← HomeGIAC / SANS · Full exam outline
GCCC
Critical Controls Certification
Security controls / risk
1Control Framework Foundations
1.1CIS Controls structure and implementation groups
1.2Mapping controls to other frameworks
1.3Governance and control ownership
2Asset and Data Controls
2.1Enterprise and software asset inventory
2.2Data protection and recovery
2.3Account and access management
3Infrastructure and Application Controls
3.1Secure configuration of assets
3.2Continuous vulnerability management
3.3Network infrastructure and application software security
4Operational Controls
4.1Audit log management
4.2Malware defences
4.3Email and browser protections
4.4Incident response management
5Control Assessment and Measurement
5.1Evidence of control implementation
5.2Measurement and metrics
5.3Penetration testing and audit
Weights are the certification body’s published values and are checked against each outline revision.