Choose your language
CIS Training Course
More than 2 million students worldwide

CIS Training Course

Master the CIS Controls and Benchmarks framework from the ground up and apply it across your entire organization. This course covers everything from asset inventory and secure configuration to incident response and security governance. You'll gain the hands-on knowledge to reduce attack surface, satisfy audit requirements, and build a defensible security program that scales.

Dedika for businesses

What you will learn:

This course takes you through the complete CIS framework, starting with core cybersecurity concepts and moving into practical implementation across networks, endpoints, identities, and cloud environments. You will learn how to assess organizational maturity, assign controls to the right Implementation Group, and build a phased adoption roadmap. Topics include secure configuration management, data protection, vulnerability scanning, penetration testing fundamentals, and SIEM operations. You will also develop skills in incident response, third-party risk management, security awareness program design, and executive communication. By the end, you will be equipped to lead a CIS-aligned security program from strategy through execution.

How you study in practice CIS Training Course

How you practice CIS Training Course

For companies looking to train their teams

With Dedika for businesses, the course includes exercises and examples tailored to your own business and the way your company needs.

Click here

Course Content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of CIS and Cybersecurity

  • Lesson 1 • Introduction to CIS Frameworks

    Covers the origin, purpose, and structure of CIS benchmarks and controls. Provides the conceptual baseline for all subsequent framework application.

  • Lesson 2 • Regulatory and Compliance Context

    Maps CIS controls to common compliance obligations without referencing specific legal codes. Students understand how CIS satisfies audit and regulatory requirements.

  • Lesson 3 • Asset Identification and Classification

    Teaches systematic inventory of hardware, software, and data assets. Asset classification directly enables prioritized control implementation.

  • Lesson 4 • Threat Landscape and Adversary Models

    Surveys current threat actors, attack categories, and adversary motivations. Grounds control selection in realistic threat scenarios.

  • Lesson 5 • Core Cybersecurity Concepts

    Introduces confidentiality, integrity, and availability as foundational pillars. Connects these principles to practical CIS control objectives.

Chapter 2See details

CIS Controls Implementation Groups

  • Lesson 1 • Roadmap Planning for Control Adoption

    Guides creation of a phased implementation roadmap aligned to business risk tolerance. Output is a prioritized control adoption schedule.

  • Lesson 2 • IG2 and IG3 Controls Overview

    Surveys the additional safeguards introduced at higher maturity levels. Students identify which controls require specialized tooling or expertise.

  • Lesson 3 • Organizational Maturity Assessment

    Provides tools to assess current security posture and select the appropriate starting group. Maturity scores drive the implementation roadmap built later.

  • Lesson 4 • Implementation Group Structure

    Explains the tiered IG1, IG2, and IG3 model and the criteria for group assignment. Establishes the prioritization logic used throughout the course.

  • Lesson 5 • IG1 Controls in Depth

    Examines each IG1 safeguard with configuration guidance and acceptance criteria. Mastery of IG1 is prerequisite to advancing to IG2 content.

Chapter 3See details

Secure Configuration Management

  • Lesson 1 • Application and Browser Hardening

    Covers secure configuration of productivity software, browsers, and common server applications. Reduces client-side and server-side attack vectors.

  • Lesson 2 • Configuration Validation and Drift Detection

    Introduces automated scanning tools to verify compliance and detect configuration drift. Continuous validation sustains the hardened baseline over time.

  • Lesson 3 • CIS Benchmark Structure and Usage

    Explains benchmark document layout, scoring levels, and applicability statements. Students navigate benchmarks efficiently to extract actionable guidance.

  • Lesson 4 • Network Device Configuration

    Applies CIS benchmarks to routers, switches, and firewalls. Properly configured network devices enforce segmentation and access control policies.

  • Lesson 5 • Operating System Hardening

    Applies benchmark recommendations to server and workstation operating systems. Hardened OS configurations form the foundation of endpoint security.

Chapter 4See details

Identity and Access Management Controls

  • Lesson 1 • Access Control Policies and Enforcement

    Translates CIS access safeguards into enforceable policy documents and technical controls. Policy enforcement closes gaps between documented intent and actual configuration.

  • Lesson 2 • Identity Monitoring and Anomaly Detection

    Applies log analysis and behavioral baselines to detect unauthorized access attempts. Identity monitoring feeds directly into the incident response process.

  • Lesson 3 • Account Management Fundamentals

    Covers account lifecycle from provisioning to deprovisioning aligned to CIS safeguards. Proper lifecycle management prevents orphaned and over-privileged accounts.

  • Lesson 4 • Privileged Access Management

    Addresses controls for administrative and service accounts with elevated permissions. PAM reduces the blast radius of credential compromise.

