Course Description
The Certified Chief Information Security Officer (CCISO) Program has certified leading information security professionals around the world. A core group of high-level information security executives, the CCISO Advisory Board, formed the foundation of the program and outlined the content covered by the exam, body of knowledge, and training. Some members of the Board contributed as authors, others as exam writers, others as quality assurance checks, and still others as instructors. Each segment of the program was developed with the aspiring and sitting CISO in mind and looks to transfer the knowledge of seasoned executives to the next generation of leaders in the areas that are most critical in the development and maintenance of a successful information security program.
The CCISO Certification is an industry-leading, security certification program that recognizes the real-world experience necessary to succeed at the highest executive levels of information security. Bringing together all the components required for a C-Level position, the CCISO program combines audit management, governance, IS controls, human capital management, strategic program development, and the financial expertise vital to leading a highly successful information security program. The job of the CISO is far too important to be learned by trial and error. Executive-level management skills are not areas that should be learned on the job.
The material in the CCISO Program assumes a high-level understanding of technical topics and doesn’t spend much time on strictly technical information, but rather on the application of technical knowledge to an information security executive’s day-to-day work. The CCISO aims to bridge the gap between the executive management knowledge that CISOs need and the technical knowledge that many sitting and aspiring CISOs have. This can be a crucial gap as a practitioner endeavors to move from mid-management to upper, executive management roles. Much of this is traditionally learned as on the job training, but the CCISO Training Program can be the key to a successful transition to the highest ranks of information security management.
Agenda
Certified Chief Information Security Officer (CCISO) Master Program:
Domain 1: Governance and Risk Management
1. Define, Implement, Manage, and Maintain an Information Security Governance Program
1.1. Form of Business Organization
1.2. Industry
1.3. Organizational Maturity
2. Information Security Drivers
3. Establishing an information security management structure
3.1. Organizational Structure
3.2. Where does the CISO fit within the organizational structure
3.3. The Executive CISO
3.4. Nonexecutive CISO
4. Laws/Regulations/Standards as drivers of Organizational Policy/Standards/Procedures
5. Managing an enterprise information security compliance program
5.1. Security Policy
5.1.1. Necessity of a Security Policy
5.1.2. Security Policy Challenges
5.2. Policy Content
5.2.1. Types of Policies
5.2.2. Policy Implementation
5.3. Reporting Structure
5.4. Standards and best practices
5.5. Leadership and Ethics
5.6. EC-Council Code of Ethics
6. Introduction to Risk Management
3.1. Organizational Structure
3.2. Where does the CISO fit within the organizational structure
3.3. The Executive CISO
3.4. Nonexecutive CISO
Audience
To sit for the exam after taking training, candidates must have five years of experience in three of the five CCISO Domains verified via the Exam Eligibility Application.