DoD DCWF - Security Control Assessor

MCSI Certification

MSCA - Certified Security Control Assessor

This dynamic course is designed for aspiring and current Security Control Assessors, focusing on security auditing, management, and risk assessment frameworks. Participants will gain expertise in vulnerability scanning across systems and networks, software assessment, and secure code review techniques.

Through hands-on training, participants will learn to detect and mitigate vulnerabilities, propose strategic recommendations, and automate secure configurations across diverse infrastructures.

This course equips individuals with essential skills in security control assessment, ensuring they are ready to enhance organizational security in today's digital world.

Intermediate Level MCSI Certification Intermediate
ic-certificate Certification
ic-clock 600+ hours
ic-money $1295
No Expiry, No Renewals

Course Overview

This comprehensive course is tailored for aspiring and current Security Control Assessors, emphasizing security auditing, management, and risk assessment frameworks. Participants will develop expertise in conducting vulnerability scans across systems and networks, assessing software security, and performing secure code reviews.

Throughout the program, participants will delve into the fundamentals of vulnerability scanning, learning to identify and assess vulnerabilities across Windows and Linux systems, within network architectures, and embedded in software development pipelines. The course emphasizes hands-on experience, allowing learners to apply these concepts in real-world scenarios. They will not only detect vulnerabilities but also propose and implement strategic recommendations to mitigate these risks, thereby enhancing the security posture of their organizations.

A significant portion of the course is dedicated to the assessment of software programs. Participants will be introduced to the techniques of secure code review and the practice of fuzzing to understand and improve the behavior of applications under test conditions. These critical skills are paramount for those aiming to ensure the integrity, confidentiality, and availability of software systems.

Upon completion, learners will be proficient in:

  • Apply fundamental security auditing principles for effective risk mitigation.
  • Develop comprehensive checklists to audit hardware, software, and business operations.
  • Master risk assessment techniques and actively manage emerging security concerns.
  • Utilize industry-standard security baselines to set organizational security standards.
  • Employ security testing techniques using tools like Nmap, SonarQube, and OWASP ZAP.
  • Provide recommendations to enhance organizational security measures across on-premises and cloud environments.

Knowledge, Skills and Abilities You Will Acquire

MCSI is one of the most respected and trusted names in cyber security education and training. Our certifications teach critical skills, knowledge and abilities needed to advance a career in cyber security. Our courses are comprehensive and up-to-date, and our instructors are experienced professionals who are dedicated to helping students learn. MCSI provides the real-world skills and knowledge you need to protect any organization from cyber threats.

  • Lab Setup and Configuration

    Lab setup and configuration are crucial for MSCA to provide hands-on experience in applying security controls and methodologies. This practical training allows participants to simulate real-world scenarios, reinforcing their understanding of security principles and enhancing their ability to conduct effective security control assessments.

    OpenVAS

    OpenVAS is a vital tool for MSCA, enabling comprehensive vulnerability scanning and assessment across various systems and networks.

    VirtualBox

    VirtualBox is essential for setting up and configuring virtual lab environments, providing a sandboxed platform for testing security controls and configurations.

    Chef - AWS

    Chef integrated with AWS facilitates automated configuration management and deployment of security controls in cloud environments, a critical aspect of modern security assessments.

    Puppet - AWS

    Puppet in conjunction with AWS supports secure configuration management and orchestration, enabling efficient management of security controls across cloud infrastructures.

  • Auditing and Risk Management

    Auditing and risk management are crucial for security control assessors as they enable the identification, evaluation, and mitigation of organizational risks. By conducting thorough audits and risk assessments, assessors can provide actionable insights and recommendations to enhance security postures and ensure compliance with industry standards and regulations.

    This proactive approach helps organizations maintain robust security measures and effectively manage potential threats and vulnerabilities.

    Gap Analysis

    Crucial for identifying security gaps and discrepancies between current practices and desired standards, guiding prioritization of improvement efforts for security control assessors.

