Course Outline
1. Introduction to the CISO Role and Organizational Context
- Understanding the strategic importance of the Chief Information Security Officer (CISO) position within government agencies.
- Defining roles, responsibilities, and leadership expectations for CISOs in public sector organizations.
- Integrating information security governance into broader corporate strategies for government operations.
2. Governance, Risk, and Compliance (GRC)
- Developing robust information security governance frameworks tailored for government use.
- Ensuring alignment of policies with industry standards such as ISO/IEC 27001, COBIT, and NIST to enhance cybersecurity in public sector operations.
- Achieving regulatory compliance and maintaining audit readiness for government agencies.
3. Information Security Risk Management
- Implementing effective risk identification, analysis, and mitigation techniques for government entities.
- Utilizing established risk management methodologies and frameworks to protect public sector information assets.
- Integrating risk management into decision-making processes within government organizations.
4. Security Program Development and Management
- Designing and implementing comprehensive enterprise security strategies for government agencies.
- Developing and maintaining security policies, standards, and procedures to ensure robust protection of public sector data.
- Establishing metrics, reporting mechanisms, and continuous improvement processes to enhance cybersecurity in government operations.
5. Information Security Controls and Technologies
- Providing an overview of modern security technologies and architectures suitable for government applications.
- Addressing data protection, identity management, and cloud security in the context of public sector operations.
- Applying defense-in-depth and zero-trust principles to enhance cybersecurity in government environments.
6. Incident Management, Business Continuity, and Disaster Recovery
- Developing and implementing incident response plans tailored for government agencies.
- Formulating business continuity planning and recovery strategies to ensure uninterrupted public sector operations.
- Conducting post-incident reviews and applying lessons learned to improve future responses in government settings.
7. Leadership, Communication, and Strategic Alignment
- Building a security-aware culture across government organizations.
- Effectively communicating risk and strategic initiatives to executive leadership and the board of directors in government agencies.
- Managing cross-functional teams and vendor relationships to support cybersecurity objectives for government operations.
8. PECB Certification Exam Preparation
- Reviewing the exam structure, format, and key topics relevant to public sector CISOs.
- Practicing with sample questions and a mock exam to prepare for certification in government roles.
- Understanding the certification process and maintenance requirements for ongoing professional development in government cybersecurity leadership.
Summary and Next Steps
- Reviewing key leadership and governance competencies essential for CISOs in government agencies.
- Providing guidance on maintaining certification and continuing professional development to support ongoing cybersecurity needs for government operations.
- Offering resources for further specialization in cybersecurity leadership within the public sector.
Requirements
- Understanding of information security principles and frameworks
- Experience in information security or IT governance positions
- Knowledge of ISO/IEC 27001 or similar standards is advised
Audience
- Information Security Managers and Senior IT Professionals
- Risk and Compliance Officers
- IT Directors and Consultants
- Individuals seeking to advance into Chief Information Security Officer (CISO) roles, particularly for government entities
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
Speed of response and communication