Chief Information Security Officer (CISO) Certification
(Cyber Security Management Program)
In an era of sophisticated digital threats (especially from Agentic AI and quantum computing) and strict regulatory environments, cybersecurity is no longer just an IT issue – it is a core business imperative. This program bridges the gap between technical defense and executive leadership, equipping both technical managers and business leaders to design, govern, and scale enterprise-wide security programs.
Rather than focusing solely on isolated defensive tools, the curriculum emphasizes risk-based decision-making, aligning proactive threat mitigation with broader business objectives and compliance mandates.
This customized program (described below) bridges technical defense and executive leadership, preparing candidates to design, govern, and scale enterprise-wide security programs. Participants will learn to:
- Establish the foundations of information security (e.g., planning, policy, risk management, compliance, incident response)
- Apply ethical hacking, penetration testing, and computer forensic investigation techniques to identify and document vulnerabilities
- Develop incident response, disaster recovery, and business continuity plans, including virtualization-based recovery strategies
- Administer network security — access control, cryptography, wireless and mobile security, and vulnerability assessment
- Address emerging security domains, including AI (Agentic AI), security governance, Zero Trust, and quantum-safe cryptographic risk management
Select at least 4 courses from the following:
Information Technology Management or its equivalent.
1. Cyber Security Foundation; Program Pre-requisite
This 24-hour introduction to information security provides the foundation for understanding the planning and implementation of policies and procedures for protecting information assets, determining the levels of protection and response to security threats and incidents, and designing an appropriate information security system. It provides the foundation for all other courses in this certificate. Candidates will gain an overview of the field of information security and assurance, and will also learn the necessary knowledge to engage in information assurance activities and procedures. Coverage will include inspection and protection of information assets, detection of and reaction to threats to information assets, examination of pre- and post-incident procedures, technical and managerial responses, ransomware, and an overview of the information security planning and staffing functions. Instructors will also introduce the role of the Chief Information Security Management Officer (CISMO).
Candidates will also master risk management, security planning, and security policy enforcement and auditing activities. Candidates will learn about security guidelines, regulations, and legal implications, and standards that apply in information security management, as well as information confidentiality, data integrity, and system availability. The course also presents related concepts such as privacy and business continuity planning. While emphasis is placed on managerial and operational security controls, the course also provides an overview of the current and emerging technical security controls (including AI) applied to access control, operating systems, applications, networks/web, cryptographic solutions, intrusion detection systems, physical security, wireless security, VPNs, digital forensics, and related topics.
The primary objectives of the course are to:
- Understand the importance of information security in business continuity
- Critically analyze security threats and define appropriate technical and managerial controls for these threats
- Understand procedures for ensuring compliance with security policies and standards, and establish appropriate systems and plans for security implementation
- Identify legal implications of security and standards for security management
- Recognize the management, organizational, and sourcing considerations for having an effective information security program
- Describe audit and recovery approaches for coping with security breaches
- Provide the foundation Cyber Security knowledge required for the other courses in this certificate
This prerequisite course or its equivalent is required before taking any of the other courses in this Certificate.
2. Ethical Hacking
This 40-hour course offers a comprehensive guide for ethical hacking. An ethical hacker is defined as someone who uses the same methods as criminal attackers use to exploit vulnerabilities in a network accessible to them. The difference is that an ethical hacker performs these “attacks” to document whether a network can be breached by known vulnerabilities in order to mitigate the attack vector they expose.
Topics covered include:
- Introduction to Ethical Hacking
- Footprinting and Reconnaissance
- Impact of AI (Agentic AI)
- Scanning Networks
- Enumeration
- System Hacking
- Trojans and Backdoors
- Viruses and Worms
- Sniffers
- Social Engineering
- Denial of Service
- Session Hijacking
- Hacking Webservers
- Hacking Web Applications
- Ransomware
- SQL Injection
- Hacking Wireless Networks
- Evading IDS, Firewalls, and Honeypots
- Buffer Overflow
- Cryptography
- Penetration Testing
Upon successful completion of this course, candidates will be prepared to pass the Certified Ethical Hacker exam.