    Security Baselines

    Establish foundational security configurations and standards to assess deviations, ensuring consistent and effective security practices are maintained.

    Bypassing Controls

    Understanding control weaknesses and potential bypasses is essential for identifying vulnerabilities and strengthening security measures as part of security control assessments.

    Audit Charter Document

    Defines the scope and objectives of audits, ensuring structured and comprehensive assessments that align with security control assessment goals.

    Engagement Letter

    Establishes clear terms and expectations for audit engagements, providing transparency and alignment between stakeholders in security control assessments.

    Privacy Audit Checklist

    Ensures compliance with privacy regulations and identifies risks associated with personal data handling, which is critical for security control assessors assessing privacy controls.

    Hardware & Software Acquisition Audit Checklists

    Assesses newly acquired assets for security vulnerabilities, ensuring that security controls are applied to prevent risks in the infrastructure.

    Logical Access Review Checklist

    Evaluates access controls and permissions to prevent unauthorized access, a key aspect of security control assessments.

    System Testing Review

    Validates system security through comprehensive testing, identifying vulnerabilities and areas for improvement in security control assessments.

    Risk Governance

    Establishes policies and processes for effective risk management, ensuring that security control assessors can align security practices with organizational goals.

    Gap Assessment Workbooks

    Organizes findings from gap analyses, aiding in prioritizing remediation efforts and tracking progress for security control assessors.

    IT Security Standard Documents

    Establishes consistent security standards for data protection and access control, guiding security control assessors in maintaining and enforcing security practices across the organization.

  • Vulnerability Assessment and Exploitation

    Vulnerability assessment and exploitation are critical for security control assessors to identify weaknesses and potential entry points in systems, networks, and applications, enabling informed risk management and mitigation strategies.

    Understanding vulnerabilities and their exploitation helps assessors gauge the effectiveness of existing controls and prioritize remediation efforts to enhance overall security posture.

    Nmap

    Nmap is a critical tool for network scanning and identifying potential vulnerabilities within networked systems, aiding in comprehensive assessments for security control assessors.

    Utilizing Nmap to identify and exploit vulnerabilities

    Utilizing Nmap not only helps in identifying vulnerabilities but also aids in understanding system weaknesses and potential attack vectors, crucial for security control assessors in assessing risk.

    Writing PowerShell scripts to identify Windows vulnerabilities

    Writing PowerShell scripts enables automated detection and assessment of vulnerabilities in Windows environments, streamlining assessment processes for security control assessors.

    Identifying and exploiting numerous Linux vulnerabilities (such as Privilege escalation, etc.)

    Identifying and exploiting Linux vulnerabilities provides essential hands-on experience in assessing Linux systems, including privilege escalation, which is vital for comprehensive security assessments by security control assessors.

  • Security Testing and Configuration Management

    Security Testing and Configuration Management are crucial for security control assessors as they enable comprehensive assessments of system vulnerabilities and ensure adherence to secure configuration standards.

    By conducting rigorous security testing and effectively managing configurations, assessors can identify, mitigate, and prevent potential security risks within organizational infrastructures.

    Perform Security Testing in Jenkins CI/CD Pipelines

    Integrating security testing into CI/CD pipelines created using Jenkins is crucial for security control assessors to automate and validate security measures throughout the development lifecycle, ensuring early detection and mitigation of vulnerabilities.

    DefectDojo for Security Testing in CI/CD Pipelines

    DefectDojo facilitates security testing within CI/CD pipelines, enabling assessors to manage findings and track remediation efforts efficiently, ensuring continuous security improvement in software development processes.

    OWASP ZAP for Security Testing in CI/CD Pipelines

    OWASP ZAP provides security testing capabilities in CI/CD pipelines, allowing assessors to identify and address security vulnerabilities early in the development cycle, enhancing the overall security posture of applications.

    Integrating Threat Mapper

    Integrating Threat Mapper is valuable for security control assessors to visualize and analyze threat models, aiding in the identification of potential security risks and the formulation of effective security strategies.

