Course track
IT & Admins
For IT, sysadmins, and privileged-account holders: ransomware response, admin credential hygiene, hardened MFA, backup discipline, shadow IT, endpoint hardening, evidence preservation, and vendor access risk.
Who takes this: IT staff, system administrators, and anyone holding privileged or admin credentials
ISOSOC2NISTPCINDPAHIPAA
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| Behind the Firewall: Network Fundamentals | 5 min | Explain segmentation and least privilege, and why "behind the firewall" is not "safe." | ISO, SOC2, NIST |
| Ransomware: First 60 Minutes Priority | 7 min | Execute the isolate, report, preserve sequence before touching a suspected ransomware host. | ISO, SOC2, NIST |
| Privileged Account & Admin Credential Hygiene | 5 min | Apply least privilege and unique admin credentials, and never share root or admin logins. | ISO, SOC2, PCI |
| MFA Fatigue & Account Takeover for Admins | 4 min | Harden admin accounts against push-bombing and configure number-matching MFA. | ISO, SOC2, NIST |
| Patch, Backup & Recovery Discipline | 5 min | Explain why untested backups are not backups, and verify a restore quarterly. | ISO, SOC2, NIST |
| Shadow IT & Unapproved AI Tools | 4 min | Identify and report unsanctioned SaaS or AI tools handling company data. | NDPA, ISO, SOC2 |
| Endpoint Hardening: Locking Down the Devices You Manage | 5 min | Apply practical endpoint hardening steps to reduce the attack surface on devices under your administration. | ISO, NIST, SOC2 |
| Incident Logging and Evidence Preservation for Admins | 5 min | Collect and preserve logs and digital evidence correctly during a security incident so investigations stay intact and usable. | NIST, NDPA, HIPAA |
| Third-Party Access and Vendor Risk Management | 5 min | Identify the risks vendors and third-party tools introduce and apply controls that limit their access to what they actually need. | ISO, SOC2, NIST |
| Security Awareness as an Admin Responsibility | 5 min | Describe how IT admins can actively support a security-aware culture across their organization, not just manage technical controls. | ISO, NIST, SOC2 |
Compliance codes show which frameworks each module supports; they describe what the training content covers, not a guarantee of legal compliance. Confirm specific clause wording with your own compliance advisor before citing it to a regulator or auditor.