3. Computer Hacking Forensic Investigation
This 40-hour course presents a detailed and methodological approach to computer forensics and evidence analysis. This will enable candidates to understand the often complex issues associated with investigating cybercrimes, handling digital evidence, detection methods, and proof in a variety of digital forensic contexts, including computers, networks, and portable digital devices. Each module will build upon the knowledge gained from previous modules. This course will introduce cutting-edge technologies and methodologies, alongside fundamental building blocks, allowing candidates to simultaneously understand the theory and practical aspects in dealing with digital investigations.
The primary topics covered in the course are intended to prepare candidates to:
- Understand the function and limitations of forensic investigations.
- Understand procedures used in conducting forensic investigations.
- Guide first responders towards successful data acquisition and preservation.
- Describe digital forensics and relate it to an investigative process.
- Explain the legal issues of preparing for and performing digital forensic analysis based on the investigator’s position and duty.
- Considerations for leveraging and protecting against AI.
- Be aware of (digital) evidence storage preparation and requirements.
- Perform basic digital forensic investigations.
- Demonstrate use of digital forensics tools and their underlying principles.
- Size and set up a digital forensic lab.
- Conduct simple binary analysis on files with unknown and possibly malicious functionality.
- Recognize the state of the practice and the gaps in technology, policy, and legal issues.
4. Security Analysis and Penetration Testing
This 40-hour course provides an in-depth understanding of how to effectively protect computers and computer networks. Candidates will learn the tools and penetration testing methodologies used by penetration testers. In addition, the course provides a thorough discussion of what and who a penetration tester is and how important they are in protecting corporate and government data from cyber-attacks. Candidates will learn updated computer security resources that describe new vulnerabilities and innovative methods to protect networks. Also covered is a thorough update of federal and state computer crime laws, as well as changes in penalties for illegal computer hacking.
The primary objectives of the course are to ensure candidates understand how:
- computer systems are attacked, ransomed, and how to defend against those attacks.
- to analyze legal questions, ethical dilemmas, and privacy issues related to computer security.
- to use their knowledge of computer security to analyze and suggest means of securing information systems.
- to use their knowledge of computer forensics technology and laws relevant to computer-based crime to analyze various technical challenges, scenarios, and cases regarding computer crime.
5. Security Programming
The purpose of this 30-hour course (including either the .Net or Java course) is to provide candidates with a comprehensive understanding of what a Secure Development Process is. The candidates will learn secure programming concepts and techniques; learn how to identify key characteristics of secure code; learn how to use design patterns for secure code; learn how to build in a secure requirements process in the software life cycle from the beginning to the end; and learn how to write, test, and debug programs using secure programming techniques. Topics will include design principles, code snippets, and a simple explanation of each step as you work your way through the course.
The primary objectives of the course are to:
- Identify what secure programming is and why it is needed
- Work with principles associated with software engineering
- Understand principles of security and quality in the industry and how to use them
- Understand the Application Guide
- Learn how to understand, analyze, and interpret software requirements
- AI’s impact on security
- Design for quality using industry frameworks
- Know what industry design patterns are and how to carry them out
- Understand industry-standard development tools
- Know how to produce secure code
- Sustain a formal development process
Security Considerations for Programming Language Courses (select 1 of the following 2 courses to be included with the Security Programming course):
- .Net
- Java
6. Incident Response Handling, Disaster Recovery, & Cyber Resilience
This intensive 24-hour executive course examines the end-to-end framework of enterprise contingency planning, threat containment, and operational resilience. Designed for CISOs and security management leaders, this course bridges the gap between technical threat handling and strategic business continuity. Participants will evaluate how to design, test, and execute robust Incident Response (IR), Disaster Recovery (DR), and Business Continuity (BC) programs capable of navigating modern threat vectors—including double/triple-extortion ransomware, cloud-native outages, supply chain compromises, and critical infrastructure disruption.
Emphasizing Cyber Resilience, the course prepares leaders to build dynamic Computer Security Incident Response Teams (CSIRTs), minimize mean time to detect and respond (MTTD/MTTR), ensure regulatory reporting compliance, and maintain core business operations during high-impact crisis events.
Key Focus Areas & Topics
Enterprise Risk Management & Cyber Resilience: Aligning IR/DR/BC strategies with organizational risk appetite, business impact analysis (BIA), and continuous operational availability.
Planning for Organizational Readiness: Designing adaptive contingency strategies, policy frameworks, and multi-cloud resilience models.
