Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CIS(Center for internet Security) Controls for IT,OT & IOT.
Rating: 3.6 out of 5(28 ratings)
205 students

CIS(Center for internet Security) Controls for IT,OT & IOT.

Cyber Security controls, OT security control & IOT security controls
Created byAbha Sood
Last updated 8/2021
English

What you'll learn

  • They will learn about "CIS Controls Version 8" which is applicable on Cyber security, OT security and IOT security.

Course content

1 section21 lectures3h 4m total length
  • Introduction of CIS Controls Version 814:41

    Explore CIS controls version 8 for IT, OT, and IoT, including asset inventory, software control, data protection, secure configurations, access management, and continuous vulnerability management.

  • Introduction of CIS Control Version 8 - Part 210:13

    Introduces CIS control version 8 with emphasis on email and web protection, malware defenses, network monitoring, security awareness, third-party risk, secure software development, incident response, and penetration testing.

  • CIS - Control 1 - Inventory and Control of Enterprise Assets14:39

    Learn to establish and maintain a comprehensive inventory and control of enterprise assets across physical, virtual, and cloud environments using active and passive discovery to support security and incident response.

  • CIS - Control 2 - Inventory and Control of Software Assets11:24

    Establish and maintain a detailed software inventory, authorize only approved software, implement allow listing and denial controls, and biannually review licenses and security measures.

  • CIS - Control 3- Data Protection14:45

    Identify, classify, and securely handle data to protect against breaches; implement encryption in transit and at rest, data retention and disposal, and a data breach and incident response framework.

  • CIS - Control 4 - Secure Configuration of Enterprise Assets & Software12:27

    Establish and maintain the secure configuration of enterprise assets and software, replacing default credentials. Disallow unused services, apply benchmarks, and manage updates to enforce secure DNS and device protections.

  • CIS - Control 5 - Account Management7:46

    Define account management to assign and control access for user, administrative, and service accounts, enforcing password policy, MFA, inventory of accounts, and access reviews.

  • CIS - Control 6- Access Control6:59

    Implement the CIS control 6 access control by enforcing identity and access management, least privilege, need-to-know, provisioning, centralized audit trails, and multifactor authentication for remote and privileged access.

  • CIS - Control 7 - Continuous Vulnerability Management7:37

    Develop and maintain a plan for continuous vulnerability management across internal and external assets, using scanning tools, ticketing workflows, and remediation to minimize the window of opportunity.

  • CIS - Control 8 - Audit Log Management6:57

    Implement audit log management with centralized logging, standardized time synchronization, and retention of at least 90 days to support incident investigation and enterprise analysis.

  • CIS - Control 9 - Email & Web Browser Protection9:40

    Protect email and web browsing by blocking phishing and social engineering, updating browsers, and limiting risky plugins. Enforce content filtering and anti-malware tools to secure email gateways.

  • CIS - Control 10 - Malware Defenses5:54

    CIS control 10 outlines malware defenses that prevent and control malicious code across enterprise endpoints, removable media, email, web applications, and cloud services through automated, updated protection and incident response.

  • CIS - Control 11 - Data Recovery6:27

    Establish and maintain data recovery practices using full, incremental, and differential backups, automate backups, define backup frequency, test regularly, and restore systems to the original trusted state.

  • CIS - Control 12 - Network Infrastructure Management7:31

    Implement an actively managed network infrastructure by inventorying devices, tracking changes, and correcting vulnerabilities. Document architecture diagrams, enforce RBAC and logging, and use secure protocols and multifactor authentication for administration.

  • CIS - Control 13 - Network Monitoring and Defense7:40

    Implement comprehensive network monitoring and defense through continuous monitoring, centralized security alerting, and threat intelligence. Deploy ids/ips, firewall filtering, log collection, and strict access controls to detect and respond quickly.

  • CIS - Control 14 - Security Awareness and Skills Training7:46

    Establish and maintain a security awareness program to influence behavior and reduce cybersecurity risks. Deliver role-based training, phishing exercises, and incident reporting with emphasis on multifactor authentication and data handling.

  • CIS - Control 15 - Service Provider Management9:22

    Implement a third-party risk assessment for service providers handling sensitive data, including inventory, risk classification, contractual accountability, monitoring, and annual reassessment to meet HIPAA, PCI DSS, and FFIEC standards.

  • CIS - Control 16 - Application Software Security10:35

    Improve application security under CIS control 16 by integrating vulnerability management into the development lifecycle, training developers in secure coding, and securing third-party components across multi-platform architectures.

  • CIS - Control 17 - Incident Response Management5:09

    Establish and maintain an incident response program to detect, respond, contain, and recover from cyber incidents, with clear roles, communication, training, root-cause analysis, and post-incident lessons.

  • CIS - Control 18 - Penetration Testing7:23

    Explore how penetration testing identifies and exploits vulnerabilities to assess the resilience of IT, OT, and IoT controls, including external and internal assessments and attacker impact.

  • CIS - Course Material

Requirements

  • No

Description

What is CIS?

  • CIS stands for The Center for Internet Security.

  • It is a community-driven non profitable organization formed in Oct,2000.

  • It makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation.

Few CIS Controls

1. Inventory and Control of Enterprise Assets - Manage all enterprise assets connected to the infrastructure physically, virtually, remotely, and those within cloud environments, to accurately know the totality of assets that need to be monitored and protected within the enterprise.

2. Inventory and Control of Software Assets - Manage all software on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.

3. Data Protection - Develop processes and technical controls to identify, classify, securely handle, retain, and dispose of data.

4. Secure Configuration of Enterprise Assets & Software - Establish and maintain the secure configuration of enterprise assets and software.

5. Account Management - Use processes and tools to assign and manage authorization to credentials for user accounts, including administrator accounts, as well as service accounts, to enterprise assets and software.

6. Access Control - Use processes and tools to create, assign, manage, and revoke access credentials and privileges for user, administrator, and service accounts for enterprise assets and software.

Who this course is for:

  • Security, risk, compliance, IT team lead and Managers