top of page
Image by Alvaro Reyes

Defensible 10 Practitioner  Course

Apply the Standards. Perform the Work. Prove the Results.

Defensible 10 Practitioner—Pro Bundle

Payment options available

 

A complete path from standards to implementation and proof. Includes the D10S Practitioner course, digital materials, practical domain exercises, one CPL Cyber Capstone Portfolio evaluation, and lifetime ISAUnited membership.​

Includes:

  • Course access

  • Course eBooks

  • CPL Cyber Capstone (1 attempt)

  • Plus, a lifetime ISAU membership

What will I Learn?

Defensible 10 Practitioner Course

Description

ISAUnited’s D10S Practitioner course prepares cybersecurity professionals to implement the Defensible 10 Standards in practice within an organization.

Students learn a structured and repeatable method for interpreting Parent Standard requirements, applying Associate Standards, gathering current-state evidence, identifying technical gaps, and converting requirements into actionable engineering work.

The program teaches Practitioners how to develop technical specifications, implement assigned improvements, define measurable acceptance criteria, perform Verification and Validation, and document results in Evidence Workbooks and Evidence Packs.

The Practitioner performs the technical work within their assigned area. They collaborate with technical owners and D10S Champions to ensure implementation results are measurable, tested, traceable, and supported by objective evidence.

Field of study: Cybersecurity — Architecture & Engineering Standards

 

Program level: Certified Professional

 

Pathway: Defensible 10  Credential

 

Delivery format: 100% online (self-paced) with technical instructor support

 

Pace: ≤10 days (2 weeks)

 

Credits: 20 CPEs

 

Exam: Cyber Capstone Portfolio

D10S_cover_webpic3.png

Mastering The Defensible 10 (ebook included)

This book introduces the Defensible 10 Standards and provides a practitioner-oriented method for applying the 10 parent domains as measurable cybersecurity architecture and engineering disciplines.

Edition:      First Edition 2026

ISBN:           979-8-218-78040-1

What will I take?

BASIC Courses

B100 

Course: Defensible 10 Standards Foundations

Field: Cybersecurity Essentials

This course introduces students to the Defensible 10 Standards and explains how the ten domains organize security responsibilities across enterprise and cloud environments. Students learn the purpose of each domain, the relationships among controls, requirements, and measurable acceptance criteria, and how to interpret a system diagram through the D10S lens. 

B102

Course: Cybersecurity Core Principles
 

Field: Cybersecurity Essentials

A practical introduction to the ideas that anchor secure design, from confidentiality and integrity to least privilege, layered defenses, and verifiable operations. Learn how these principles shape choices in architecture, configuration, and daily practice across data centers and cloud services. Through real examples and guided critiques, connect each principle to measurable outcomes that reduce risk and produce resilient, trustworthy systems.

B104

Course: Cybersecurity Controls Management Framework

Field: Cybersecurity Essentials

This course teaches students how to build a clear, organized system for selecting, mapping, measuring, and maintaining security controls across enterprise and cloud environments. Students learn to translate policy goals into concrete requirements, plan evidence from the outset, and conduct ongoing checks that demonstrate that protections work in real-world operations.

B107

Course: Security by Design Foundations

Field: Cybersecurity Essentials

Security by Design Foundations teaches you to plan and review security like an engineer: set measurable goals, use simple design models to place controls, make sound trade-offs, add lightweight delivery guardrails, and produce evidence that your choices work. Built for both managers and technical teams.

 

CORE Courses

D10S301

Course: D10S Technical Implementation, Verification and Evidence-Based Practice

Field: Defensible 10 Standards

A core practitioner course in the Defensible 10 Standards focused on technical implementation, Verification and Validation, and evidence production. Covers how to interpret Parent and Associate Standards; define scope and technical gaps; translate requirements into engineering work and acceptance criteria; implement assigned controls and specifications; verify and validate results; and document evidence, exceptions, dependencies, and outcomes for Champion review.

What is the Exam?

Cyber Capstone Portfolio

Description

A focused, real-world mission scenario that allows you to demonstrate practical D10S implementation capability through a concise, defensible submission. The Cyber Capstone uses a structured Mission Pack and is completed individually as a written, remote, time-boxed assignment over two weeks (10 business days). Earlier submission is accepted. There are no multiple-choice tests.

 

What you will complete

  • Artifact 1: Practitioner Assignment Brief and Scope
    Define the assigned domain, technical objective, implementation scope, stakeholders, owners, assumptions, and constraints.

  • Artifact 2: Current-State Technical Assessment
    Review the supplied architecture, configurations, and evidence. Evaluate the applicable Parent and Associate Standard requirements and identify what is met, partially met, not met, not applicable, or cannot be verified.

  • Artifact 3: Technical Implementation Package
    Convert identified gaps into actionable engineering tickets with D10S references, technical specifications, owners, acceptance criteria, rollback requirements, and required evidence.

  • Artifact 4: Verification, Validation, and Evidence Package
    Define and document how the proposed work will be verified, validated, retested, and recorded through the Evidence Workbook.

  • Artifact 5: Implementation Status Briefing
    Summarize the technical assessment, proposed improvements, open gaps, V&V results, evidence status, and recommended next steps in a concise presentation deck with speaker notes.

How it is evaluated

Your submission is evaluated using the ISAUnited Defensible Capability Score, a two-section scoring model based entirely on your written deliverables.

Part 1 — Practitioner Artifact Evaluation: Pass or Fail
Evaluates standards interpretation, assessment completeness, technical accuracy, ticket quality, acceptance criteria, traceability, Verification and Validation, evidence readiness, and defensibility.

Part 2 — Skills, Knowledge, and Abilities Capability Profile
Evaluates disciplined practice, technical judgment, implementation planning, evidence management, collaboration, and communication, with references tied directly to the submitted artifacts.

 

Outcome

Successful completion satisfies the Cyber Capstone Portfolio requirement for the ISAUnited Certified Professional License in the D10S Practitioner track.

What Do I Get?

CPL-D10S_Cert_practitioner.png.jpg

Your Professional License - Certified Defensible 10 Practitioner

This is the license you earn when you pass the D10S CPL evaluation (included in the Pro Bundle). The evaluation is capstone-based—no multiple-choice exams. A successful review adds your name to the ISAUnited public registry.

  • Designation: Certified Defensible 10 Professional

  • Credentialing: Digital certificate + verifiable License ID/issue date

  • The Certified Professional License is valid for a three-year term.

Are you Ready?

Do you have questions about which program to choose or how the CPL works? Book a quick consult and we’ll help you or send us a message below.

Scrabble Letters

Acronym Library

Decode Our Alphabet Soup!

bottom of page