Program Brief

Embark on a transformative journey with our SEC566: Implementing and Auditing CIS Controls course, designed to fortify your organization’s cybersecurity defenses. Over five intensive days, immerse yourself in mastering the CIS Critical Controls, a gold standard for securing IT systems and data. This program will equip you with the knowledge and practical skills to not only understand but effectively implement and audit these critical controls within your infrastructure. From gaining a deeper understanding of controls' structure and intent to leveraging tools and resources for bolstering security, this program covers it all. Engage in hands-on exercises that simulate real-world cybersecurity threats and responses, ensuring you’re battle-ready to protect your enterprise assets. Learn to assess control effectiveness, manage vulnerabilities, and navigate the complex landscape of IT security with confidence. Whether you're safeguarding software assets, enhancing data protection, or managing access controls, SEC566 provides the strategies and insights needed for a comprehensive cybersecurity framework. Perfect for IT professionals tasked with security management, auditing, and compliance, this program is your steppingstone to becoming a cybersecurity leader in your organization. Join us to elevate your skills, meet compliance standards, and lead with security excellence.

Program Topic
  • Signature Programs
Program Goals

At the end of the training program, the participant should be able to:

  • Understand the structure and intent behind CIS Critical Controls for effective cybersecurity defense mechanisms.
  • Gain expertise in utilizing the tools and resources associated with CIS Controls to bolster their organization’s security posture.
  • Learn to assess the effectiveness of implemented controls against common threats using frameworks like Mitre ATT&CK.
  • Acquire the skills to perform comprehensive control assessments to identify and mitigate vulnerabilities within their organization's security infrastructure.
  • Discover techniques for inventorying and controlling enterprise assets to prevent unauthorized access and use.
  • Implement and manage robust data protection controls to secure sensitive information against breaches and unauthorized disclosures.
  • Understand the importance of each control and how it is compromised if ignored.
  • Master strategies for effective account and access control management to ensure that only authorized users have access to critical systems.
  • xplain the defensive goals that result in quick wins and increased visibility of the network and systems.
  • Learn the best practices for managing audit logs, enabling effective monitoring and analysis of security-related events.
  • Acquire knowledge to secure email communications and web browsing activities within organization.
  • Understand the broader context of cybersecurity within organizational governance, focusing on developing a culture of security awareness and compliance.
  • Competently map CIS Controls to compliance and standards such as PCIDSS, the NIST Cybersecurity Framework (CSF), ISO 27000, and more.
Program Agenda
Module 1: Introduction and Overview of the CIS Controls
  • 1 Understanding the CIS Critical Controls

    • 2 Understanding the resources and tools related to the CIS Controls

      • 3 Understand control effectiveness against common threats leveraging Mitre ATT

        • 4 Understanding and practicing control assessments

          • 5 CIS Control 1: Inventory and Control of Enterprise Assets

            • 6 Exercises:

              • Preparing Student Laptops for Class

                • How to Use the AuditScripts CIS Critical Control Initial Assessment Tool

                  • Asset Inventory with Microsoft PowerShell

                  Module 2: Data Protection, Identity and Authentication, Access Control Management, Audit Log Management
                  • 1 CIS Control 2: Inventory and Control of Software Assets

                    • 2 CIS Control 3: Data Protection

                      • 3 CIS Control 5: Account Management

                        • 4 CIS Control 6: Access Control Management

                          • 5 Exercises:

                            • How to use Microsoft AppLocker to enforce Application Control

                              • How to Use Veracrypt to Encrypt Data at Rest

                                • How to Use Mimikatz to Abuse Privileged Access

                                  • Understanding Windows Management Instrumentation (WMI) for Baselining

                                  Module 3: Server, Workstation, Network Device Protections (Part 1)
                                  • 1 CIS Control 7: Continuous Vulnerability Management

                                    • 2 CIS Control 4: Secure Configuration of Enterprise Assets and Software

                                      • 3 CIS Control 8: Audit Log Management

                                        • 4 CIS Control 9: Email and Web Browser Protections

                                          • 5 Exercises:

                                            • sing PowerShell to Test for Software Updates

                                              • How to Use the CIS-CAT Tool to Audit Configurations

                                                • How to Parse Nmap Output with PowerShell

                                                  • How to use GoPhish to perform phishing simulations

                                                  Module 4: Server, Workstation, Network Device Protections (Part 2)
                                                  • 1 CIS Control 10: Malware Defenses

                                                    • 2 CIS Control 11: Data Recovery

                                                      • 3 CIS Control 12: Network Infrastructure Management

                                                        • 4 IS Control 13: Network Monitoring and Defense

                                                          • 5 Exercises:

                                                            • How to use CIS Navigator to map controls between Frameworks, Compliance and CIS Controls

