Course Outline
1. Overview of the Chief Information Security Officer (CISO) Function and Public Sector Context
- Assessing the strategic significance of the CISO position within government operations
- Defining roles, duties, and leadership standards for public sector leaders
- Integrating information security governance into national and agency strategic planning
2. Governance, Risk, and Compliance (GRC) Frameworks
- Constructing robust information security governance structures
- Harmonizing internal policies with ISO/IEC 27001, COBIT, and NIST benchmarks for government compliance
- Ensuring regulatory adherence and readiness for federal and state audits
3. Strategic Information Security Risk Management
- Techniques for identifying, analyzing, and mitigating digital and physical security risks
- Application of established risk management methodologies and frameworks
- Incorporating risk assessment into high-level policy decision-making processes
4. Security Program Architecture and Administration
- Formulating and executing comprehensive enterprise security strategies
- Formulating standardized security policies, protocols, and operational procedures
- Establishing performance metrics, reporting mechanisms, and continuous improvement cycles
5. Security Controls and Technological Infrastructure
- Analysis of contemporary security technologies and architectural models
- Implementation of data protection, identity management, and cloud security measures
- Application of defense-in-depth and zero-trust architectures for federal systems
6. Incident Response, Business Continuity, and Disaster Recovery
- Development and execution of standardized incident response protocols
- Strategies for maintaining business continuity and operational recovery
- Conducting post-incident reviews and integrating lessons learned into future planning
7. Executive Leadership, Communication, and Strategic Integration
- Cultivating a security-conscious culture across government agencies and departments
- Effectively conveying risk posture and strategic priorities to executive leadership and governing boards
- Oversight of cross-functional teams and management of vendor and partner relationships
8. PECB Certification Examination Preparation
- Review of exam structure, question formats, and core competency areas
- Engagement with practice assessments and simulated examination conditions
- Understanding certification procedures and ongoing maintenance obligations
Conclusion and Implementation Pathways
- Reevaluation of core leadership and governance competencies for public sector application
- Strategies for sustaining certification status and pursuing continuous professional development
- Identification of resources for advanced specialization in cybersecurity leadership
PECB Chief Information Security Officer (CISO) Certification Criteria
To obtain the PECB CISO credential, all candidates must successfully complete the official PECB Chief Information Security Officer examination and formally accept the PECB Code of Ethics.
Based on existing professional history and leadership experience, candidates may qualify for one of two distinct credential levels:
1. Information Security Officer
-
Credential Designation: PECB Certified Information Security Officer
-
Required Professional Experience: No minimum years of experience mandated
-
CISO Management System Project Experience: No specific project hours required
-
Target Audience: Entry-to-mid-level security professionals or managers who have passed the examination but lack the extensive executive track record associated with the Chief level title.
2. Chief Information Security Officer
-
Credential Designation: PECB Certified Chief Information Security Officer
-
Required Professional Experience: A minimum of five years of total professional experience, including at least two years specifically dedicated to information security roles.
-
CISO Management System Project Experience: A cumulative minimum of 300 hours of documented project involvement.
https://pecb.com/en/education-and-certification-for-individuals/pecb-ciso/ciso
Requirements
- Working knowledge of information security concepts and established frameworks
- Practical experience in information security or IT governance roles
- Recommended familiarity with ISO/IEC 27001 or equivalent industry standards
Target Audience
- Information Security Managers and Senior IT Professionals in the public sector
- Risk Management and Compliance Officers
- IT Directors and Government Consultants
- Professionals seeking to assume the role of Chief Information Security Officer (CISO) in government
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .
Dana Foster - Corrigan Oil Company
Course - ISO 9001 Foundation
Speed of response and communication