  • Lesson 5 • Authentication Mechanisms and MFA

    Examines password policies, multi-factor authentication, and passwordless options. Strong authentication directly satisfies multiple CIS safeguards.

Chapter 5See details

Data Protection and Privacy Controls

  • Lesson 1 • Secure Data Disposal and Retention

    Defines retention schedules and secure disposal methods for physical and digital media. Proper disposal eliminates residual data exposure after asset decommission.

  • Lesson 2 • Data Inventory and Classification

    Establishes a repeatable process for discovering, cataloging, and classifying sensitive data. Classification drives encryption and handling requirements downstream.

  • Lesson 3 • Data Loss Prevention Strategies

    Introduces DLP tooling, policy rules, and endpoint controls to prevent unauthorized data exfiltration. DLP complements encryption by controlling data movement.

  • Lesson 4 • Backup and Recovery Controls

    Aligns CIS backup safeguards with recovery time and recovery point objectives. Tested backups are the last line of defense against ransomware and data loss.

  • Lesson 5 • Encryption at Rest and in Transit

    Covers algorithm selection, key management, and deployment patterns for data encryption. Encryption satisfies CIS safeguards and common regulatory obligations.

Chapter 6See details

Network Security and Monitoring

  • Lesson 1 • Continuous Network Monitoring Operations

    Establishes operational procedures for sustained network visibility and threat hunting. Continuous monitoring transforms reactive detection into proactive defense.

  • Lesson 2 • Security Information and Event Management

    Configures SIEM platforms to aggregate, correlate, and alert on security events. SIEM is the operational hub for CIS continuous monitoring requirements.

  • Lesson 3 • Intrusion Detection and Prevention

    Deploys IDS and IPS sensors aligned to CIS monitoring safeguards. Signature and behavioral detection provide layered visibility into network threats.

  • Lesson 4 • Network Architecture and Segmentation

    Applies CIS guidance to design segmented network zones that limit lateral movement. Segmentation is foundational to all subsequent monitoring and detection work.

  • Lesson 5 • Firewall and Perimeter Controls

    Covers rule-base design, change management, and review cycles for perimeter firewalls. Effective perimeter controls reduce inbound and outbound threat exposure.

Chapter 7See details

Vulnerability Management and Penetration Testing

  • Lesson 1 • Vulnerability Management Program Design

    Defines scope, cadence, and roles for an enterprise vulnerability management program. A structured program ensures consistent identification and remediation of weaknesses.

  • Lesson 2 • Remediation Prioritization and Tracking

    Applies risk-based scoring to prioritize remediation efforts across large finding sets. Tracking closure rates demonstrates measurable risk reduction to stakeholders.

  • Lesson 3 • Penetration Testing Fundamentals

    Introduces penetration testing methodology, scoping, and rules of engagement aligned to CIS. Students understand how pen test findings map to specific CIS safeguards.

  • Lesson 4 • Reporting and Continuous Improvement

    Structures vulnerability and pen test reports for technical and executive audiences. Trend analysis drives continuous improvement of the security program.

  • Lesson 5 • Vulnerability Scanning and Assessment

    Covers authenticated and unauthenticated scanning techniques and result interpretation. Accurate scan results are the input to prioritized remediation workflows.

Chapter 8See details

Incident Response and Security Program Governance

  • Lesson 1 • Security Program Governance and Metrics

    Integrates CIS controls into a governance framework with measurable KPIs and executive reporting. Governance structures sustain the security program beyond individual projects.

  • Lesson 2 • Incident Detection and Classification

    Defines detection sources, triage criteria, and severity classification for security incidents. Accurate classification ensures proportionate and timely response actions.

  • Lesson 3 • Containment, Eradication, and Recovery

    Covers tactical response steps from isolation through root-cause removal and system restoration. Structured containment limits damage while preserving forensic evidence.

  • Lesson 4 • Incident Response Program Foundations

    Establishes IR policy, team structure, and communication protocols aligned to CIS safeguards. A documented IR program reduces response time and limits breach impact.

  • Lesson 5 • Post-Incident Review and Lessons Learned

    Guides structured post-incident reviews that produce actionable improvement items. Lessons learned close control gaps identified during real incidents.

Certification

Your valid completion certificate

This course is for you:

  • IT administrators: ready to formalize their organization's security practices.

  • Security analysts: looking to deepen expertise in structured control frameworks.

  • Network engineers: wanting to align infrastructure work with recognized security standards.

  • Compliance officers: seeking to connect regulatory obligations to technical security controls.

  • Career changers: transitioning into cybersecurity from adjacent IT or technical roles.

  • Small business IT managers: responsible for building a security program from scratch.

What our students say

Your classes are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to switch platforms... I thank you for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can switch chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the presentation style and video transcription, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top trainings

FAQ

Who is Dedika?

Is the certificate valid in United States?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course