1 – DOMAIN 1 – GOVERNANCE (POLICY, LEGAL AND COMPLIANCE)
- Information security management programme
- Defining an information security governance programme
- Compliance with regulatory and legal requirements
- Risk management
2 – INFORMATION SECURITY MANAGEMENT CONTROLS AND AUDIT MANAGEMENT
- Designing, deploying and managing security controls
- Understanding the types and objectives of security controls
- Implementing control assurance frameworks
- Understanding the audit management process
3 – DOMAIN 3 OF THE C|CISO PROGRAM COVERS THE DAY-TO-DAY RESPONSIBILITIES OF A CISO, INCLUDING
- The role of the CISO
- Information security projects
- Integrating security requirements into other operational processes (change management, version control, disaster recovery, etc.)
4 – DOMAIN 4 OF THE CCISO PROGRAM COVERS THE TECHNICAL ASPECTS OF THE CISO ROLE FROM A MANAGEMENT PERSPECTIVE, INCLUDING:
- Access controls
- Physical security
- Disaster recovery and business continuity planning
- Network security
- Threat and vulnerability management
- Application security
- Systems security
- Encryption
- Vulnerability assessments and penetration testing
- Computer forensics and incident response
5 – DOMAIN 5 OF THE CCISO PROGRAM ADDRESSES THE AREA WHERE MANY MORE TECHNICALLY ORIENTED PROFESSIONALS HAVE THE LEAST EXPERIENCE, INCLUDING:
- Strategic security planning
- Aligning with business goals and risk tolerance
- Emerging security trends
- Key Performance Indicators (KPIs)
- Financial planning
- Developing business cases for security
- Analysing, forecasting and preparing a capital expenditure budget
- Analysing, forecasting and preparing an operating expenditure budget
- Return on Investment (ROI) and cost-benefit analysis
- Vendor management
- Integrating security requirements into contractual agreements and procurement processes
- Together, these five domains of the C|CISO programme give participants a thorough grounding as competent information security leaders.