    Writing Sensible Playbooks for Different Circumstances

    Developing sensible playbooks is essential for security control assessors using automation tools like Ansible, enabling consistent and secure configuration management across diverse environments, thereby reducing security risks.

    Utilizing Chef for AWS Configuration Management

    Utilizing Chef for AWS configuration management allows security control assessors to enforce consistent and secure configurations, ensuring compliance with organizational security policies and standards in cloud environments.

    Utilizing Puppet to Configure AWS Firewall

    Leveraging Puppet for AWS firewall configuration enables security control assessors to manage and enforce firewall rules efficiently, enhancing network security and mitigating potential threats in AWS environments.

  • Browzer Fuzzing

    Browser fuzzing is important for security control assessors because it allows them to identify and exploit vulnerabilities in web browsers, which are common entry points for attackers. By simulating unexpected or malformed inputs, fuzzing helps assessors uncover potential security weaknesses and ensure the robustness of browser security measures.

    Writing Scripts to Automate Browser Fuzzing

    Writing scripts to automate browser fuzzing is crucial for security control assessors, enabling efficient and systematic testing of web browsers for vulnerabilities. Automation allows assessors to scale their efforts and identify potential security weaknesses more effectively.

    Browser Fuzzing with the HTML Engine

    Browser fuzzing using the HTML engine is significant for security control assessors, as it helps simulate unexpected input scenarios and detect vulnerabilities specific to HTML rendering. This approach is essential for ensuring robust security measures in web browsers.

    Browser Fuzzing Using the JavaScript Engine

    Browser fuzzing using the JavaScript engine is important for security control assessors to assess the security of JavaScript execution within web browsers. This method enables assessors to uncover potential vulnerabilities related to JavaScript handling and execution.

DoD Cyber Workforce Framework KSATs

This course teaches the specific Knowledge, Skills, Abilities, and Tasks (KSATs) aligned with the DoD Cyber Workforce Framework (DCWF) as outlined in DoD 8140. By focusing on these critical competencies, the course ensures that you develop the essential capabilities required for various cybersecurity roles within the Department of Defense. This alignment not only guarantees that the training is relevant and comprehensive but also that it prepares you to meet the specific operational needs and standards of the DoD cyber workforce.

