CIS Critical Security Control 4: Secure Configuration of Enterprise Assets and Software (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 4: Secure Configuration of Enterprise Assets and Software. The primary objective of this control is to implement best practices for managing secure services and disabling insecure ones.

Course Content
This course helps learners prepare for industry certifications around the CIS Controls. These security controls can be combined with frameworks such as NIST SP 800-37 (the NIST Risk Management Framework, RMF) to provide organizations with defense-in-depth best practices.
CIS Critical Security Control 4: Secure Configuration of Enterprise Assets and Software (v8) teaches organizations how to establish and maintain secure baseline configurations for devices, operating systems, applications, and network infrastructure. By reducing unnecessary services, disabling insecure defaults, and standardizing system settings, organizations can significantly limit their attack surface and improve operational consistency.
Topics include configuration baselines, hardening standards, change management considerations, configuration monitoring, and methods for identifying drift from approved settings. Real-world examples demonstrate how attackers exploit weak or inconsistent configurations and how organizations can proactively reduce those risks. Start learning today.














