EC-Council’s Certified Chief Information Security Officer

The CCISO Certification is an industry-leading program that recognizes the real-world experience necessary to succeed at the highest executive levels of information security.

EC-Council’s CCISO Program has certified leading information security professionals around the world. A core group of high-level information security executives, the CCISO Advisory Board, contributed by forming the foundation of the program and outlining the content that would be covered by the exam, body of knowledge, and training. Some members of the Board contributed as authors, others as exam writers, others as quality assurance checks, and still others as trainers. Each segment of the program was developed with the aspiring CISO in mind and looks to transfer the knowledge of seasoned professionals to the next generation in the areas that are most critical in the development and maintenance of a successful information security program.

The CCISO program is the first of its kind training and certification program aimed at producing top-level information security executives. The CCISO does not focus solely on technical knowledge but on the application of information security management principles from an executive management point of view. The program was developed by sitting CISOs for current and aspiring CISOs.

In order to sit for the CCISO exam and earn the certification, candidates must meet the basic CCISO requirements. Candidates who do not have 5 years of experience in 3 of the C|CISO domains for the C|CISO training but have 2 years of experience in at least 1 domain (or who currently hold either the CISSP, CISM or CISA certifications) are qualified for the Associate C|CISO program.

What is the role of a certified Chief Information Security Officer(CISO)?

The CISO position emerged worldwide as a designation of executive leaders who can address the emerging threats to information security by developing and maintaining a tough information security strategy. CISOs – with the experience, leadership, communication skills and innovative strengths are born to resolve the ever-growing information security threats. The CISO of tomorrow will play a vital role in creating effective and efficient processes and will lead a team of technically skilled professionals to defend the core interests of their organization.

Become a Chief Information Security Officer

Today’s world is one of constant and instant information exchange. Organizations, be it private businesses or government bodies, rely on sophisticated computer databases and networks to share digital information on a daily basis with their subsidiaries, branches, partners, clients, employees, and other stakeholders. However, years of information security incidences and the onslaught of the recent cyber-attacks prove that digital data can be easily compromised. Organizations therefore, are increasingly in need of a new set of skills and processes to ensure the security of information at a scale that will be required tomorrow.

If your aspiration is to have the highest regarded title within the information security profession – CISO, if you already have earned the role of a CISO, or if you are currently playing the role of a CISO in your organization without the official title, the CISO designation is the recognition of your knowledge and achievements that will award you with professional acknowledgement and propel your career.

Achieving the CCISO Certification will differentiate you from others in the competitive ranks of senior Information Security Professionals. CCISO will provide your employers with the assurance that as a CCISO executive leader, you possess the proven knowledge and experience to plan and oversee Information Security for the entire corporation.

Certification Target Audience

CCISOs are certified in the knowledge of and experience in the following CISO Domains:

  • Governance, Risk, Compliance, and Audit Management
  • Organizational Executive Leadership
  • Information Security Controls, Security Program Management & Operations
  • Information Security Core Competencies
  • Strategic Planning, Finance, Procurement, and Third-Party Management

Clause: Age Requirements and Policies Concerning Minors

Minors are not permitted to take the EC-Council exam without a written consent/indemnity letter signed by their parent or legal guardian, along with a supporting letter from their institution of learning. Only candidates from a nationally accredited institution of learning shall be considered.

Minor/Adult legal ages are defined by the country of residence/origin for the candidate. For further clarification or to submit a letter of consent, please contact certmanager@eccouncil.org. EC-Council reserves the right to revoke the certification status of candidates in case of non-compliance with this policy.

Disclaimer:

  • EC-Council reserves the right to impose additional restriction to comply with the policy.
  • EC-Council reserves the right to modify certification policies without notice.
  • EC-Council reserves the right to revoke the certification of any person determined to be in breach of this policy.

CCISO Exam Details

CCISO Exam Details
Duration 2.5 Hours
Questions 150

 Hand Book Blue Print

For more information, please click here.

Passing Criteria:

In order to maintain the high integrity of our certification exams, EC-Council Exams are provided in multiple forms (i.e., different question banks). Each form is carefully analyzed through beta testing with an appropriate sample group under the purview of a committee of subject matter experts that ensure that each of our exams not only have academic rigor but also have “real world” applicability. We also have a process to determine the difficulty rating of each question. The individual rating then contributes to an overall “Cut Score” for each exam form. To ensure each form has equal assessment standards, cut scores are set on a “per exam form” basis. Depending on which exam form is challenged, cut scores can range from 60% to 85%.

