gain the hands-on knowledge to reduce attack surface, satisfy audit requirements, and build a defensible security programme that scales.
What you will learn:
This course takes you through the complete CIS framework, starting with core cybersecurity concepts and moving into practical implementation across networks, endpoints, identities, and cloud environments. You will learn how to assess organisational maturity, assign controls to the right Implementation Group, and build a phased adoption roadmap. Topics include secure configuration management, data protection, vulnerability scanning, penetration testing fundamentals, and SIEM operations. You will also develop skills in incident response, third-party risk management, security awareness programme design, and executive communication. By the end, you will be equipped to lead a CIS-aligned security programme from strategy through execution.
How you study in practice CIS Training Course
How you practise CIS Training Course
For companies looking to train their teams
With Dedika for businesses, the course includes exercises and examples tailored to your company and its specific needs.
Course content
8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)
Chapter 1HideHide detailsSee detailsFoundations of CIS and Cybersecurity
Foundations of CIS and Cybersecurity
Lesson 1 • Introduction to CIS Frameworks
Covers the origin, purpose, and structure of CIS benchmarks and controls. Provides the conceptual baseline for all subsequent framework application.
Lesson 2 • Regulatory and Compliance Context
Maps CIS controls to common compliance obligations without referencing specific legal codes. Students understand how CIS satisfies audit and regulatory requirements.
Lesson 3 • Asset Identification and Classification
Teaches systematic inventory of hardware, software, and data assets. Asset classification directly enables prioritised control implementation.
Lesson 4 • Threat Landscape and Adversary Models
Surveys current threat actors, attack categories, and adversary motivations. Grounds control selection in realistic threat scenarios.
Lesson 5 • Core Cybersecurity Concepts
Introduces confidentiality, integrity, and availability as foundational pillars. Connects these principles to practical CIS control objectives.
Chapter 2HideHide detailsSee detailsCIS Controls Implementation Groups
CIS Controls Implementation Groups
Lesson 1 • Roadmap Planning for Control Adoption
Guides creation of a phased implementation roadmap aligned to business risk tolerance. Output is a prioritised control adoption schedule.
Lesson 2 • IG2 and IG3 Controls Overview
Surveys the additional safeguards introduced at higher maturity levels. Students identify which controls require specialised tooling or expertise.
Lesson 3 • Organisational Maturity Assessment
Provides tools to assess current security posture and select the appropriate starting group. Maturity scores drive the implementation roadmap built later.
Lesson 4 • Implementation Group Structure
Explains the tiered IG1, IG2, and IG3 model and the criteria for group assignment. Establishes the prioritisation logic used throughout the course.
Lesson 5 • IG1 Controls in Depth
Examines each IG1 safeguard with configuration guidance and acceptance criteria. Mastery of IG1 is prerequisite to advancing to IG2 content.
Chapter 3HideHide detailsSee detailsSecure Configuration Management
Secure Configuration Management
Lesson 1 • Application and Browser Hardening
Covers secure configuration of productivity software, browsers, and common server applications. Reduces client-side and server-side attack vectors.
Lesson 2 • Configuration Validation and Drift Detection
Introduces automated scanning tools to verify compliance and detect configuration drift. Continuous validation sustains the hardened baseline over time.
Lesson 3 • CIS Benchmark Structure and Usage
Explains benchmark document layout, scoring levels, and applicability statements. Students navigate benchmarks efficiently to extract actionable guidance.
Lesson 4 • Network Device Configuration
Applies CIS benchmarks to routers, switches, and firewalls. Properly configured network devices enforce segmentation and access control policies.
Lesson 5 • Operating System Hardening
Applies benchmark recommendations to server and workstation operating systems. Hardened OS configurations form the foundation of endpoint security.
Chapter 4HideHide detailsSee detailsIdentity and Access Management Controls
Identity and Access Management Controls
Lesson 1 • Access Control Policies and Enforcement
Translates CIS access safeguards into enforceable policy documents and technical controls. Policy enforcement closes gaps between documented intent and actual configuration.
Lesson 2 • Identity Monitoring and Anomaly Detection
Applies log analysis and behavioural baselines to detect unauthorised access attempts. Identity monitoring feeds directly into the incident response process.
Lesson 3 • Account Management Fundamentals
Covers account lifecycle from provisioning to deprovisioning aligned to CIS safeguards. Proper lifecycle management prevents orphaned and over-privileged accounts.
Lesson 4 • Privileged Access Management
Addresses controls for administrative and service accounts with elevated permissions. PAM reduces the blast radius of credential compromise.
Lesson 5 • Authentication Mechanisms and MFA
Examines password policies, multi-factor authentication, and passwordless options. Strong authentication directly satisfies multiple CIS safeguards.
Chapter 5HideHide detailsSee detailsData Protection and Privacy Controls
Data Protection and Privacy Controls
Lesson 1 • Secure Data Disposal and Retention
