CIS Controls v8 Implementation and Assessment Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-056
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security teams are often asked to demonstrate that their controls are effective, prioritised and connected to business risk, yet their evidence is commonly spread across vulnerability tools, policies, ticket queues and audit findings. CIS Controls v8 provides a practical structure for turning that fragmented activity into an ordered cyber security improvement programme. This course helps practitioners assess their current control environment, identify implementation gaps and produce a defensible roadmap rather than a generic compliance checklist.

Participants work through all 18 CIS Controls v8 and the associated Safeguards, with particular attention to Implementation Groups (IG1, IG2 and IG3), asset and software inventories, secure configuration, access control, vulnerability management, logging, incident response and service provider management. They learn to scope an assessment, collect and test evidence, rate safeguard implementation, distinguish design gaps from operating gaps, and prioritise remediation using risk, dependency and effort criteria. The course also maps CIS Controls v8 activity to NIST CSF 2.0 outcomes for clearer reporting to governance and assurance stakeholders.

Instructor-led briefings are combined with a realistic organisational case study, guided evidence reviews, group scoring workshops and remediation-planning exercises. Participants use CIS Controls v8 assessment structures and CIS RAM concepts to build a control profile, record evidence, assign accountable owners and sequence actions. Each participant leaves with a completed CIS Controls v8 assessment pack: a scoped control profile, safeguard gap register, prioritised remediation roadmap, ownership model and management-ready reporting outline that can be adapted for use in their own organisation.

The course is designed for cyber security, IT risk, audit and technology operations professionals who already work with security controls and need a repeatable method for implementation assessment and improvement planning.

Course objectives

By the end of this course, participants will be able to:

  • Scope a CIS Controls v8 assessment using organisational boundaries, critical services and Implementation Groups
  • Classify assets, software, identities and data flows to establish the evidence base for control assessment
  • Evaluate implementation of CIS Controls v8 Safeguards using documented, technical and operational evidence
  • Differentiate control design deficiencies from operating-effectiveness gaps in an assessment register
  • Apply CIS RAM concepts to express control gaps, risk scenarios and treatment priorities
  • Map CIS Controls v8 Safeguards to NIST CSF 2.0 outcomes for governance and assurance reporting
  • Build a prioritised remediation roadmap using risk, dependencies, accountable owners and delivery effort
  • Produce a management-ready CIS Controls v8 assessment report with findings, decisions and next actions

Benefits of attending

For you

  • Gain a repeatable assessment method for evaluating CIS Safeguards beyond simple tick-box compliance
  • Develop evidence-testing judgement for distinguishing implemented controls from controls that operate reliably
  • Create a portfolio-ready CIS Controls v8 assessment pack and remediation roadmap
  • Improve credibility when presenting technical control gaps to risk committees, auditors and senior managers
  • Prepare to lead CIS Controls-based improvement initiatives across infrastructure, cloud and endpoint teams

For your organisation

  • Establish a common control assessment language across security, IT operations, risk and internal audit
  • Identify high-value safeguard gaps before they become audit findings, incidents or uninsured exposures
  • Prioritise remediation funding using documented risk, control dependencies and accountable ownership
  • Improve evidence quality for customer assurance requests, internal audits and regulatory reviews
  • Create an actionable CIS Controls v8 roadmap aligned to business-critical services and implementation maturity

Target competencies

Control scopingSafeguard assessmentEvidence evaluationRisk prioritisationRemediation roadmappingAssurance reporting

Who should attend

  • Cyber Security Managers — who need a structured method to measure and improve their control environment
  • Information Security Analysts — who collect evidence, assess safeguard implementation and track remediation
  • IT Risk Managers — who must translate technical control gaps into prioritised business risk treatment
  • Security Architects — who design control patterns and need to align technical services to CIS Safeguards
  • Internal Auditors — who review control design and require consistent criteria for testing operating evidence
  • IT Operations and Infrastructure Managers — who own configuration, patching, identity and logging controls

Requirements and prerequisites

Participants should have practical familiarity with core information security concepts, including asset management, access control, vulnerability management, secure configuration, logging and incident response. Experience working with security policies, audit evidence, risk registers, service management tickets or control reviews is useful. Participants should be able to interpret a basic network or cloud service architecture and discuss how technical controls operate. No prior CIS Controls certification, formal audit qualification, coding ability or specialist GRC platform experience is required. A laptop with spreadsheet and document-editing capability is recommended for workshop exercises.

Training methodology

The five-day programme combines focused instructor-led explanation with progressive assessment workshops based on a realistic multi-site organisation. Participants interpret the CIS Controls v8 structure, examine sample architecture diagrams, policies, configuration records, vulnerability reports and log-management evidence, then score Safeguards in small groups. Case discussions test decisions around Implementation Group selection, evidence sufficiency and remediation priority. The final day is an application-planning workshop in which participants adapt the assessment approach to their own environment and prepare a first-phase implementation plan.