  • knowledge
    ID Description
    19 Knowledge of cyber defense and vulnerability assessment tools, including open source tools, and their capabilities.
    22 Knowledge of computer networking concepts and protocols, and network security methodologies.
    40 Knowledge of organization’s evaluation and validation requirements.
    55 Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data.
    58 Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins.
    63 Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
    70 Knowledge of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption).
    77 Knowledge of current industry methods for evaluating, implementing, and disseminating information technology (IT) security assessment, monitoring, detection, and remediation tools and procedures utilizing standards-based concepts and capabilities.
    105 Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
    108 Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
    1072 Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    1158 Knowledge of cybersecurity principles.
    1159 Knowledge of cyber threats and vulnerabilities.
    6900 Knowledge of specific operational impacts of cybersecurity lapses.
    6935 Knowledge of cloud computing service models Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
    6938 Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments.
    27 Knowledge of cryptography and cryptographic key management concepts.
    38 Knowledge of organization’s enterprise information security architecture system.
    43A Knowledge of embedded systems.
    53A Knowledge of security risk assessments and authorization per Risk Management Framework processes.
    69A Knowledge of risk management processes and requirements per the Risk Management Framework (RMF).
    88 Knowledge of new and emerging information technology (IT) and cybersecurity technologies.
    88A Knowledge of current and emerging cyber technologies.
    95B Knowledge of penetration testing principles, tools, and techniques, including specialized tools for non-traditional systems and networks (e.g., control systems).
    121 Knowledge of structured analysis principles and methods.
    128 Knowledge of systems diagnostic tools and fault identification techniques.
    143 Knowledge of the organization’s enterprise information technology (IT) goals and objectives.
    942 Knowledge of the organization’s core business/mission processes.
    1034A Knowledge of Personally Identifiable Information (PII) data security standards.
    1034B Knowledge of Payment Card Industry (PCI) data security standards.
    1034C Knowledge of Personal Health Information (PHI) data security standards.
    1036 Knowledge of applicable laws (e.g., Electronic Communications Privacy Act, Foreign Intelligence Surveillance Act, Protect America Act, search and seizure laws, civil liberties and privacy laws), statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures relevant to work performed.
    1037 Knowledge of information technology (IT) supply chain security and risk management policies, requirements, and procedures.
    1038B Knowledge of local specialized system requirements (e.g., critical infrastructure/control systems that may not use standard information technology [IT]) for safety, performance, and reliability).
    1131 Knowledge of security architecture concepts and enterprise architecture reference models (e.g., Zackman, Federal Enterprise Architecture [FEA]).
    1141A Knowledge of an organization’s information classification program and procedures for information compromise.
    1142 Knowledge of security models (e.g., Bell-LaPadula model, Biba integrity model, Clark-Wilson integrity model).
  • skills
    ID Description
    183 Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
    197 Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
    3B Skill in conducting vulnerability scans and recognizing vulnerabilities in information systems and networks.
    156 Skill in applying confidentiality, integrity, and availability principles.
    203 Skill in identifying measures or indicators of system performance and the actions needed to improve or correct performance, relative to the goals of the system.
    1039 Skill in evaluating the trustworthiness of the supplier and/or product.
  • tasks
    ID Description
    537 Develop methods to monitor and measure risk, compliance, and assurance efforts.
    548 Develop specifications to ensure risk, compliance, and assurance efforts conform with security, resilience, and dependability requirements at the software application, system, and network environment level.
    566 Draft statements of preliminary or residual security risks for system operation.
    691 Maintain information systems assurance and accreditation materials.
    710 Monitor and evaluate a system’s compliance with information technology (IT) security, resilience, and dependability requirements.
    417 Apply coding and testing standards, apply security testing tools including “‘fuzzing” static-analysis code scanning tools, and conduct code reviews.
    457 Conduct Privacy Impact Assessments (PIA) of the application’s security design for the appropriate security controls, which protect the confidentiality and integrity of Personally Identifiable Information (PII).
    772 Perform validation steps, comparing actual results with expected results and analyze the differences to identify impact and risks.
    775 Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks.
    798 Provide an accurate technical evaluation of the software application, system, or network, documenting the security posture, capabilities, and vulnerabilities against relevant cybersecurity compliances.
    827 Recommend new or revised security, resilience, and dependability measures based on the results of reviews.
    836B Review and approve security and privacy assessment plans.
    836 Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network.
    878 Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations.
    879 Verify that the software application/network/system accreditation and assurance documentation is current.
    936 Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers).
    1146 Develop and Implement cybersecurity independent audit processes for application software/networks/systems and oversee ongoing independent audits to ensure that operational and Research and Design (R&D) processes and procedures are in compliance with organizational and mandatory cybersecurity requirements and accurately followed by Systems Administrators and other cybersecurity staff when performing their day-to-day activities.

Career Outcomes

Our Security Control Assessor course provides you with the expertise needed to conduct thorough security assessments. Through hands-on training, you will learn to evaluate security controls, manage risks, and ensure compliance with cybersecurity standards. Gain practical experience in developing security specifications, performing privacy impact assessments, and verifying system security postures. By the end of the course, you will be prepared to ensure the effectiveness of security controls and protect critical information systems.

Certification Detail

MCSI certifications are highly respected and sought-after credentials in the industry. Earning an MCSI certification is a testament to your knowledge and skillset, and demonstrates your commitment to excellence. The content is cutting-edge, uniquely-designed, and hands-on. Our exercises teach in-demand skills that are immediately applicable in the field.

The certifications are valid indefinitely and do not require any renewal fees. The training is accessible without any time limits.

