
Defensible 10 Practitioner Course
Apply the Standards. Perform the Work. Prove the Results.
Defensible 10 Practitioner—Pro Bundle
Payment options available
A complete path from standards to implementation and proof. Includes the D10S Practitioner course, digital materials, practical domain exercises, one CPL Cyber Capstone Portfolio evaluation, and lifetime ISAUnited membership.
Includes:
-
Course access
-
Course eBooks
-
CPL Cyber Capstone (1 attempt)
-
Plus, a lifetime ISAU membership
What will I Learn?
Defensible 10 Practitioner Course
Description
ISAUnited’s D10S Practitioner course prepares cybersecurity professionals to implement the Defensible 10 Standards in practice within an organization.
Students learn a structured and repeatable method for interpreting Parent Standard requirements, applying Associate Standards, gathering current-state evidence, identifying technical gaps, and converting requirements into actionable engineering work.
The program teaches Practitioners how to develop technical specifications, implement assigned improvements, define measurable acceptance criteria, perform Verification and Validation, and document results in Evidence Workbooks and Evidence Packs.
The Practitioner performs the technical work within their assigned area. They collaborate with technical owners and D10S Champions to ensure implementation results are measurable, tested, traceable, and supported by objective evidence.
Field of study: Cybersecurity — Architecture & Engineering Standards
Program level: Certified Professional
Pathway: Defensible 10 Credential
Delivery format: 100% online (self-paced) with technical instructor support
Pace: ≤10 days (2 weeks)
Credits: 20 CPEs
Exam: Cyber Capstone Portfolio

Mastering The Defensible 10 (ebook included)
This book introduces the Defensible 10 Standards and provides a practitioner-oriented method for applying the 10 parent domains as measurable cybersecurity architecture and engineering disciplines.
Edition: First Edition 2026
ISBN: 979-8-218-78040-1
What will I take?
BASIC Courses
CORE Courses
D10S301
Course: D10S Technical Implementation, Verification and Evidence-Based Practice
Field: Defensible 10 Standards
A core practitioner course in the Defensible 10 Standards focused on technical implementation, Verification and Validation, and evidence production. Covers how to interpret Parent and Associate Standards; define scope and technical gaps; translate requirements into engineering work and acceptance criteria; implement assigned controls and specifications; verify and validate results; and document evidence, exceptions, dependencies, and outcomes for Champion review.
What is the Exam?
Cyber Capstone Portfolio
Description
A focused, real-world mission scenario that allows you to demonstrate practical D10S implementation capability through a concise, defensible submission. The Cyber Capstone uses a structured Mission Pack and is completed individually as a written, remote, time-boxed assignment over two weeks (10 business days). Earlier submission is accepted. There are no multiple-choice tests.
What you will complete
-
Artifact 1: Practitioner Assignment Brief and Scope
Define the assigned domain, technical objective, implementation scope, stakeholders, owners, assumptions, and constraints. -
Artifact 2: Current-State Technical Assessment
Review the supplied architecture, configurations, and evidence. Evaluate the applicable Parent and Associate Standard requirements and identify what is met, partially met, not met, not applicable, or cannot be verified. -
Artifact 3: Technical Implementation Package
Convert identified gaps into actionable engineering tickets with D10S references, technical specifications, owners, acceptance criteria, rollback requirements, and required evidence. -
Artifact 4: Verification, Validation, and Evidence Package
Define and document how the proposed work will be verified, validated, retested, and recorded through the Evidence Workbook. -
Artifact 5: Implementation Status Briefing
Summarize the technical assessment, proposed improvements, open gaps, V&V results, evidence status, and recommended next steps in a concise presentation deck with speaker notes.
How it is evaluated
Your submission is evaluated using the ISAUnited Defensible Capability Score, a two-section scoring model based entirely on your written deliverables.
Part 1 — Practitioner Artifact Evaluation: Pass or Fail
Evaluates standards interpretation, assessment completeness, technical accuracy, ticket quality, acceptance criteria, traceability, Verification and Validation, evidence readiness, and defensibility.
Part 2 — Skills, Knowledge, and Abilities Capability Profile
Evaluates disciplined practice, technical judgment, implementation planning, evidence management, collaboration, and communication, with references tied directly to the submitted artifacts.
Outcome
Successful completion satisfies the Cyber Capstone Portfolio requirement for the ISAUnited Certified Professional License in the D10S Practitioner track.
What Do I Get?

Your Professional License - Certified Defensible 10 Practitioner
This is the license you earn when you pass the D10S CPL evaluation (included in the Pro Bundle). The evaluation is capstone-based—no multiple-choice exams. A successful review adds your name to the ISAUnited public registry.
-
Designation: Certified Defensible 10 Professional
-
Credentialing: Digital certificate + verifiable License ID/issue date
-
The Certified Professional License is valid for a three-year term.