Modern CSIRT & Security Operations: Building, organizing, and empowering high-performing Incident Response Teams, SOCs, and third-party forensics partners.
Detection, Triage, & AI-Augmented Analytics: Leveraging XDR, SOAR, and AI threat intelligence for rapid incident detection and decision-making.
Incident Response & Ransomware Containment: Playbook execution for complex threats, including double-extortion ransomware, identity hijacking, and cloud tenant breaches.
Data Recovery & System Restoration: Immutable backups, air-gapped storage architectures, automated failover, and cloud-native disaster recovery models.
Business Continuity Execution: Maintaining mission-critical business processes, alternate operating modes, and supply chain continuity during major disruptions.
Crisis Management & Executive Leadership: C-Suite communication, PR/media alignment, legal disclosure mandates (e.g., SEC rules), and international standards (ISO 22301, ISO 27035).
7. Disaster Recovery and Virtualization Planning
This 40-hour course provides an understanding of the various methods for identifying business and technology vulnerabilities. In addition, this course outlines the appropriate countermeasures to mitigate risks and prevent failure. This course is designed to develop a solid foundation in various disaster recovery and business continuity principles, including the assessment of risks, the preparation of a disaster recovery plan, the development of policies and procedures, and an understanding of the roles and relationships within an organization that is recovering from a disaster and the implementation of a plan.
As an important part of a flexible and highly efficient disaster recovery plan, this course addresses the use of virtualization techniques that will assist in the development of an enterprise approach for disaster recovery and business continuity. An introduction to these techniques will be covered, as well as the importance of securing the virtual environments.
The approach used in this course is enterprise-wide and provides the methods for developing a quality and efficient disaster recovery and business continuity plan, including the creation and management of a secure network environment, establishing procedures and policies, and how to restore that network in the unfortunate event of a disaster.
The primary objectives of the course are:
- Understanding the importance of disaster recovery in the enterprise.
- Understanding how to create an enterprise disaster plan.
- Identifying strategies to develop a secure network.
- Understanding the importance of Policy and Procedure.
- Exploring virtualization technologies.
- Understanding the use of traditional and virtual technologies in disaster planning.
8. Network Security Administration & Zero Trust Architecture
Designed for security executives and senior technical leaders in the CISO Certification program, this comprehensive 40-hour course delivers an executive and operational guide to enterprise network security management. As traditional network perimeters dissolve into distributed multi-cloud and hybrid work ecosystems, security leaders must evolve beyond legacy firewalls to implement identity-first Zero Trust Architecture (ZTA), Secure Access Service Edge (SASE), and AI-augmented threat detection.
Participants will master the strategic, legal, and operational frameworks necessary to defend complex enterprise networks against modern attack vectors—ranging from AI-driven social engineering and deepfakes to ransomware campaigns, API exploits, and supply chain intrusions.
Key Focus Areas & Topics
Foundations of Modern Network Architecture: Perimeterless Security, Zero Trust Architecture (ZTA), SASE, & SD-WAN Security Design
AI & Adversarial Threat Landscapes: AI-Driven Malware, Automated Phishing, Deepfake Social Engineering, & Securing AI Agent Pipelines
Advanced Access Control & Identity: Phishing-Resistant MFA, Identity-Driven Microsegmentation, & Dynamic Risk-Based Authorization
Data Protection & Cryptography: Modern Public-Key Infrastructure (PKI), Post-Quantum Cryptography Readiness, Data Loss Prevention (DLP), & Privacy Compliance
Host, Cloud, & Application Security: API Security, Securing Cloud-Native Infrastructure, & Software Supply Chain Protection
Threat Exposure & Vulnerability Management: Continuous Threat Exposure Management (CTEM), Automated Penetration Testing, & XDR/SIEM/SOAR Orchestration
Ransomware Defense & Incident Response: Containment Strategies, Air-Gapped Disaster Recovery, & Business Continuity Alignment
Wireless, Mobile, & Edge Protection: Securing Remote Telemetry, IoT/OT Network Segregation, & Mobile Device Management (MDM)
Governance, Ethics, & Regulatory Compliance: SEC Cybersecurity Disclosure Mandates, Legal Liabilities, & Organizational Risk Mitigation
9. Managing Emerging Information Technology
This course provides a strategic blueprint for evaluating, integrating, and scaling disruptive technologies across the modern enterprise. Positioning participants in the joint roles of the CIO, CTO, CISO, and CDO, this course focuses on building an agile, secure, and future-ready technology foundation capable of driving rapid AI innovation. Participants will examine how to orchestrate a modern ecosystem—spanning Generative and Agentic AI, edge analytics, IoT, cognitive computing, and next-generation mobile technologies—while navigating complex architecture, integration, and compliance challenges.
