"- Danny Hill, Friedkin Companies, Inc. "The perfect balance of theory and hands-on experience.

To support information security practitioners and managers implement the CIS Critical Security Controls, SANS provide a number of resources and information security courses.

CIS Critical Security Controls – Accelerated & Simplified Maintaining Continuous Compliance – A New Best-Practice Approach Top 7 Security Controls to Prioritize CIS Critical Security Controls: Technical Control Automation Attack Your Attack Surface – How to Reduce Your Exposure to Cyber Attacks with an Attack Surface Visualization Solution Following these 20 controls will help establish, in their words, a “prioritized baseline of information security measures and controls…

CIS CRITICAL SECURITY CONTROL

The Controls are effective because they are derived from the most common attack patterns highlighted in the leading threat reports and vetted across a very broad community of government and industry practitioners. The Controls take the best-in-class threat data and transform it into actionable guidance to improve individual and collective security in cyberspace.

"- James D. Perry II, University of Tennessee.

SANS Supports the CIS Critical Security Controls with Training, Research and What Works. 0000001508 00000 n SEC440: Critical Security Controls: Planning, Implementing and Auditing, SEC566: Implementing and Auditing the Critical Security Controls - In-Depth, SEC511: Continuous Monitoring and Security Operations, Download the latest papers related to the Critical Controls, http://www.cisecurity.org/critical-controls/, A Credit Union Increased Network Security With Network Access Control Based on Great Bay Software Beacon, What Works in Threat Prevention: Detecting and Stopping Attacks More Accurately and Quickly with ThreatSTOP, Inspecting Encrypted Traffic with the Blue Coat SSL Visibility Appliance, What Works in Supply Chain and Partner Security: Using BitSight to Assess and Monitor Third-Party Cybersecurity, Using WhiteHat Sentinel While most of the press coverage focuses on breaches and other security failures, there are thousands of cybersecurity leaders quietly working hard and make advances against threats while enabling business and mission needs. They were created by the people who know how attacks work - NSA Red and Blue teams, the US Department of Energy nuclear energy labs, law enforcement organizations and some of the nation's top forensics and incident response organizations - to answer the question, "what do we need to do to stop known attacks." 0000009186 00000 n

The key to the continued value is that the Controls are updated based on new attacks that are identified and analyzed by groups from Verizon to Symantec so the Controls can stop or mitigate those attacks. SANS expert John Pescatore interviews the end user and decision maker and produces a Q&A formatted case study and a live webcast that allows security practitioners to take advantage of lessons learned and accelerate their own cybersecurity improvements.

"Because of the use of real-world examples it's easier to apply what you learn.

Critical Security Controls Courses

By TJ Banasik, How to Create a Scalable and Automated Edge Strategy in the AWS Cloud 0000010397 00000 n The SANS "What Works" program highlights success stories in cybersecurity - real examples of how real security teams have made measurable improvements in the effectiveness and efficiency of their security controls.

0000004225 00000 n MAPPING THE TOP 20 CRITICAL SECURITY CONTROLS This table below provides a high-level mapping of Deep Security’s security controls to the SANS/CIS Top 20 Critical Security Controls, and also provides commentary on where cloud service providers (CSPs) like AWS, Microsoft Azure, and others have a roll to play.

Too often in cybersecurity, it seems the "bad guys" are better organized and collaborate more closely than the "good guys." 0000082331 00000 n

By Dave Shackleford, Fear of the Unknown: A Metanalysis of Insecure Object Deserialization Vulnerabilities

The SANS 20 Overview SANS has created the "20 Critical Security Controls" as a way of providing effective cyber defense against current and likely future Internet based attacks.

Dynamic and Static Solutions to Increase Application Security Before and After Production Deployment, Lifecycle Vulnerability Management and Continuous Monitoring with Rapid7 Nexpose, Using Palo Alto Networks Next Generation Firewalls to Increase Visibility into Threats and Reduce Threat Risks, Blocking Complex Malware Threats at Boston Financial, Increasing Security and Reducing Costs by Managing Administrator Rights with Process-based Privilege Management, Reaping the Benefits of Continuous Monitoring and Mitigation at Pioneer Investments, How VCU uses FireEye for Advanced Threat Detection and Prevention, Increasing Vulnerability Management Effectiveness While Reducing Cost, 2018 SANS Critical Security Controls Poster, 2014 SANS Critical Security Controls Poster, Threat Intelligence Solutions: A SANS Review of Anomali ThreatStream, How to Create a Scalable and Automated Edge Strategy in the AWS Cloud, Fear of the Unknown: A Metanalysis of Insecure Object Deserialization Vulnerabilities

The CIS Critical Security Controls are a recommended set of actions for cyber defense that provide specific and actionable ways to stop today's most pervasive and dangerous attacks. 0000007887 00000 n That group of experts reached consensus and today we have the most current Controls.

