CIS Controls v8 Implementation and Assessment Training Course
| Course code | SD-CS-056 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evidence is commonly spread across vulnerability tools, policies, ticket queues and audit findings. CIS Controls v8 provides a practical structure for turning that fragmented activity into an ordered cyber security improvement programme. This course helps practitioners assess their current control environment, identify implementation gaps and produce a defensible roadmap rather than a generic compliance checklist.
Participants work through all 18 CIS Controls v8 and the associated Safeguards, with particular attention to Implementation Groups (IG1, IG2 and IG3), asset and software inventories, secure configuration, access control, vulnerability management, logging, incident response and service provider management. They learn to scope an assessment, collect and test evidence, rate safeguard implementation, distinguish design gaps from operating gaps, and prioritise remediation using risk, dependency and effort criteria. The course also maps CIS Controls v8 activity to NIST CSF 2.0 outcomes for clearer reporting to governance and assurance stakeholders.
Instructor-led briefings are combined with a realistic organisational case study, guided evidence reviews, group scoring workshops and remediation-planning exercises. Participants use CIS Controls v8 assessment structures and CIS RAM concepts to build a control profile, record evidence, assign accountable owners and sequence actions. Each participant leaves with a completed CIS Controls v8 assessment pack: a scoped control profile, safeguard gap register, prioritised remediation roadmap, ownership model and management-ready reporting outline that can be adapted for use in their own organisation.
The course is designed for cyber security, IT risk, audit and technology operations professionals who already work with security controls and need a repeatable method for implementation assessment and improvement planning.
Course objectives
By the end of this course, participants will be able to:
- Scope a CIS Controls v8 assessment using organisational boundaries, critical services and Implementation Groups
- Classify assets, software, identities and data flows to establish the evidence base for control assessment
- Evaluate implementation of CIS Controls v8 Safeguards using documented, technical and operational evidence
- Differentiate control design deficiencies from operating-effectiveness gaps in an assessment register
- Apply CIS RAM concepts to express control gaps, risk scenarios and treatment priorities
- Map CIS Controls v8 Safeguards to NIST CSF 2.0 outcomes for governance and assurance reporting
- Build a prioritised remediation roadmap using risk, dependencies, accountable owners and delivery effort
- Produce a management-ready CIS Controls v8 assessment report with findings, decisions and next actions
Benefits of attending
For you
- Gain a repeatable assessment method for evaluating CIS Safeguards beyond simple tick-box compliance
- Develop evidence-testing judgement for distinguishing implemented controls from controls that operate reliably
- Create a portfolio-ready CIS Controls v8 assessment pack and remediation roadmap
- Improve credibility when presenting technical control gaps to risk committees, auditors and senior managers
- Prepare to lead CIS Controls-based improvement initiatives across infrastructure, cloud and endpoint teams
For your organisation
- Establish a common control assessment language across security, IT operations, risk and internal audit
- Identify high-value safeguard gaps before they become audit findings, incidents or uninsured exposures
- Prioritise remediation funding using documented risk, control dependencies and accountable ownership
- Improve evidence quality for customer assurance requests, internal audits and regulatory reviews
- Create an actionable CIS Controls v8 roadmap aligned to business-critical services and implementation maturity
Target competencies
Who should attend
- Cyber Security Managers — who need a structured method to measure and improve their control environment
- Information Security Analysts — who collect evidence, assess safeguard implementation and track remediation
- IT Risk Managers — who must translate technical control gaps into prioritised business risk treatment
- Security Architects — who design control patterns and need to align technical services to CIS Safeguards
- Internal Auditors — who review control design and require consistent criteria for testing operating evidence
- IT Operations and Infrastructure Managers — who own configuration, patching, identity and logging controls
Requirements and prerequisites
Participants should have practical familiarity with core information security concepts, including asset management, access control, vulnerability management, secure configuration, logging and incident response. Experience working with security policies, audit evidence, risk registers, service management tickets or control reviews is useful. Participants should be able to interpret a basic network or cloud service architecture and discuss how technical controls operate. No prior CIS Controls certification, formal audit qualification, coding ability or specialist GRC platform experience is required. A laptop with spreadsheet and document-editing capability is recommended for workshop exercises.
