CCISO Brochure V.11 1
CCISO Brochure V.11 1
Certified
Chief Information
Security Officer
www.ciso.eccouncil.org
ABOUT THE PROGRAM
The globally renowned Chief Certified professional’s career into the realm of
Information Security Officer (C|CISO) executive leadership.
program, spearheaded by EC-Council, has
truly revolutionized the capabilities of Through the C|CISO program, EC-Council
senior information security professionals will transfer the knowledge of seasoned
worldwide. With unwavering dedication, EC- professionals to you, the next generation of
Council harnessed the collective wisdom of a leadership, by focusing on the most critical
select group of esteemed senior information competencies required to develop and
security executives within our esteemed maintain a successful information security
C|CISO Advisory Board. This exceptional portfolio. The C|CISO program is a first-of-
panel of seasoned professionals meticulously its-kind training and certification course that
crafted the program’s bedrock, delineating aims to produce cybersecurity executives of
the comprehensive content encapsulated in the highest caliber and ethics. The C|CISO
the C|CISO exam, the body of knowledge, curriculum—developed by seasoned CISOs
and the training program. Through their for current and aspiring CISOs—takes an
invaluable expertise, EC-Council has executive management viewpoint that
empowered countless CISOs to excel in the incorporates both information security
realm of information security. management principles and general technical
knowledge.
Members of the Board contributed as
authors, exam writers, and instructors. They Professional experience is required for entry
also provided continuous quality assurance into this certification program. Candidates
through periodic materials reviews. Each must meet the basic C|CISO requirements in
segment of the C|CISO Program was order to take the certification examination.
developed in order to move a security
“While my 23 years of a dynamic career reflects rich experiences and a successful journey, I realized
it [was] time to move one step further and stay in power with the latest requirements for leaders in
information security.
The C|CISO was an ideal choice for me, as it provided the necessary knowledge [of] required
information security management, executive leadership, and risk management strategies to protect
an organization.”
— Deryck Rodrigues Vice President—Group CIO Regulatory, Risk & Control, Deutsche Bank
2
Information security
Domains controls, compliance, and
audit management
C|CISOs exhibit their
knowledge and experience
3
within five core domains: Security program
management and
operations
4
Information
security core
competencies
5
Strategic planning,
finance, procurement,
Who Needs the and vendor management
C|CISO Program?
The C|CISO certification is designed for information security professionals who want to
advance their careers as a CISO or other executive-level security career path. In the C|CISO
program, cybersecurity leaders hone their knowledge and learn how to integrate information
security initiatives with needs of the business, aligning to the critical goals and objectives of an
organization. Existing CISOs are also encouraged to participate in this program to strengthen
their security program knowledge, understand current technology principles, and sharpen
their business acumen.
Upon passing the C|CISO exam, candidates will receive their C|CISO certificate and associated
community privileges. The C|CISO certification is valid for 3 years from the date of issuance.
After 3 years, members must adhere to the certification renewal policy as outlined in the EC-
Council Continuing Education (ECE) requirements
Candidates who do not meet 5 years of experience in 3 of the C|CISO domains, but have 2 or
more years of experience in at least 1 domain (or currently hold any one of the CISSP, CISM,
CISA certifications) can participate in the Associate C|CISO program.
Candidates participating in the Associate C|CISO will have the opportunity to attend the same
training as our C|CISO candidates, and learn the job requirements of a security executive so
they can plan their careers to meet their career goals of security industry leadership.
C|CISO training is mandatory for all Associate C|CISO candidates prior to taking the Associate
C|CISO examination.
“If you want to be the best, I strongly believe the C|CISO credential should be one of the first things
you add to your professional profile.”
•A
merican National Standards Institute (ANSI)
The C|CISO is independently accredited and designed to meet the rigorous ANSI
standards.
•U
.S. Department of Defense (DoD)
The CCISO certification is an approved baseline certification under DoD Directive
8570/8140.
•U
.S. Armed Forces
The CCISO certification provides an excellent opportunity for advancement in the U.S.
military and is recognized by the U.S. Army, Navy, Air Force, and Marine Corps.
•G
overnment Communications Headquarters (GCHQ) Certified Training
The CCISO course is designed to meet the standards of the United Kingdom’s GCHQ.
Recommendations
and Accreditations
Accredited by ANSI
The five C|CISO domains bring together the components required for a C-level information
security position. The C|CISO curriculum combines security risk management, controls,
audit management, security program management and operations, governance, information
security core concepts, strategic planning, finance, and vendor management—all of which are
vital for leading a highly successful information security program.
The five C|CISO domains align with the NICE Workforce Framework for Cybersecurity,
a national resource that categorizes and describes cybersecurity work and roles, including
common job duties and skills needed to perform specific tasks. In addition to outlining 33
specialty areas and 52 work roles, the NICE Framework defines seven highly important
cybersecurity functions:
SECURELY PROVISION
Accredited by ANSI
EC-Council’s C|CISO certification program is accredited by ANSI. EC-Council is one of the ew
certification bodies with a primary specialization in information security to meet the ANSI/
ISO/IEC 17024 personnel certification accreditation standard.
Complimentary access to one EC-Council CISO event per year (limited free passes available on
a first-come, first-served basis), plus discounts for additional events