FAQs

The Certified Chief Information Security Officer program is the first of its kind certification that recognizes an individual’s accumulated skills in developing and executing an information security management strategy in alignment with organizational goals. C|CISO equips information security leaders with the most effective toolset to defend organizations from cyber-attacks. To rise to the role of the CISO, strong technical knowledge, and experience is more imperative now than ever before but it must be accompanied by the ability to communicate in business value. C|CISOs understand that their information security decisions often have a direct impact on their organization’s operational cost, efficiency, and agility. As organizations introduce new technologies, C|CISOs will develop and communicate a strategy to avoid the potential risks stemming from their implementation to the organization’s operations.

In order to qualify to take the CCISO Exam, applicants must fill out the CCISO Exam Eligibility Application found here. Applications, questions about the application process, and inquiries regarding where an application is in the process should be sent to cciso@eccouncil.org for US applicants, ccisoapp@eccouncil.org for International applicants. If the applicant is attempting the exam without taking EC-Council Authorized Training, five years of experience in each of the five CCISO Domains is required (experience can be overlapping) and a $100 application fee is due with the application. If an applicant has purchased EC-Council Authorized Training, there is no application fee due and only five years of experience in three of the five domains is required. For more information, please see https://ciso.eccouncil.org/cciso-certification/.

Application processing time varies due to the fact that part of the process involves reaching out to verifiers indicated by the applicants as able to verify their experience. In order to speed up this process, applicants can assist the application processing team by reaching out to their verifiers to ensure they have received the required forms from EC-Council and understand what is required. Applications from students in EC-Council Authorized Training are prioritized and expedited in order to ensure testing can occur at the time of the class if the student desires.

The five CCISO Domains are:
  • Domain 1 – Governance, Risk, Compliance, and Audit Management
  • Domain 2 – Organizational Executive Leadership
  • Domain 3 – Information Security Controls, Security Program Management & Operations
  • Domain 4 – Information Security Core Competencies
  • Domain 5 – Strategic Planning, Finance, Procurement, and Third-Party Management
No! In most high-level information security management jobs, each of the 5 CCISO Domains is part of each day. The five years can and usually do overlap.

No! If you do not meet the minimum requirements for the CCISO Exam, that doesn’t mean you can’t take training. Anyone can take the CCISO course, but only those who qualify to take the CCISO Exam will be issued an exam voucher. Students who do not have the years required can take the Associate C|CISO exam after CCISO training.

The Associate C|CISO program covers a broad range of essential topics needed to successfully lead information security management functions. With a comprehensive curriculum, including in-depth knowledge of the essential infosec domains, the Associate C|CISO program helps security executive aspirants grow advanced skills by bridging the gap between their current capabilities to leadership competence and knowledge. The Associate C|CISO program enables candidates to leverage the C|CISO knowledge by training through C|CISO courseware, equipping them with a robust understanding of information security management systems and leadership skills.

CCISO training is available at:
To obtain full C|CISO status, candidates must meet the experience requirements by having a minimum of 5 years of experience in at least 3 of the 5 domains. – The required experience must be earned while the candidate remains current with the Associate C|CISO credential (Continuing Education fees and professional education credits). – After gaining the required experience, Associate C|CISO certification holders will have their experience verified with EC council before being approved to take the C|CISO exam. – Training prior to taking the C|CISO exam is optional, as the Associate C|CISO already completed the training earlier. If a long period of time has elapsed since taking the training, we advised candidates to retake the training to understand current C|CISO program materials. – If the candidate’s Associate C|CISO certification has lapsed, they must reapply for the C|CISO program and follow the standard C|CISO application process from the beginning.

C|CISO is the right choice for you and your career if you:

  • Aspire to attain the highest regarded title within the information security profession – CISO.
  • Already serve as an official CISO
  • Or perform CISO functions in their organization without the official title.

C|CISO is the right choice for you and your career if you:

  • Aspire to attain the highest regarded title within the information security profession – CISO.
  • Already serve as an official CISO
  • Or perform CISO functions in their organization without the official title.

Application processing time varies due to the fact that part of the process involves reaching out to verifiers indicated by the applicants as able to verify their experience. In order to speed up this process, applicants can assist the application processing team by reaching out to their verifiers to ensure they have received the required forms from EC-Council and understand what is required. Applications from students in EC-Council Authorized Training are prioritized and expedited in order to ensure testing can occur at the time of the class if the student desires.

To renew your certification, you must satisfy the Continuing Professional Education requirements and remit a Continuing Education fee of $100.00 (USD).

We would love to help! Contact us at cciso@eccouncil.org

TOP