Central to this course is establishing enterprise-wide Multi-Cloud Governance to optimize costs and deployment strategies across hybrid environments, alongside enforcing a robust Zero Trust security framework to safeguard data, APIs, and AI workloads against modern threat vectors.
Key Focus Areas & Topics
Enterprise AI Infrastructure & Readiness: Preparing data pipelines, compute resources, and architectures for Generative, Agentic, and Cognitive AI initiatives.
Multi-Cloud Governance & Architecture: Orchestrating hybrid/multi-cloud environments, cloud FinOps, vendor management, and workload optimization.
Zero Trust Security & Modern Privacy Frameworks: Enforcing identity-centric access controls, microsegmentation, continuous verification, and regulatory compliance across distributed environments.
Emerging Edge & IoT Telemetry: Integrating IoT devices, mobile ecosystems, ambient intelligence, and real-time edge computing into core enterprise architectures.
Technology Standards & Integration Frameworks: Managing API ecosystems, interoperability standards, and legacy modernization to enable seamless technology adoption.
Strategic Executive Alignment: Unifying C-suite vision (CIO/CTO/CISO/CDO) to balance rapid technological innovation with enterprise risk, governance, and business ROI.
10. Managing IT Resources
This course takes a comprehensive resource-management perspective on business strategy, governance, demonstrating value, IT processes, organizational structure, sourcing, and managing emerging technologies. It puts you in the role of an IT leader building a strategy that’s genuinely enabled by IT, preparing you to keep IT relevant as business, economic, and technology conditions keep shifting.
11. AI Security: From Backroom Detail to Boardroom Imperative
Artificial Intelligence has introduced unprecedented complexity to the cybersecurity landscape. Today, securing AI systems is no longer just an operational detail managed in the back office—it is a critical boardroom imperative. While ethical design principles provide a foundation, live AI deployments require real-time runtime protection to defend against active threats and safeguard organizational trust.
This executive-level course equips leaders and security professionals with the frameworks required to govern, protect, and oversee enterprise AI architectures effectively.
Key Learning Topics
Part 1: Strategic Governance & Executive Ownership
Boardroom Accountability: Elevating AI security to executive leadership and managing the reputational and regulatory risks of AI-related breaches.
Cross-Functional Governance: Structuring shared ownership between the Chief AI Officer (CAIO) and Chief Information Security Officer (CISO), backed by IT, Legal, and Data Governance teams.
Managing Shadow AI: Mitigating the risks associated with unauthorized tool adoption and unvetted third-party integrations across the enterprise.
Part 2: Threat Landscape & Defense Frameworks
Adversarial Risks & Guardrail Bypass: Countering emerging vulnerabilities such as “policy puppetry,” prompt injection, and model manipulation.
Runtime Protection & Live Defense: Enforcing real-time controls to safeguard active models in production.
Model Privilege Boundaries: Implementing frameworks like MLDR (Machine Learning Detection and Response) and CaMeL (Context-Aware / Causal Model Lineage) alongside industry standards like NIST AI RMF and OWASP Top 10 for LLMs.
Optional Programs & Courses to Choose From
CISSP Certification Preparation
This 8-hour course, after taking the respective GIIM asynchronous or face-to-face courses, prepares candidates to pass the CISSP certification examination
Hence, students have the option of getting a GIIM Certificate, ICCP Certification, Master’s Degree, and/or CISSP certification.
This CISSP Preparation Course is not included towards the GIIM Certificate
CAATS Certification Preparation
AI and machine learning are providing significant contributions to the efficiency and effectiveness of auditing (e.g., security, accounting, finance). This course, for both IT and auditing professionals, focuses on the application of AI to the essential practices employed by auditors to identify irregularities. Leveraging these AI auditing tools is enhancing the forensic analysis procedures used throughout every business and industry. Working with these tools enables auditors to select and analyze the right data to identify abnormalities. This course will prepare candidates on using Computer Aided Audit Tools (CAATs) such as ACL Robotics, Machine Learning, and Python to automate the auditing process. To visualize the results, visualization tools such as Tableau will also be covered.
