C/CISO (Certified Chief Information Security Officer)
5-day training to become a Certified Chief Information Security Officer. C/CISO is the first and only certification/title in the world for (aspiring) CISOs! The C/CISO training includes the official EC-Council C/CISO v4 exam.
C/CISO v4 (Certified Chief Information Security Officer) – mode of study
Option 1: 5-day training (in-class and live online)
Option 2: in-company training (in-class and live online)
Why become a Certified Chief Information Security Officer (C/CISO)?
Organizations are increasingly in need of a new set of skills and processes to ensure the security of information at a scale that will be required tomorrow. As a C/CISO, you possess the proven knowledge and experience to plan and oversee information security for the entire corporation. The C/CISO certification is the right choice for you and your career if you:
- Aspire to attain the most respected title within the information security profession: CISO
- Already serve as an official CISO, or
- Perform a CISO position in your organization without the official title
C/CISO at a glance
- C/CISO is the world's first and only - vendor independent - certification for CISOs and aspiring CISOs
- C/CISO is ranked at the top 5 amongst 800 certifications, based on salary package
- 99% of the delegates reported that the C/CISO training vastly improved their cybersecurity leadership skills
- 76% of the delegates achieved a higher salary after becoming C/CISO certified
Advance your career now and become a certified CISO!
C/CISO – toplevel certification training for (aspiring) Chief Information Security Officers
This 5-day C/CISO training has certified numerous leading information security professionals around the world. It is the first of its kind training and certification program aimed at producing top-level information security leaders. The C/CISO training does not focus solely on technical knowledge, but on the application of information security management principles from an executive management point of view.
The C/CISO program assumes a high-level understanding of technical topics and does not spend much time on strictly technical information, but rather on applying this technical knowledge in an information security executive's daily work. The C/CISO training aims to bridge the gap between the executive management knowledge that CISOs need and the technical knowledge that many (aspiring) CISOs have.
The program is comprised of 3 components: training, the Body of Knowledge (BoK), and the C/CISO exam. The training consists of individualized instruction, hands-on labs, group exercises, and self testing. On the last training day, you will participate in an interactive Cyber Wargame in which a cyber incident is simulated and dealt with from a CISO's perspective.
Why is the C/CISO certification important for organizations?
The C/CISO certification assures organizations that their certified professionals possess the necessary skills to identify factors that pose a risk to the successful operation of the organization and to develop and implement technical, operational, and procedural safeguards to manage those risks. C/CISOs are the leadership force that will protect the organization from undesired and costly security breaches by designing information security programs and leading a team of information security professionals.
Protect your business now with this high-level certified CISO training for your security professionals!
Who should be C/CISO trained and certified?
C/CISO is the step anyone interested in an executive career in information security should take after completing certification trainings like CISSP, CISA, CISM, etc. Are you working in a CISO position or do you want to work in a CISO position, then this is the training for you.
The C/CISO designation is well-known, highly respected, and often a certification requirement for professionals like (aspiring) CISO's, security managers, security administrators, CIOs, network engineers with a specialization in security, security specialists, security analysts, security engineers, security architects, risk officers, IT auditors, and many other information security professionals.
About the C/CISO (exam) domains
The C/CISO training covers the 5 C/CISO domains, ensuring a holistic understanding of information security from a leadership perspective. C/CISOs are certified for their knowledge of and experience in the following C/CISO (exam)domains:
- Domain I - Governance and risk management
- Domain II - Information security controls, compliance, and audit management
- Domain III - Security program management and operations
- Domain IV - Information security core competencies
- Domain V - Strategic planning, finance, procurement, and third-party management
C/CISO prerequisites/eligibility
There are no prerequisites to attend the C/CISO training. However, in order to sit the C/CISO exam, you must demonstrate 5 years of experience in 3 of the 5 C/CISO domains (verified via the EC-Council's exam eligibility application you will find in your personal online learning environment).
About the C/CISO exam
EC Council's exam to become a Certified Chief Information Security Officer (C/CISO) is scenario-based and consists of 150 multiple choice questions. The exam takes 2,5 hours of your time. The passing score is 75%. The delivery is computer-based and you can take the exam on our training location or remotely at a time convenient to you.
Should you not pass the C/CISO or Associate C/CISO exam the first time, you may re-attend the C/CISO training for free (within a period of one year)!
Not yet qualified to take the C/CISO exam? Become an Associate C/CISO!
Should you not (yet) meet the minimum requirements for the C/CISO exam, you can take the Associate C/CISO exam. The course outline and examination for Associate C/CISO is the same as for the C/CISO certification!
Who is the Associate C/CISO certification for?
The Associate C/CISO certification is suitable for all cyber and security professionals who possess either a minimum of 2 or more years of experience in any of the C/CISO domains or already hold certifications such as CISA, CISM or CISSP.
Transition from Associate C/CISO to C/CISO
Associate C/CISOs may apply for the C/CISO exam once they have attained the required years of experience. After successfully passing the C/CISO exam, you will be granted the C/CISO title. Associate C/CISOs will have their expertise verified with EC-Council before being approved to take the C/CISO exam.
Renewal of your C/CISO certification
Your C/CISO certification is valid for a period of 3 years. To renew your C/CISO certification you must satisfy the continuing education requirements of EC-Council and remit a renewal fee of USD 100.
Level of the training
The C/CISO training is lectured on a Bachelor level.
About EC-Council
EC-Council is the world's largest cyber security technical certification body and operates in more than 150 countries globally. EC-Council has trained and certified over 200,000 information security professionals worldwide. EC-Council is the owner and developer of the world-famous CEH (Certified Ethical Hacker), EDRP (Disaster Recovery Professional), and C/TIA (Certified Threat Intelligence Analyst) trainings and certifications, among many others. The C/CISO training will be organised in collaboration with Tshukudu Technology College, an authorized partner of EC-Council.