Syllabus

Training Modules

This course provides you with multiple training modules, each of which is designed to teach you practical skills that can help you solve important cyber problems. Each module offers exercises that will help you build your skills and capabilities.

  • MSCA-001: Lab Setup - 3 exercises
  • MSCA-101: Auditing Concepts - 4 exercises
  • MSCA-102: Information Security Auditing - Part 1 - 9 exercises
  • MSCA-103: Information Security Auditing - Part 2 - 10 exercises
  • MSCA-104: Risk Management - 11 exercises
  • MSCA-105: Gap Assessment Workbooks - 5 exercises
  • MSCA-106: IT Security Standards - 7 exercises
  • MSCA-107: Information Security Management Concepts - 3 exercises
  • MSCA-201: Network Vulnerability Scanning with NMAP - 15 exercises
  • MSCA-202: Windows Vulnerability Enumeration - 5 exercises
  • MSCA-203: Enumerating and Exploiting Linux Vulnerabilities - 8 exercises
  • MSCA-204: Security Testing in CI/CD Pipelines - 13 exercises
  • MSCA-205: Configuration Management with Ansible - 9 exercises
  • MSCA-206: Configuration Management with Chef - 10 exercises
  • MSCA-207: Configuration Management with Puppet - 7 exercises
  • MSCA-401: Browser Fuzzing: Introduction - 5 exercises
  • MSCA-402: Browser Fuzzing: Fuzzing the HTML Engine - 4 exercises
  • MSCA-403: Browser Fuzzing: Fuzzing the Javascript Engine - 5 exercises

Scenarios

Cyber professionals must be ready for everything. The typical security training strategy, which focuses on individual skills and tools, is insufficient. You must be able to operate as part of a team, see the big picture, and respond swiftly and effectively to unforeseen circumstances. That's why, as part of our training, we use replays of whole cyber missions. Our scenarios help you prepare for the demands of the job and give you confidence in your ability to work professionally.

  • MSCA-SC-01: Secure Code Reviews - 4 exercises

Enroll now with lifetime access for $1295

Certifications

MCSI Industry Certifications are important for you to earn because they signify that you have the skills required to work in a cybersecurity. Certificates of Completion are also important to earn because they signify that you have completed an exercise. Earning Certificates of Completion and Industry Certifications demonstrates that you are willing to put in the extra work to be successful.

1
ic-step-1

Student

2
ic-step-2

Obtain CPE points by solving exercises

3
ic-step-3

Achieve multiple certifications

4
ic-step-4

Receive help from instructors online

This certification is aligned with the DoD Cyber Workforce Framework (DoD 8140), ensuring you receive training that meets the standards and competencies required for cybersecurity roles within the Department of Defense. This alignment guarantees that you gain relevant, up-to-date skills and knowledge tailored to the specific needs of the DoD cyber workforce, effectively preparing you to support and secure defense operations.

Certificate Level Curriculum Completion Requirement Scenarios Completion Requirement
MCSI Security Control Assessor (Basic) Level 1 50% 0%
MCSI Security Control Assessor (Intermediate) Level 2 75% 50%
MCSI Security Control Assessor (Advanced) Level 3 95% 100%

Sample Exercises

Write a Data Protection Standard

exercise

Set up Jenkins in a Docker container

exercise

Set Up Chef On Your Local Environment To Configure Virtual Machines

exercise

Help and Support

Unmatched Mentorship: Accelerate Your Growth

At MCSI, mentorship is built to unlock your full potential. Receive personalized insights from multiple experts, tackle real-world challenges, and get the guidance you need to grow rapidly and excel in your cybersecurity career.

  • Personalized feedback with an average instructor response time of 1 business day
  • Direct access to instructors and peers via a 24/7 Discord server
  • Progress tracking and milestone assessments to keep you on course toward success
  • 95% of MCSI graduates land cybersecurity jobs with expert mentoring and feedback

24/7/365 Discord Community:

If you're looking for additional support during your studies, consider joining our Discord server. Our community of fellow students and instructors is always available to provide help and answer any questions you may have.