Additional Optional / Elective Courses
A. Architecting IT Security Infrastructure & Enterprise Resilience
This course delivers a strategic, architecture-first approach to designing, analyzing, and managing complex information security infrastructure across enterprise environments. Designed for security executives and senior architects, this course addresses security across three interconnected domains: organizational governance, operational processes, and technology architectures (data, multi-cloud, applications, network, identity, and hybrid edge).
Participants will explore how to align business requirements, technical capabilities, and dynamic cyber risk profiles to build adaptive, self-healing security architectures. Grounded in modern management research, IT strategic planning, and modern distributed systems, this course equips CISOs and security leaders to evaluate defense-in-depth frameworks, make risk-informed technology choices, and continuously govern the enterprise security posture.
Key Focus Areas & Topics
Zero Trust Architecture & Enterprise Design: Modern Perimeterless Infrastructure, Identity-Centric Segmentation, Microsegmentation, & SASE Integration
Cloud-Native & Application Security: Cloud Security Posture Management (CSPM/CNAPP), API Gateway Defense, Securing DevSecOps Pipelines, & Container/Kubernetes Security
Modern Cryptography & Identity Management: Public Key Infrastructure (PKI), Asymmetric/Symmetric Cryptography (AES-256, RSA, ECC), Post-Quantum Cryptography Readiness, & Zero-Trust Access Control
Threat Exposure & Intrusion Defense: Next-Gen Firewalls (NGFW), XDR/SIEM/SOAR Orchestration, Automated Threat Hunting, & DDoS Mitigation Strategies
Critical Infrastructure & OT/SCADA Resilience: Securing Industrial Control Systems (ICS/SCADA), Converged IT/OT Architecture, & Cyber-Physical Risk Mitigation
Data & Communication Protection: Secure Protocols (TLS 1.3, IPsec, SSH), Data Loss Prevention (DLP), Modern Endpoint Detection, & Anti-Ransomware Frameworks
Security Administration & Policy Governance: Continuous Compliance Automation, Risk-Based Security Frameworks (NIST CSF, ISO 27001), & Executive IT-Security Alignment
B. Business Continuity and Disaster Recovery Planning
Recent natural, environmental, and “man-made” events have increased the need for organizations to develop strategies for mitigating, preparing for, responding to, and recovering from small and large scale emergencies (e.g., hurricanes, tsunamis, earthquakes, terrorism, unethical acts). In the context of a highly integrated global economy, nearly every business is likely to feel the effects of emergencies around the world, and in the face of intense competition, it is crucial that all businesses have a plan for continuing operations before, during, and after emergencies of all types.
This course presents the important considerations for business continuity and disaster recovery planning. It includes a comprehensive advanced business continuity planning and management workshop which is designed to teach practical methods to develop, test, and maintain a business continuity plan. This course is based on industry best practices and guidelines for business continuity, disaster recovery, and emergency management.
C. Legal, Ethical, and Compliance Concerns
The purpose of this course is to provide an overview of the security initiatives (legal, ethical, and compliance) required by the existing and emerging computing environment while evaluating the controls in place or planned for meeting those requirements. This course examines every major aspect of the relationship between information security and the law at a level suitable for information security specialists and senior managers who supervise information security operations.
The course focuses on the substantive legal principles relating to information security with regard to both industry and government perspectives. It explores information security considerations as the repository of information that may be at issue in legal proceedings. In the United States, the government requires that all federal systems have a customized security plan. In addition, the National Training Standard for Information Systems Security (INFOSEC) Professionals requires programs that meet this standard to produce security professionals capable of developing and supporting a security plan.
This course provides an introduction to security planning as recommended by NIST guidelines for developing security plans. Candidates are required to conduct a case study in which a security plan is developed for their organization.
