Implementing and Auditing CIS Controls
Once basic hygiene is in place, the CIS Controls become a programme and an audit target. This eight week course covers implementing safeguards across a larger estate and then auditing them with evidence rather than a completed questionnaire.
You will build an audit programme for a set of controls, run it against sample evidence, and write findings that hold up when the control owner disagrees with you.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- CIS Controls Implementation Group 1
- Class size
- Capped at 12 learners

What you will be able to do
- Decide which Implementation Group your organization should target and defend it
- Prioritise safeguards by risk reduction and implementation effort
- Plan implementation across business units, cloud estates and acquired companies
- Write test steps that measure whether a safeguard operates, not whether it exists
- Sample sensibly and document working papers a reviewer can follow
- Distinguish a design failure from an operating failure in your findings
- Crosswalk CIS evidence to NIST CSF and ISO 27001 so it is collected once
- Report control efficacy to management with a defensible maturity picture
Course outline
6 modules
- What changes between Implementation Groups 1, 2 and 3
- Choosing a target group based on data sensitivity and threat exposure
- Governance: ownership, decision rights and funding
- Handling multiple business units with different starting points
- Setting a realistic multi-quarter implementation sequence
What you need before you start
- Completion of CIS Controls Implementation Group 1 or equivalent practical experience
- Working knowledge of enterprise IT operations and identity management
- Some exposure to audit, assurance or control testing is helpful but not required
- Around five hours a week outside class for audit programme work
Who this course is for
- Security and IT managers scaling a controls programme past basic hygiene
- Internal auditors testing technology and security controls
- Governance, risk and compliance staff who own control assurance
- Consultants assessing client control environments against CIS
Where this leads
Prepares you for
CISA
Awarded by ISACA
Audit planning, testing and reporting practice here supports preparation for ISACA CISA. ISACA administers that examination, verifies experience and issues the certificate. What you get from us is instruction, structured practice and feedback on your working papers.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



