Course Outline
1. Overview of the Chief Information Security Officer (CISO) Role and Organizational Context
- Evaluating the strategic value of the CISO position within federal and corporate structures
- Defining roles, responsibilities, and leadership expectations for senior security executives
- Integrating information security governance with overarching organizational strategy
2. Governance, Risk, and Compliance (GRC)
- Establishing robust information security governance frameworks for government and private sector entities
- Aligning security policies with ISO/IEC 27001, COBIT, and National Institute of Standards and Technology (NIST) standards
- Ensuring regulatory compliance and maintaining readiness for internal and external audits
3. Information Security Risk Management
- Implementing techniques for risk identification, analysis, and mitigation in government operations
- Applying established risk management methodologies and frameworks for public sector accountability
- Integrating risk management principles into senior-level corporate and governmental decision-making processes
4. Security Program Development and Management
- Designing and executing enterprise-wide security strategies tailored for government environments
- Formulating comprehensive security policies, standards, and operational procedures
- Utilizing metrics, reporting mechanisms, and continuous improvement cycles to enhance program effectiveness
5. Information Security Controls and Technologies
- Assessing modern security technologies and architectural models suitable for government systems
- Addressing data protection, identity and access management, and cloud security requirements
- Applying defense-in-depth and zero-trust architectures to secure federal infrastructure
6. Incident Management, Business Continuity, and Disaster Recovery
- Developing and operationalizing incident response plans aligned with federal crisis management protocols
- Establishing business continuity planning and recovery strategies for critical government services
- Conducting post-incident reviews and incorporating lessons learned to improve future preparedness
7. Leadership, Communication, and Strategic Alignment
- Fostering a culture of security awareness across federal agencies and corporate teams
- Effectively communicating risk profiles and strategic initiatives to executive leadership and governing boards
- Managing cross-functional teams and overseeing third-party vendor relationships for government projects
8. PECB Certification Exam Preparation
- Reviewing exam structure, format, and key topic areas relevant for government cybersecurity professionals
- Practicing with sample questions and mock examinations to ensure readiness for certification
- Understanding the certification process and ongoing maintenance requirements for credentialed officials
Summary and Next Steps
- Recapping essential leadership and governance competencies for public sector security leaders
- Providing guidance on maintaining certification status and pursuing continuing professional development
- Distributing resources for further specialization in cybersecurity leadership within the government sector
PECB Chief Information Security Officer (CISO) Certification Requirements
To qualify for the PECB CISO designation, all applicants must successfully pass the formal PECB Chief Information Security Officer examination and agree to adhere to the PECB Code of Ethics.
Based on existing professional history and leadership background, candidates may apply for one of two specific credential tiers:
1. Information Security Officer
-
Credential Title: PECB Certified Information Security Officer
-
Professional Experience Required: None
-
CISO Management System Project Experience: None
-
Target Audience: Entry-to-mid level security professionals or managers who have successfully passed the examination but do not yet possess the extensive executive track record required for the chief title.
2. Chief Information Security Officer
-
Credential Title: PECB Certified Chief Information Security Officer
-
Professional Experience Required: Five years of overall professional experience, including a minimum of two years explicitly dedicated to information security work experience.
-
CISO Management System Project Experience: A cumulative total of at least 300 hours of documented project activities relevant for government or corporate security initiatives.
https://pecb.com/en/education-and-certification-for-individuals/pecb-ciso/ciso
Requirements
Key Qualifications
- Comprehensive understanding of information security principles and established frameworks.
- Practical experience within information security or IT governance capacities.
- Familiarity with ISO/IEC 27001 or comparable regulatory standards is preferred.
Target Audience
- Information Security Managers and senior information technology specialists.
- Risk management and compliance officers.
- IT Directors and advisory consultants.
- Professionals seeking advancement to Chief Information Security Officer (CISO) positions, with a specific focus on solutions designed for government environments.
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
Speed of response and communication