D. Information Risk Management Game (optional)
This 1-day business simulation focuses on deriving an information risk management strategy to protect against predators like Oceans99! The story is about a large exhibition in the Tokyo Museum. An important Bank is sponsoring this challenging event. During the preparation of this exhibition, there is a rumor that Oceans99 has made plans to steal the precious objects. We don’t know how Oceans99 wants to do this, but the challenge for the team is to analyze possible risks, protect against threats, and to make the exhibition a success. Participants are part of the international team that will transport the objects from Amsterdam, London, and Las Vegas to the local airports, then fly the objects to Tokyo and transport them to the Tokyo museum, where the objects will be exhibited for 4 months. During the preparation, the team will develop an information security strategy/policy. This document will define the objectives, the risks/threats, the measures, and activities to manage the protection of the objects against theft. The plans will be implemented and maintained to maintain the assurance levels. Would Oceans99 be able to execute their plans?
E. Quantum-Safe Cybersecurity; Cryptographic Risk Management for the Quantum Computing Era
Public-key cryptography is the foundation of our digital economy. It authenticates web sessions, signs critical firmware, secures cloud identity, and protects payment systems. A cryptographically relevant quantum computer (CRQC) will not just weaken this foundation; it will break it entirely by solving RSA, Diffie-Hellman, and elliptic-curve cryptography using Shor’s algorithm.
Because adversaries are already intercepting and storing encrypted data to decrypt later (“harvest now, decrypt later”), this risk is active today for any data that must remain confidential for years to come.
With NIST’s post-quantum standards (FIPS 203, 204, and 205) finalized and vendors deploying early implementations, transition planning is no longer a future research project. It is an immediate operational and fiduciary duty. This course approaches the transition not as a theoretical physics problem, but as a practical exercise in cryptographic risk management under a defined timeline.
What You Will Learn
Cryptographic Asset Discovery: How to inventory and map where vulnerable public-key algorithms live across your enterprise.
Risk Modeling & Prioritization: How to evaluate the real-world threat window against your data’s confidentiality lifespan.
Post-Quantum Cryptography (PQC) Migration: Strategies to transition systems to the new NIST standards (ML-KEM, ML-DSA, and SLH-DSA) without disrupting current operations.
Hybrid Implementation: Deploying dual-mode classic and post-quantum keys to maintain compliance while testing quantum resistance.
Who This Course Is For: This is a graduate-level, decision-oriented course designed for advanced undergraduates, master’s students, and senior technical and business leaders who need to act now. We balance technical depth with executive strategy: every technical concept is paired with a business risk framework, and every strategic decision is grounded in technical reality.
Prerequisites: While we welcome business and technology leaders, you should be comfortable with critical reading of technical standards, basic risk modeling, and fundamental IT infrastructure concepts.
As organizations accelerate digital transformation, leveraging emerging technologies for competitive advantage requires proactive, robust cybersecurity leadership. Securing enterprise assets is no longer just a technical function—it is a core business imperative that demands seamless alignment between C-suite leaders, technical officers, and operational executives.
This program equips business and technology leaders with the strategic frameworks, governance models, and decision-making tools necessary to protect organizational assets, manage emerging AI-era threats, and build a cyber-resilient enterprise.
Format: Live / Synchronous (Online or In-Person)
Duration: 20 Contact Hours (Flexible delivery, typically ten 2-hour executive sessions)
Target Audience: C-Suite Executives (CEO, COO, CIO, CTO, CISO, CFO), Vice Presidents, Senior Directors, and Management Leaders
Core Focus Areas
Strategic Business Alignment: Align cybersecurity strategy directly with enterprise goals to protect core value drivers and foster cross-functional harmony across business units.
Governance & Decision Rights: Design modern organizational structures, vendor sourcing models, clear accountability frameworks, and cloud/IT-OT governance strategies.
AI (Agentic AI) & Next-Gen Threat Management: Evaluate the impact of artificial intelligence, automated attack vectors, and emerging technologies on defense capabilities, threat exposure, and enterprise risk.
Threat Mitigation, Zero Trust, & Managerial Controls: Analyze modern cyber threats to implement effective managerial, operational, and technical controls—anchored by an identity-first Zero Trust architecture across all enterprise endpoints, data layers, and environments.
Business Continuity & Operational Resilience: Integrate information security seamlessly into enterprise continuity, disaster recovery, supply chain management, and risk-management planning.
Crisis Management & Recovery: Master audit frameworks, executive crisis communications, and incident response approaches to effectively mitigate, contain, and recover from security breaches.
Legal, Ethical, & Regulatory Compliance: Navigate evolving security standards, SEC disclosure mandates, privacy regulations, and legal implications across industries.