Course outline

Day 1: CIS Controls v8 foundations and assessment scope

  • CIS Controls v8 structure: Controls, Safeguards and asset types
  • Implementation Groups IG1, IG2 and IG3 selection criteria
  • Control ownership across security, IT operations and business services
  • Assessment scoping by organisational boundary and critical service
  • Asset, software, identity and data-flow discovery requirements
  • Evidence sources for design and operating-effectiveness assessment
  • CIS Controls v8 relationship to NIST CSF 2.0 functions and outcomes

Workshop: Participants define an assessment scope and select an Implementation Group for a case-study organisation, producing a scope statement and evidence-request list.

Day 2: Assessing foundational technical safeguards

  • Enterprise asset inventory assessment under Control 1
  • Software inventory and unauthorised software management under Control 2
  • Data protection assessment under Control 3
  • Secure configuration assessment under Control 4
  • Account management testing under Control 5
  • Access control management assessment under Control 6
  • Vulnerability management evidence review under Control 7

Workshop: Participants inspect sample inventory, configuration, identity and vulnerability evidence to score foundational Safeguards and record evidence-based findings.

Day 3: Assessing protective, monitoring and response controls

  • Audit log management assessment under Control 8
  • Email and web browser protection under Control 9
  • Malware defence assessment under Control 10
  • Data recovery assessment under Control 11
  • Network infrastructure management under Control 12
  • Network monitoring and defence under Control 13
  • Security awareness and skills training under Control 14

Workshop: Teams assess a simulated phishing-led security incident, producing a safeguard evidence matrix covering prevention, detection, recovery and user awareness.

Day 4: Risk-based gap analysis and remediation design

  • Service provider management assessment under Control 15
  • Application software security assessment under Control 16
  • Incident response management assessment under Control 17
  • Penetration testing assessment under Control 18
  • CIS RAM risk scenario formulation for control deficiencies
  • Design gap versus operating gap classification
  • Remediation prioritisation using risk, dependency, effort and control coverage

Workshop: Participants convert assessment findings into a risk-ranked gap register, assigning risk scenarios, accountable owners, target dates and treatment recommendations.

Day 5: Reporting, roadmap governance and implementation planning

  • CIS CSAT assessment workflow and reporting concepts
  • Control maturity and implementation status reporting
  • Remediation roadmap sequencing and quick-win identification
  • RACI design for Safeguard ownership and evidence maintenance
  • Metrics for safeguard coverage, overdue actions and risk reduction
  • Executive reporting of residual risk and investment decisions
  • NIST CSF 2.0 crosswalk for programme governance communication

Workshop: Participants produce and present a management-ready CIS Controls v8 roadmap containing priorities, owners, measures, milestones and a 90-day action plan.

Tools & standards covered

CIS Controls v8, CIS CSAT, CIS RAM v2.1, NIST Cybersecurity Framework 2.0

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand common security controls such as patching, access management, secure configuration, logging and incident response. You do not need previous CIS Controls experience or an audit qualification, but the course moves beyond introductory cyber security concepts.

A laptop is recommended so you can complete assessment worksheets, evidence matrices and roadmap exercises. The course introduces CIS CSAT workflow concepts, but participants do not need an existing CIS CSAT account or licence.

It is most suitable for professionals responsible for implementing, testing, governing or improving cyber security controls. Security managers, analysts, IT risk practitioners, architects, auditors and infrastructure leaders will all work with relevant assessment scenarios.

This course centres on the operational assessment and implementation of CIS Controls v8 Safeguards, including evidence review, Implementation Group selection and remediation sequencing. It is not an ISO 27001 lead implementer course and does not focus primarily on management-system certification requirements.

You can use the assessment pack to scope a pilot review of a business service, technology estate or control domain. The same method supports evidence requests, safeguard scoring, risk-ranked findings, accountable ownership and a phased remediation roadmap.

You will leave with a completed case-study CIS Controls v8 assessment pack, including a scope statement, evidence matrix, safeguard gap register, risk priorities and 90-day roadmap. These templates can be adapted to your organisation's control environment and reporting process.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

OWASP Application Security Verification Standard Implementation Training Course

Application teams often have security requirements scattered across user stories, penetration-test findings, supplier questionnaires and pol…

5 Days Certificate

Burp Suite Web Application Security Testing Training Course

Web applications expose business processes, customer data and internal services through complex combinations of APIs, authentication flows, …

10 Days Certificate

Cloud Security Architecture for Solutions Architects Training Course

Solutions architects are expected to turn business requirements into cloud designs that are secure, scalable, operable and defensible during…

5 Days Certificate

NIST Cybersecurity Framework Risk Management Training Course

Cybersecurity leaders are expected to explain which risks matter, who owns them, how controls reduce exposure, and when residual risk is acc…