Course Outline
1. Introduction to the CISO Role and Organizational Context
- Understanding the strategic importance of the CISO position
- Roles, responsibilities, and leadership expectations
- Information security governance within corporate strategy
2. Governance, Risk, and Compliance (GRC)
- Developing information security governance frameworks
- Aligning policies with ISO/IEC 27001, COBIT, and NIST standards
- Regulatory compliance and audit readiness
3. Information Security Risk Management
- Risk identification, analysis, and mitigation techniques
- Risk management methodologies and frameworks
- Integrating risk management into corporate decision-making
4. Security Program Development and Management
- Designing and implementing enterprise security strategies
- Developing security policies, standards, and procedures
- Metrics, reporting, and continuous improvement
5. Information Security Controls and Technologies
- Overview of modern security technologies and architectures
- Data protection, identity management, and cloud security
- Defense-in-depth and zero-trust principles
6. Incident Management, Business Continuity, and Disaster Recovery
- Developing and implementing incident response plans
- Business continuity planning and recovery strategies
- Lessons learned and post-incident review processes
7. Leadership, Communication, and Strategic Alignment
- Building a security-aware culture across the organization
- Communicating risk and strategy to executive leadership and the board
- Managing cross-functional teams and vendor relationships
8. PECB Certification Exam Preparation
- Exam structure, format, and key topic review
- Sample questions and mock exam
- Certification process and maintenance requirements
Summary and Next Steps
- Review of key leadership and governance competencies
- Guidance on maintaining certification and continuing professional development
- Resources for further specialization in cybersecurity leadership
Requirements
- Knowledge of information security concepts and frameworks
- Experience in information security or IT governance roles
- Familiarity with ISO/IEC 27001 or related standards is recommended
Audience
- Information Security Managers and Senior IT Professionals
- Risk and Compliance Officers
- IT Directors and Consultants
- Professionals aspiring to become Chief Information Security Officers (CISOs)
Testimonials (4)
Theory followed by practical examples and exercices. Job well done!
Vincenzo Delle Donne - Department of National Defence
Course - ISO 37301 Compliance Management System
the expertise & knowledge of the trainer
Erica DeRosa DeRosa - Aecon Group INc.
Course - ISO 37001 Anti-Bribery Management System
I enjoyed the quizzes, and Driton's style of teaching.
Chloe - SEEC MM Ltd.,
Course - ISO 9001 Lead Implementer
With both my 2022 ISO 9001 audit prep-related training & the recently completed ISO 9001 audit prep refresher course; Dereck has helped me significantly with regards to gaining a new & practical perspective of the ISO 9001:2015 clauses & sections & how they apply to our business. Dereck has also helped me with both training courses --- to improve my ISO-related communications both with our company's employees and the external ISO Auditors .