Courses

CIS Critical Security Control 7: Continuous Vulnerability Management (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 7: Continuous Vulnerability Management. The primary objective of this control is to configure a repository for Linux servers and configure a Windows System Update Service for a domain controller.

CIS Critical Security Control 6: Access Control Management (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 6: Access Control Management. The primary objective of this control is to enable Multifactor Authentication (MFA) on a Linux server and define role-based access controls.

CIS Critical Security Control 3: Data Protection (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 3: Data Protection. These protocols are meticulously designed to identify, classify, securely handle, retain, and ultimately dispose of data, ensuring its integrity, availability, and confidentiality throughout its lifecycle.

CIS Critical Security Control 4: Secure Configuration of Enterprise Assets and Software (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 4: Secure Configuration of Enterprise Assets and Software. The primary objective of this control is to implement best practices for managing secure services and disabling insecure ones.

CIS Critical Security Control 16: Application Software Security (v8)
Applications are frequent targets for attackers looking for vulnerabilities to exploit. This course explores how CIS Critical Security Control 16 helps organizations build, manage, and maintain more secure software.

CIS Critical Security Control 17: Incident Response Management (v8)
Even strong defenses can be tested by a determined attacker. This course explores how CIS Critical Security Control 17 helps organizations prepare response plans, coordinate action, and recover effectively from security incidents.

CIS Critical Security Control 13: Network Monitoring and Defense (v8)
This course is part of our series on the CIS Top 18 Critical Security Controls v8, and covers Control 13: Network Monitoring and Defense. Attackers often move quietly through networks before they’re detected. In this course, you’ll learn how CIS Critical Security Control 13 helps organizations monitor network activity, identify threats, and strengthen defensive capabilities.

CIS Critical Security Control 15: Service Provider Management (v8)
Your organization’s security depends on more than just your internal systems. This course explores how CIS Critical Security Control 15 helps organizations manage third-party relationships and reduce risks introduced by external service providers.
My professional journey has taken me through senior roles at organizations like Amazon, USAA, Brace Industrial Group, Argo Group, and the US Army, where my contributions have been instrumental in safeguarding critical infrastructures and formulating robust cybersecurity strategies. Besides my corporate endeavors, I carry the proud badge of being a combat veteran, having served in Iraq and Afghanistan. My passion for knowledge sharing sees me as an adjunct professor and an author whose focus predominantly lies in cybersecurity. I have a BS, MS, and a Doctorate specializing in Cybersecurity Regulatory Risk and Compliance. I learned to program on an Apple 2E and have been in love with computer science ever since.
Living in San Antonio, Texas, I am blissfully married to my beautiful wife, Selda. We are blessed with four exceptional children, aged 12 to 25, consisting of a son and three daughters who are the light of our lives. Our household is always full of life and joy, with our children and three adorable dogs - two lovely Maltese and a spirited Beagle.