Personalized Support:

Your submissions will be reviewed by MCSI instructors, who will provide you with personalized feedback. This input is critical since it can assist you in identifying the areas where you need to enhance your skills. The instructor's feedback will also tell you how well you did an exercise and what you can do to improve your performance even further.

Click here to see an example of personalized feedback.

Our personalized support will take your skills to the next level. Read what a student says about it:

Quick Questions:

If you have any questions or need clarification on any of the exercises, MCSI offers a Quick Questions section on each exercise where you can ask for help. This is a great resource to use if you need assistance. This feature is only available for paid courses.

Prerequisites

Training Laptop Requirement

This course can be completed on a standard training laptop. To ensure you have the necessary hardware to complete the course, your machine should meet the following specifications:

  • 64-bit Intel i5/i7 2.0+ GHz processor or equivalent
  • 8GB of RAM
  • Ability to run at least (1) virtual machine using Virtual Box, or an equivalent virtualization software
  • Windows 10 or later, macOS 10 or later, or Linux
  • Local administrator privileges
Do you support older operating systems?

Yes. Many of the exercises can be completed on older OS versions. A few of our students are successfully using older equipment to learn cyber security.

Proficiency in the English language

You must have the ability to comfortably read and understand IT documentation written in English. Ideally, they have an IELTS score of 6.5 with no band less than 6 (or equivalent).

Note: You can register for this course without having undertaken an English test.

Lab Environment

This course teaches you how to setup and configure your own cybersecurity lab.

  • Save thousands by avoiding the costs of pre-built labs
  • Customize your lab with the hardware and software you prefer
  • Gain practical skills in networking, system administration, and technical troubleshooting
  • Build confidence by practicing tasks you'll need to perform in real-world jobs
  • Manage and maintain your own tools—just as employers expect in the workplace

Aptitude Test (Optional)

This is an intermediate course. It includes exercises for novices but assumes that they have competent IT skills and a strong understanding of cybersecurity concepts.

Aptitude Test:

If you're not sure if you'll be able to fully enjoy this course, then contact us via email to organize a free aptitude test. This test will determine whether you meet the course's basic baseline criteria. If you've never studied with us before, it will also introduce you to the MCSI Method™.

Why MCSI's Security Control Accessor Certification is World Class

why MCSI

Comprehensive Cyber Defense Infrastructure Support Training

The MSCA certification equips aspiring and current Security Control Assessors with a deep understanding of security auditing, management, and risk assessment frameworks, preparing them to perform comprehensive security control assessments in diverse environments.

why MCSI

Specialized Focus on System Security Assessment

MSCA-certified assessors gain expertise in vulnerability scanning, secure code review, and automation of secure configurations across various infrastructures, enabling them to identify and mitigate vulnerabilities across systems, networks, and applications effectively.

why MCSI

Proficiency in Security Control Assessment

The MSCA certification covers the essential aspects of information security, including vulnerability detection, secure code assessment, and automation of security controls, preparing participants to enhance the security posture of organizations through comprehensive security control assessments.

Enrollment and Fees

Fees

Your next breakthrough starts with bold action—take it today with MCSI, buy now:

What You Receive

MCSI delivers unmatched benefits, expertly combined to give you a competitive edge:

  • Lifetime access with no renewal fees or hidden costs
  • All updates free, with regularly refreshed content.
  • certifications in one purchase
  • Personalized feedback and direct access to instructors for continuous support
  • Join a community of 35,000+ users to network, collaborate, and grow

Click here to read student testimonials to see firsthand accounts of their experiences with MCSI training.

Time to Value

After just 5 exercises, 66% of users report stronger problem-solving skills as a direct result of their MCSI training.

Put in the effort, and we guarantee you'll see measurable improvements in your skills within weeks. Depending on your starting point, the MCSI Method will help you become a competent professional within the specific cyber domain taught in this course in just a few months.

Actively Maintained Course

This course is actively maintained, regularly tested, and updated with industry support to ensure accuracy, quality, and the most up-to-date skills—setting it apart as one of the best in the market.

