Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Entry-level

CIS Controls Implementation Group 1

Implementation Group 1 is the CIS Controls answer to a fair question: if we can only do a limited set of things, which ones. This four week course walks the IG1 safeguards in the order a small team can realistically complete them.

Every week you leave with something implemented or documented, not a reading list. The course suits small Canadian organizations and larger ones that need a defensible starting point.

Duration
4 weeks
Format
Live online, instructor-led
Prerequisites
None required
Class size
Capped at 12 learners
CIS Controls Implementation Group 1

What you will be able to do

  • Explain what the CIS Controls are and why Implementation Group 1 exists
  • Build and maintain an enterprise asset and software inventory
  • Apply secure configuration baselines to workstations, servers and cloud accounts
  • Implement multi-factor authentication on the accounts that matter most
  • Establish account and access management processes including timely removal
  • Set up basic audit log collection and know what to look at first
  • Configure malware defences, email and browser protections that hold up
  • Produce a backup and recovery approach you have actually tested

Course outline

5 modules

  • How the CIS Controls are structured and what a safeguard is
  • Implementation Groups 1, 2 and 3 and choosing yours honestly
  • Sequencing IG1 so early work makes later work easier
  • Assigning owners when the whole IT team is three people
  • Setting up the tracker and defining what evidence means

What you need before you start

  • Hands-on responsibility for IT or security in your organization
  • Administrative access to at least some of the systems you will be improving
  • No prior framework experience needed
  • Around three hours a week outside class for implementation work

Who this course is for

  • IT generalists carrying security responsibility in small organizations
  • Owners and managers of small businesses that need a defensible baseline
  • Managed service provider staff standardizing client security
  • Security newcomers who want a concrete framework rather than theory
  • Larger teams needing a credible starting point before a wider programme

Where this leads

Prepares you for

Security+

Awarded by CompTIA

The hygiene topics here overlap with CompTIA Security+ foundations, so this course is useful groundwork if you plan to sit that exam. CompTIA sets and awards Security+; this academy provides the training and practice only.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.