Extra – free trial of phishing tool
As an attendee of the C/CISO training you will receive a free e-mail phishing simulation tool to protect your workplace (up to 1,000 users) from phishing attacks. The OnPhish Learning Management System consists of numerous templates and interactive e-learning modules. Moreover, you will receive 12 editions of the EC-Council e-magazine CISO MAG for free.
Also of interest!
All our courses are delivered in-class, unless otherwise stated. Below is a selection of courses that may also be of interest to you:
In-company
With at least 5 participants, an in-house training could be your best choice. An in-company training, customized to the needs of your organization, has many advantages and:
- saves you and your colleagues time
- enables you to train in the comfort of your own working environment
- saves travel and accommodation expenses
- can be arranged at a date and time convenient for you
- sensitive issues can be discussed openly since no outsiders are present
Do you prefer an in-company training? Please contact us for more information. We are more than happy to discuss the various possibilities with you!
We have organized in-company trainings all around the globe, among others in the following countries: Aruba, Azerbaijan, Curaçao, Denmark, Finland, Germany, Great Britain, Greece, Luxembourg, Nigeria, Oman, Pakistan, Saudi Arabia, Suriname, Switzerland, Türkiye, Uganda.
Content
C/CISO (Certified Chief Information Security Officer) – program
DOMAIN I
Governance, Risk, Compliance
Governance
- Define, implement, manage, and maintain an information security governance program
- Align information security governance framework with organizational goals and governance
- Information security management structure
- Framework for information security governance monitoring
- Standards, procedures, directives, policies, regulations, and legal issues that affect the information security program.
- The enterprise information security compliance program
- Managing an enterprise information security compliance program
- Risk management program policy and charter
- Risk assessment methodology and framework
- Risk register
- Risk assessment schedule and checklists
- Risk reporting metrics and processes
Compliance
- Analyze and understand common external laws, regulations, standards, best practices and organizational ethics
- International security and risk standards (ISO 27000, ISO 31000)
- Implement and manage information security strategies, plans, policies, and procedures to reduce regulatory risk
- Information security changes, trends, and best practices
- Manage enterprise compliance program controls, information security compliance process and procedures, compliance auditing, and certification programs
- The information security compliance process and procedures
- Compile, analyze, and report compliance programs
- Compliance auditing and cortication programs
- Organizational ethics
DOMAIN II
Information Security Controls and Audit Management
Information Security Controls
- Identify the organization's operational process and objectives
- Design information systems controls in alignment with the operational process and objectives
- Identify and select the resources required to effectively implement and maintain information systems controls
- Design and implement information systems controls to mitigate risk
- Design and conduct testing of information security controls
- Design and implement processes to appropriately remediate deficiencies and evaluate problem management practices
- Assess and implement tools and techniques to automate information systems control processes
- Measure, manage, and report on security control implementation and effectiveness
Audit Management
- The IT audit process and IT audit standards
- Apply information systems audit principles, skills, and techniques
- Execute, interpret, and evaluate the audit process
- Formulate a practical and cost-effective plan to improve exposures
- Develop an IT audit documentation process and share reports with stakeholders for decision making
- Ensure that the necessary changes based on the audit findings are effectively and timely implemented
DOMAIN III
Security Program Management & Operations
Security Program Management
- Develop a clear project scope statement for each information systems project in alignment with organizational objectives
- Define activities needed to successfully execute the information systems program
- Develop, manage, and monitor the information systems program budget
- Identify, negotiate, acquire, and manage the resources needed for successfully designing and implementing the information systems program
- Acquire, develop, and manage the information security project team
- Assign clear information security personnel job functions and provide continuous training
Security Program Operations
- Resolve personnel and teamwork issues within time, cost, and quality constraints
- Identify, negotiate, and manage vendor agreement and community
- Participate with vendors and stakeholders to review/assess recommended solutions
- Evaluate the project management practices and controls
- Develop a plan to continuously measure the effectiveness of the information systems projects
- Identify stakeholders, manage stakeholders' expectations, and communicate effectively to report progress and performance
- Ensure that necessary changes and improvements to the information systems processes are implemented as required
DOMAIN IV
Information Security Core Competencies
- Access control
- Social engineering, phishing attacks, identity theft
- Physical security
- Disaster recovery and business continuity planning
- Firewall IDS/IPS and network defense systems
- Wireless security
- Virus, Trojans and malware, and other malicious code threats
- Secure coding best practices and security web applications
- OS hardening
- Encryption technologies
- Vulnerability assessment and penetration testing
- Threat management
- Incident response and computer forensics
DOMAIN V
Strategic planning, finance, procurement, and third-party management
- Strategic planning
- Finance
- Procurement
- Third-party management
Certificate
When you successfully pass the official EC-Council CCISO (C/CISO v4) exam, you will receive your personal certificate.
Trainer(s)
Your instructor is a very experienced EC-Council accredited and certified trainer.
Start date(s)
The C/CISO training consists of 5 days, in-class and remote/live-online (up to your choice). The C/CISO in-class training will be organized in Amsterdam (or surroundings) on the following dates:
- 29 June - 3 July 2026
- 28 September - 2 October 2026
- 30 November - 4 December 2026
Fee / Registration
The fee for the 5-day C/CISO training is € 4,980 (VAT excl.) per person. The fee includes all lunches, coffee/tea, the official EC-Council C/CISO study guide and the C/CISO or Associate C/CISO exam (value about € 1,000). Should you fail to pass the C/CISO exam the first time, you may re-attend the C/CISO training within a period of 1 year for free.