                                                              • How to Use Nipper to Audit Network Device Configurations

                                                                • How to Use Wireshark to Detect Malicious Activity

                                                                  • How to Use Wireshark and Ngrep to emulate Data Loss Prevention

                                                                  Module 5: Governance and Operational Security
                                                                  • 1 CIS Control 14: Security Awareness and Skills Training

                                                                    • 2 CIS Control 15: Service Provider Management

                                                                      • 3 CIS Control 16: Application Software Security

                                                                        • 4 CIS Control 17: Incident Response Management

                                                                          • 5 CIS Control 18: Penetration Testing

                                                                            • 6 Exercises:

                                                                              • How to build robust Incident Response Tabletop Exercises

                                                                                • How to use CIS Risk Assessment Model (CIS-RAM) to identify, prioritize and report on residual risk

                                                                                Program Requirements

                                                                                Not Available

                                                                                Program Path

                                                                                Names of the training programs that are integrated (enriched) with the training program:

                                                                                • Not Available

                                                                                Names of the training programs that after the training program:

                                                                                • Not Available
                                                                                Program Method
                                                                                • Lecture
                                                                                • Case Studies
                                                                                • Practical Implementation
                                                                                • Exercises and assignments
                                                                                Evaluation Method
                                                                                • Simulation Test for professional exam
                                                                                Training Type
                                                                                • In Class Training

                                                                                Add Comment

                                                                                CAPTCHA

                                                                                Realted Program

                                                                                International Financial Reporting Standard 17

                                                                                Unlock the complexities of IFRS 17 with our comprehensive training program designed for finance and insurance professionals. Over four days, participants will gain an in-depth understanding of key principles, the General Measurement Model, and the Premium Allocation Approach. Our expert-led sessions combine lectures, case studies, and practical implementation to ensure mastery of IFRS 17 standards. Learn about reinsurance and regulatory requirements specific to Saudi Arabia, and gain insights into projecting cash flows in compliance with IFRS 17. Additionally, we cover IFRS 9, offering a holistic view of financial reporting and its impact on IFRS 17. Enhance your skills through hands-on training that includes interactive exercises and real-world examples. Our face-to-face sessions provide the perfect environment for learning and networking with peers. Don't miss this opportunity to stay ahead in the dynamic world of finance and insurance—register now to secure your spot and elevate your expertise to the next level. Join us and ensure compliance with the latest standards in financial reporting.

                                                                                Details

                                                                                Financial Modeling and Valuation Analyst

                                                                                This three-day Financial Modelling course equips participants with advanced skills in building and analyzing financial models, emphasizing best practices. It begins with the 8 principles of modelling best practice, covering topics like consistent timelines, formulae, circular references, and macros. The curriculum includes sessions on Model Design and Planning, exploring model types, valuation, transaction structuring, and data manipulation. Participants will engage in practical exercises, constructing models, handling complex calculations like IRR and NPV, and conducting scenario analyses. This course is essential for professionals seeking to enhance their financial modelling and decision-making skills.

                                                                                Details

                                                                                Investing in Fintech Business

                                                                                The program offers a comprehensive exploration of how technology is transforming finance. Through a series of expert-led lectures and interactive workshops, participants will delve into FinTech investment strategies and gain a thorough understanding of the sector’s dynamics. The curriculum includes an in-depth immersion into Silicon Valley’s ecosystem, providing valuable opportunities to connect with leading FinTech startups, seasoned investors, and industry experts. This experience highlights the lifecycle of ventures and strategies for strategic growth. Aimed at equipping attendees with critical insights, the program emphasizes the importance of legal compliance, the strategic value of investments, and the transformative impact of partnerships in the FinTech industry.

                                                                                Details

                                                                                Preparation Program for Certified Internal Auditor Exam (CIA®)- First Part

                                                                                A professional certificate accredited by the Institute of Internal Auditors, IIA, USA, an organization offered in the internal field of performance, as well as there is a need in the labor market for holders of this certificate, and hence the high value of the benefits and job opportunities for them. This certificate helps prepare a new generation of accountants with globally qualified professional qualifications, to face the economic challenges faced by business establishments. The CIA Internal Auditor Certificate in Part One focuses on the internal basics of studying internal concepts, the mandatory mountain, and techniques of Iranian auditing.

                                                                                Details

                                                                                Microsoft Excel- Advanced Level

                                                                                One of the basic skills needed to carry out daily tasks professionally is the ability to use Microsoft Excel to manage and create equations and statistics. This training program is designed to provide participants with the knowledge and skills necessary to use advanced technologies in Excel efficiently and effectively.