Defines retention schedules and secure disposal methods for physical and digital media. Proper disposal eliminates residual data exposure after asset decommission.
Lesson 2 • Data Inventory and Classification
Establishes a repeatable process for discovering, cataloging, and classifying sensitive data. Classification drives encryption and handling requirements downstream.
Lesson 3 • Data Loss Prevention Strategies
Introduces DLP tooling, policy rules, and endpoint controls to prevent unauthorised data exfiltration. DLP complements encryption by controlling data movement.
Lesson 4 • Backup and Recovery Controls
Aligns CIS backup safeguards with recovery time and recovery point objectives. Tested backups are the last line of defence against ransomware and data loss.
Lesson 5 • Encryption at Rest and in Transit
Covers algorithm selection, key management, and deployment patterns for data encryption. Encryption satisfies CIS safeguards and common regulatory obligations.
Chapter 6HideHide detailsSee detailsNetwork Security and Monitoring
Network Security and Monitoring
Lesson 1 • Continuous Network Monitoring Operations
Establishes operational procedures for sustained network visibility and threat hunting. Continuous monitoring transforms reactive detection into proactive defence.
Lesson 2 • Security Information and Event Management
Configures SIEM platforms to aggregate, correlate, and alert on security events. SIEM is the operational hub for CIS continuous monitoring requirements.
Lesson 3 • Intrusion Detection and Prevention
Deploys IDS and IPS sensors aligned to CIS monitoring safeguards. Signature and behavioural detection provide layered visibility into network threats.
Lesson 4 • Network Architecture and Segmentation
Applies CIS guidance to design segmented network zones that limit lateral movement. Segmentation is foundational to all subsequent monitoring and detection work.
Lesson 5 • Firewall and Perimeter Controls
Covers rule-base design, change management, and review cycles for perimeter firewalls. Effective perimeter controls reduce inbound and outbound threat exposure.
Chapter 7HideHide detailsSee detailsVulnerability Management and Penetration Testing
Vulnerability Management and Penetration Testing
Lesson 1 • Vulnerability Management Programme Design
Defines scope, cadence, and roles for an enterprise vulnerability management programme. A structured programme ensures consistent identification and remediation of weaknesses.
Lesson 2 • Remediation Prioritisation and Tracking
Applies risk-based scoring to prioritise remediation efforts across large finding sets. Tracking closure rates demonstrates measurable risk reduction to stakeholders.
Lesson 3 • Penetration Testing Fundamentals
Introduces penetration testing methodology, scoping, and rules of engagement aligned to CIS. Students understand how pen test findings map to specific CIS safeguards.
Lesson 4 • Reporting and Continuous Improvement
Structures vulnerability and pen test reports for technical and executive audiences. Trend analysis drives continuous improvement of the security programme.
Lesson 5 • Vulnerability Scanning and Assessment
Covers authenticated and unauthenticated scanning techniques and result interpretation. Accurate scan results are the input to prioritised remediation workflows.
Chapter 8HideHide detailsSee detailsIncident Response and Security Programme Governance
Incident Response and Security Programme Governance
Lesson 1 • Security Programme Governance and Metrics
Integrates CIS controls into a governance framework with measurable KPIs and executive reporting. Governance structures sustain the security programme beyond individual projects.
Lesson 2 • Incident Detection and Classification
Defines detection sources, triage criteria, and severity classification for security incidents. Accurate classification ensures proportionate and timely response actions.
Lesson 3 • Containment, Eradication, and Recovery
Covers tactical response steps from isolation through root-cause removal and system restoration. Structured containment limits damage while preserving forensic evidence.
Lesson 4 • Incident Response Programme Foundations
Establishes IR policy, team structure, and communication protocols aligned to CIS safeguards. A documented IR programme reduces response time and limits breach impact.
Lesson 5 • Post-Incident Review and Lessons Learned
Guides structured post-incident reviews that produce actionable improvement items. Lessons learned close control gaps identified during real incidents.
Your valid completion certificate
This course is for you:
IT administrators: ready to formalise their organisation's security practices.
Security analysts: looking to deepen expertise in structured control frameworks.
Network engineers: wanting to align infrastructure work with recognised security standards.
Compliance officers: seeking to connect regulatory obligations to technical security controls.
Career changers: transitioning into cybersecurity from adjacent IT or technical roles.
Small business IT managers: responsible for building a security programme from scratch.
What our students say
Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...

I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.

I like the content and the way videos are presented and transcribed, which speeds up the process!

The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.

Top qualifications
FAQ
Who is Dedika?
Is the certificate valid in South Africa?
Are the courses free?
What is the course workload?
What are the courses like?
How do the courses work?
What is the duration of the courses?
What is the cost or price of the courses?
What is an EAD or online course and how does it work?
PDF Course




