Terms and Conditions

Cooling-Off Policy

Received a full refund if you changed your mind about a purchase within 24 hours. No questions asked. Read the full details here.

Don't Buy This Course

Don't buy this course if you believe cybersecurity is simple, can be mastered in hours, or that passive consumption of videos and books is enough.

Our competitors deceive you with promises that video courses and open-book certificates are sufficient. Cybersecurity demands hundreds of hours facing real challenges, with experts guiding you to strengthen your weaknesses. Only when you embrace this will you grasp the value of the MCSI Method™ and the transformation it offers.

By purchasing, you commit to our 100% practical MCSI Method™—no solutions, no walkthroughs, only critical thinking, problem-solving and research like in the real-world. Unsure? Try the free version first.

How does MCSI Compare?

MCSI is 95% more cost-effective with 20x more practical training hours:

Enroll now with lifetime access for $1295

Bloom's Taxonomy

Employers seek problem-solvers who deliver real value. With MCSI, you'll develop practical, in-demand skills applicable across diverse cyber roles.

Frequently Asked Questions

What is the MCSI Method™?

Common Questions

  • What is the MCSI Method™?

    Watch this video:

  • Are solutions disclosed and available?
    • No. Our method of teaching cyber security consists of challenging you with real-world problem statements that you're expected to research and solve by doing your own research. This is how you'll be expected to work in the field. When you fail an exercise, we provide you with constructive feedback to improve and try again.
  • Do exercises, training content, or certificates ever expire? Am I expected to buy again in the future?
    • Upon purchase, all the materials permanently unlocked with no recurring or ongoing fees.
  • Do I need to buy the training and the certification separately?
    • No. The price provided covers both. You only pay once.
  • Do you offer any special offers and discounts?
    • We understand that many of our customers may be looking for discounts, and we would love to be able to offer them. However, we do not provide discounts because we believe that our prices are fair and reasonable. We work hard to keep our prices low, and we feel that discounts would be unfair to our other customers. We hope you understand.
  • If I can't solve the exercise where do I go for help?
  • Who reviews and marks exercises?
    • Trained cyber security instructors that work for Mossé Cyber Security Institute.
    • MCSI instructors are highly qualified and experienced professionals who are able to teach a variety of topics related to information security. They have the ability to tailor their teaching methods to meet the needs of each student, regardless of their experience level. In addition, they are always up-to-date on the latest trends and developments in information security, which enables them to provide students with the most relevant and current information.
  • We can't pay via credit card. Can you raise an invoice for wire payment instead?
    • Yes. Send us the list of bundles and certifications you want to purchase at [email protected]
  • Can I access a trial/demo the certification programmes prior to enrolling?
    • We provide a free curriculum with 100+ hours practical exercises you can try.
    • The Free Curriculum teaches Security Tools, Penetration Testing, Red Teaming, Threat Hunting, Cyber Defence, GRC and Windows Internals.
    • Try the Free Curriculum
  • Do you provide Continuing Professional Education (CPE) credits?
    • Yes. Every single exercise offers CPE credits. The number of credits earned depends on the difficulty of the exercise completed. Below are the CPE Credits achieve for an exercise in each difficulty:
    • Novice exercises = 1 CPE credits
    • Advanced Beginner exercises = 2 CPE credits
    • Competent exercises = 5 CPE credits
  • Do I need to complete an exam to receive MCSI Certification?
    • No. MCSI Certifications are completed by solving practical cybersecurity exercises.
  • Do I need to purchase cybersecurity tools or subscriptions?
    • No. Only free or trial versions are used in our exercises. You do not require making any purchases.

More Kind Words from Students

Enroll now with lifetime access for $1295

DO YOU HAVE A QUESTION?

We'll respond within 24 hours

Visit our Frequently Asked Questions (FAQ) page for answers to the most common questions we receive.

Ready to learn hands-on cyber security skills online?

Try 100 hours for free