                                                                                Details

                                                                                International Financial Reporting Standards (IFRS)

                                                                                Accounting is the language of business, and it is an information system that provides a wide range of stakeholders with the financial information they need to make rational decisions in finance and investment. The accuracy of this information is important to users, so the International Accounting Standards Board IASB issued international accounting standards and international financial reporting standards to ensure the quality of this information. This course includes an explanation of the most important international accounting standards related to the preparation and presentation of financial statements and its included items matching with the IAS and IFRS requirements and meets the users’ needs

                                                                                Details

                                                                                Preparing Financial Reports

                                                                                The financial reports issued by the facility are considered as the outputs of its accounting system through which the results of the financial events related to the reporting period are presented and that help the beneficiaries of those reports to judge the state of the facility in terms of financial balance and the structure of financing the acquisition of assets, as well as showing its ability to generate revenue, and enables them From the analysis of the cost component structure. This training program is designed to provide participants with the knowledge and skills necessary to read and understand the components of financial reports and how to prepare them, and to review the most important presentation and disclosure requirements for international accounting standards and financial reporting standards.

                                                                                Details

                                                                                Risk Analysis and Management in Insurance Companies

                                                                                Risk management in insurance companies is an essential element of management and accountability, as it is a method and approach applied to all company departments to increase the effectiveness of corporate governance and compliance systems, which supports the achievement of strategic goals by identifying, analyzing, evaluating and prioritizing and monitoring risks to help ensure the sustainability of the company’s work and enable it to achieve its objectives. A main focus of this program is to identify risk management, its stages, and various tools for risk management as well as to review the legal framework for risk management in the Saudi insurance sector and to learn how to prepare an emergency plan for management of business continuity and crises.

                                                                                Details

                                                                                Preparation Program for Risk in Financial Services Certificate Exam- from CISI

                                                                                This training program aims to prepare participants with the knowledge and skills necessary to pass the The Risk in Financial Services program provides by CISI. This program covers the main areas of risk in financial services, by addressing international issues, and providing participants with a comprehensive and sound understanding of the principles of the risk management and control framework and corporate governance. The program also addresses the techniques used to identify and manage operational risks, credit risks, market risks, investment risks, and liquidity risks.

                                                                                Details

                                                                                Anti-Money Laundering and Terrorist Financing- Advanced Level

                                                                                Fighting money laundering and terrorist financing is a priority for the international community; since these financial crimes threaten the integrity and stability of the financial system and the economy in general, they can also affect the integrity and stability of financial institutions, discourage foreign investment, and distort international flows. As a result, the affected country experiences dire financial instability and poor economic performance. This program deeply explains AML & CTF standards and respective risk management in financial institutions. The program also explains pertinent local and international legislations and leading practices, as well as, the preparation and implementation of ML and TF risk-based programs, including “Know Your Customer” and “Customer Due Diligence” requirements.

                                                                                Details

                                                                                Credit Analysis and Decision-Making Mechanisms

                                                                                Choosing the right credit decision is the first line of defense for preserving lenders' capital, protecting creditors, and maximizing profitability for the bank. In this program, the participant gets familiar with the stages of credit decision-making according to the approved credit policy, the latest strategies for analyzing and calculating credit risks, local and international controls and standards, to be able to make a correct and successful credit decision that controls the expected risks.

                                                                                Details

                                                                                Financial Planning, Analysis and Forecasting

                                                                                Since the financial statements provide us with historical information and total figures, the decision maker needs tools that enable him to enter into the details of this information and the indicators that show the relationship between them. Therefore, close knowledge of the tools of planning, analysis and financial forecasting is one of the basic skills needed to manage the financial resources of the enterprise. This program provides participants with the basic knowledge to analyze financial statements and how to use the extracted indicators in evaluating the performance of the enterprise, making decisions and drawing future plans and policies for it. Additionally, it covers the forecasting model that depends on a specific set of financial criteria on which the financial plan for the facility is based.

                                                                                Details

                                                                                Motor Insurance (M94)- Dip. CII

                                                                                The Diploma in Insurance is a technical and supervisory qualification for insurance staff working across all sectors of the industry, and the logical progression from the Certificate in Insurance. The Diploma will provide you with a firm understanding of insurance fundamentals and will enable you to build towards advanced technical knowledge, thereby ensuring you have the means to function effectively in a challenging environment. Motor Insurance (M94) unit counts towards a Diploma in Insurance, it may also count towards the Advanced Diploma in Insurance. This training program provides an understanding of the risks faced by the various types of motor vehicles and the legal requirements associated with motor insurance. It includes relevant case law and an overview of the different types of motor insurance products available from the general insurance market.

                                                                                Details
                                                                                We value your feedback

                                                                                Dear visitor, we hope that you will participate in improving and developing the services provided by the academy on the website.

                                                                                Was it easy to find what you were looking for on the Academy's website?
                                                                                Was the information presented on the Academy’s website sufficient and useful?
                                                                                Please share with us your suggestions for developing the website
                                                                                Thank you!