Training methodology
The five-day programme combines focused instructor-led explanation with progressive assessment workshops based on a realistic multi-site organisation. Participants interpret the CIS Controls v8 structure, examine sample architecture diagrams, policies, configuration records, vulnerability reports and log-management evidence, then score Safeguards in small groups. Case discussions test decisions around Implementation Group selection, evidence sufficiency and remediation priority. The final day is an application-planning workshop in which participants adapt the assessment approach to their own environment and prepare a first-phase implementation plan.
Course outline
Day 1: CIS Controls v8 foundations and assessment scope
- CIS Controls v8 structure: Controls, Safeguards and asset types
- Implementation Groups IG1, IG2 and IG3 selection criteria
- Control ownership across security, IT operations and business services
- Assessment scoping by organisational boundary and critical service
- Asset, software, identity and data-flow discovery requirements
- Evidence sources for design and operating-effectiveness assessment
- CIS Controls v8 relationship to NIST CSF 2.0 functions and outcomes
Workshop: Participants define an assessment scope and select an Implementation Group for a case-study organisation, producing a scope statement and evidence-request list.
Day 2: Assessing foundational technical safeguards
- Enterprise asset inventory assessment under Control 1
- Software inventory and unauthorised software management under Control 2
- Data protection assessment under Control 3
- Secure configuration assessment under Control 4
- Account management testing under Control 5
- Access control management assessment under Control 6
- Vulnerability management evidence review under Control 7
Workshop: Participants inspect sample inventory, configuration, identity and vulnerability evidence to score foundational Safeguards and record evidence-based findings.
Day 3: Assessing protective, monitoring and response controls
- Audit log management assessment under Control 8
- Email and web browser protection under Control 9
- Malware defence assessment under Control 10
- Data recovery assessment under Control 11
- Network infrastructure management under Control 12
- Network monitoring and defence under Control 13
- Security awareness and skills training under Control 14
Workshop: Teams assess a simulated phishing-led security incident, producing a safeguard evidence matrix covering prevention, detection, recovery and user awareness.
Day 4: Risk-based gap analysis and remediation design
- Service provider management assessment under Control 15
- Application software security assessment under Control 16
- Incident response management assessment under Control 17
- Penetration testing assessment under Control 18
- CIS RAM risk scenario formulation for control deficiencies
- Design gap versus operating gap classification
- Remediation prioritisation using risk, dependency, effort and control coverage
Workshop: Participants convert assessment findings into a risk-ranked gap register, assigning risk scenarios, accountable owners, target dates and treatment recommendations.
Day 5: Reporting, roadmap governance and implementation planning
- CIS CSAT assessment workflow and reporting concepts
- Control maturity and implementation status reporting
- Remediation roadmap sequencing and quick-win identification
- RACI design for Safeguard ownership and evidence maintenance
- Metrics for safeguard coverage, overdue actions and risk reduction
- Executive reporting of residual risk and investment decisions
- NIST CSF 2.0 crosswalk for programme governance communication
Workshop: Participants produce and present a management-ready CIS Controls v8 roadmap containing priorities, owners, measures, milestones and a 90-day action plan.
Tools & standards covered
CIS Controls v8, CIS CSAT, CIS RAM v2.1, NIST Cybersecurity Framework 2.0
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
OWASP Application Security Verification Standard Implementation Training Course
Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…
Burp Suite Web Application Security Testing Training Course
Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …
Cloud Security Architecture for Solutions Architects Training Course
Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…
NIST Cybersecurity Framework Risk Management Training Course
Cybersecurity leaders are expected to explain which risks matter, who owns them, how controls reduce exposure, and when residual risk is acc…