CIS and SANS: A Longstanding Partnership Built to Advance Cybersecurity

Strong cybersecurity doesn’t happen overnight; it’s built on proven frameworks, skilled practitioners, and trusted collaboration. For decades, the SANS Institute and the Center for Internet Security (CIS) have worked together to deliver exactly that by making cybersecurity more practical, accessible, and effective.

That partnership continues to evolve to meet today's cybersecurity landscape with a new bundled offering that brings CIS Hardened Images and SANS cloud security training together in AWS Marketplace, helping organizations deploy secure cloud environments while building the expertise to sustain them.

This combined offering represents more than a new solution. It represents the latest milestone in a long-standing collaboration focused on helping organizations, from global enterprises to small and underserved communities, build stronger cybersecurity foundations.

A Partnership Rooted in Shared History and Mission

partnership logoThe relationship between CIS and SANS is rooted in shared leadership and a common mission. Both organizations share a common co-founder in Alan Paller, an industry visionary and pioneer who helped shape modern cybersecurity education and co-developed the CIS Critical Security Controls (CIS Controls) originally introduced as the SANS Top 20.

Since their introduction in 2008, the CIS Controls have helped organizations prioritize defenses against the most common cyber threats with clear, actionable guidance. In 2015, CIS assumed stewardship of the Controls, continuing their evolution while maintaining their practitioner-driven foundation.

Since then, the CIS Controls have evolved into a globally recognized standard, continuously refined by a community of experts. At every stage, CIS and SANS have remained aligned in developing the CIS Controls and other cybersecurity resources, and ensuring those efforts are accessible and implementable for all organizations, regardless of their size or available resources.

A Shared Mission: Expanding Access to Cybersecurity

shared mission logoA defining characteristic of the CIS–SANS partnership is the shared commitment to expanding access to cybersecurity resources to organizations of all sizes.

Together, CIS and SANS actively support small and underserved organizations that may lack the resources and expertise needed to address today's cyber threats. Initiatives focused on affordable training, workforce development, and awareness programs help close this gap, ensuring that even resource-constrained teams can build essential cyber resilience.

From foundational training and guidance like CIS Implementation Group 1 to broader cybersecurity awareness efforts, both organizations emphasize practical, real-world skills and scalable guidance that help small-to-medium enterprises and underserved organizations improve their cybersecurity posture and equip teams with the knowledge and tools needed to defend against modern threats.

This shared mission reflects a long-standing belief: stronger cybersecurity at the organizational level leads to a safer, more secure digital ecosystem for everyone.

Learn more about the deep partnership between CIS and SANS in the conversation below between CIS SVP and Chief Evangelist Tony Sager and SANS Instructor and Author Rich Greene, conducted at RSAC Conference 2026.

Bringing the Partnership to AWS Marketplace

bridging partnership logoThe latest CIS and SANS collaboration brings this combined expertise directly to AWS Marketplace, streamlining how organizations secure their cloud environments.

The bundled offering combines:

This combined approach addresses a common challenge: technology alone is not enough to sustain cybersecurity. Teams must also understand how to manage and evolve that environment as threats change.

From Day-One Security to Long-Term Resilience

By combining CIS Hardened Images with SANS training, organizations gain both immediate and lasting benefits:

  • Accelerate secure cloud migration with pre-hardened, CIS Benchmark-aligned images
  • Reduce risk and configuration drift across cloud environments
  • Support compliance efforts with trusted security configuration guidance
  • Build internal cloud security expertise through hands-on practitioner training

This approach ensures organizations are not only secure at launch, but resilient throughout the lifecycle of their cloud environments.

Operationalizing the CIS Controls with SANS

operationalizing logoThe CIS Controls provide the foundation for this approach, while SANS training plays a critical role in helping organizations put those safeguards into practice.

Courses like SEC366: CIS Implementation Group 1 and SEC566: Implementing and Auditing CIS Controls teach practitioners how to apply these best practices in real-world environments, from on-premises systems to cloud platforms.

By aligning training with the Controls, CIS and SANS ensure that guidance translates into measurable, actionable improvements in security posture.

Take the Next Step Toward Secure Cloud Adoption

For decades, CIS and SANS have worked together to make cybersecurity more practical, accessible, and effective. Now, with this joint offering in AWS Marketplace, that partnership delivers an end-to-end solution for modern cloud security.

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.