C Ciso: Certified Chief Information Security Officer V3
C Ciso: Certified Chief Information Security Officer V3
C CISO
Certified Chief Information Security Officer
In order to sit for the CCISO exam and earn the certification,
candidates must meet the basic CCISO requirements. Candidates
who do not yet meet the CCISO requirements but are interested
in information security management can pursue the EC-Council
Information Security Management (EISM) certification.
“
Despite maintaining a dynamic career of nearly
23 years that reflects rich experience and year-
on-year success, I knew that it was time for me to move
one step further and stay on power with the latest
requirements for leaders in information security.
- Deryck Rodrigues,
Vice President – Group CIO Regulatory, Risk & Control
at Deutsche Bank AG.
The Five CCISO Domains
CCISOs are certified in the knowledge of and experience in the following CCISO Domains:
Information
Security Controls,
Compliance,
& Audit
Strategic Planning, Management
Finance,
Procurement,
5
& Vendor
Management CCISO
DOMAINS
Security Program
Management &
Information Operations
Security Core
Competencies
Certification:
To be approved to take the CCISO exam without first
taking certified training, you will need to show evidence
and present verifiers to show that you have 5 years of
experience in each of the five CCISO domains. Experience
waivers are available for some industry-accepted
certifications and CCISO Exam Eligibility Application
Form higher education. Between certification and
training waivers, applicants can only waive 3 years of
experience for each domain. If you have taken training,
you must show 5 years of experience in 3 of the 5 domains
Target Audience: in order to take the CCISO exam.
The CCISO is for information security
executives aspiring to be CISOs through Applicants found not qualified for the CCISO Exam may
refining their skills and learning to choose to take the EC-Council Information Security
align information security programs Manager (EISM) exam instead. The EISM exam is less
with business goals and objectives. This challenging than the CCISO exam and leads to the EISM
program also encourages existing CISOs certification, which has no experience requirements, but
to improve their technical and does require that you take CCISO training.
management skills, as well as business
procedures. Candidates that successfully pass the exam will receive
their C|CISO certificate and community privileges
Members are expected to adhere to recertification
requirements through EC-Council’s Continuing
Education Requirements.
CCISO WAR GAMES All instructors lead War Games, which mimic
what happens during a breach
The National Initiative for American National Standards GCHQ Certified Training
Cybersecurity Education Institute (ANSI) (GCT)
(NICE)
United States
Department of Defense United States Navy United States Army
(DoD)
“ The program trained me to look at every security incident from a different perspective –
not as a technical professional but someone who belongs to the managerial level.
The five domains were mapped in alignment to the NICE Cybersecurity Workforce Framework (NCWF),
a national resource that categorizes and describes cybersecurity work, listing common sets of duties and
skills needed to perform specific tasks.
The framework consists of seven highly important categories; one of which is “Oversight and Development”
and deals with leadership, management, direction, and advocacy. It was upon these requirements that
the CCISO program was created, with skill development courses in legal advice and advocacy, strategic
planning and policy development, Information Systems Security Operations (ISSO), and Security Program
Management (CISO) being 95% related to the NCWF.
“ Despite my 20 years working in the area of information technology, being 8 years with
experience in information security, and 15 years leading multidisciplinary teams in
infrastructure and cybersecurity, by becoming a Certified Chief Information Security Officer,
I have gained a better understanding of the five critical domains explained in EC-Council’s
CCISO Body of Knowledge and through real-life examples that were presented by the
instructor.
- Leandro Ribeiro,
Leader of Cyber Defense at United Health Group, Brazil.
Elements that make CCISO one of a kind
Accredited by ANSI
EC-Council has been accredited by the American National Standards Institute (ANSI) for its CCISO
certification program. It is one of the few certification bodies whose primary specialization is information
security in order to meet the ANSI/ISO/IEC 17024 Personnel Certification Accreditation standard.
The five domains of the CCISO program are mapped to the NICE Cybersecurity Workforce Framework
(NCWF), a national resource that categorizes and describes cybersecurity work, listing common sets of
duties and skills needed to perform specific tasks.
The CCISO program combines audit management, governance, IS controls, human capital management,
strategic program development, and the financial expertise vital to leading a highly successful IS program.
Material in the CCISO Program assumes a high-level understanding of technical topics and doesn’t spend
much time on strictly technical information, but rather on the application of technical knowledge to an
information security executive’s day-to-day work.
Bridges the Gap between Technical Knowledge, Executive Management, and Financial
Management
The CCISO aims to bridge the gap between the executive management knowledge that CISOs need and the
technical knowledge that many aspiring CISOs have. This can be a crucial gap as a practitioner endeavors to
move from mid-management to upper, executive management roles. Much of this is traditionally learned
as on the job training, but the CCISO Training Program can be the key to a successful transition to the
highest ranks of information security management.
To reach a C-Level position, an information security officer must have prior experience to gain a holistic
idea of what to expect while in the field. With this in mind, the CCISO program consists of many real-world
experiences faced by current CISOs around the world.
The CCISO exam also challenges students to develop a business continuity plan for a company in a given
industry and situation, use metrics to communicate risk for different audiences, and describes how to align
security programs with the goals of the business–among many other exercises.
The CCISO Advisory board is comprised of practicing CISOs who designed the program based on their day-
to-day experiences - based on both technical and management concerns. The board is made up of security
leaders from Amtrak, HP, the City of San Francisco, Lennar, the Center for Disease Control, universities, and
consulting firms who have contributed their vast knowledge to create this program to address the lack of
leadership training in information security.
Join the Elite – Become a Member of the
CCISO Community
As a member of the CCISO Community, you
can gain access to:
Free attendance at one EC-Council CISO Event per year (limited free passes available
- first come, first served) and deep discounts if you would like to attend more than
one event.
The opportunity to give webinars to large EC-Council audiences via our Security Channel.
Free subscription to CISO Mag – EC-Council’s online magazine for information security
leaders! Normally $79 per year.
EC-Council
www.eccouncil.org