Cybersecurity Management

Where information security standards focus on the management system, this domain focuses on cybersecurity practice and the frameworks organizations are increasingly required to demonstrate against — the EU’s NIS 2 Directive, the NIST Cybersecurity Framework, SOC 2, CMMC, cloud security, network security, and industrial control system security. These are the credentials most often requested by customers performing security due diligence.

Courses

10

Standards

8

Languages

8

From

€390

Who this is for

  • Cybersecurity managers and heads of security operations
  • Organizations in scope of NIS 2 preparing to demonstrate compliance
  • Consultants advising on NIST CSF, SOC 2 or CMMC readiness
  • Engineers responsible for cloud, network or industrial system security

Standards in this category

CMMCCloud SecurityCybersecurityISO/IEC 27033NIS 2 DirectiveNIST CybersecuritySCADASOC 2

Credential levels available

FoundationLead AnalystLead Cybersecurity ManagerLead ImplementerLead ManagerLead SCADA Security Manager

Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →

Frequently asked questions

Who does the NIS 2 Directive apply to?

NIS 2 is EU legislation covering essential and important entities across sectors including energy, transport, banking, health, digital infrastructure, public administration, water, waste, food and manufacturing. It broadened the scope considerably compared with the original NIS Directive and introduced management accountability for cybersecurity risk.

How does the NIST Cybersecurity Framework compare with ISO/IEC 27001?

The NIST CSF is a voluntary framework organized around core functions and is widely used to assess and communicate cybersecurity posture, particularly in the United States. ISO/IEC 27001 is a certifiable international management system standard. They overlap substantially in substance and many organizations use both — NIST CSF for internal maturity assessment, ISO/IEC 27001 for external certification.

What does the SOC 2 Lead Analyst course cover?

SOC 2 is an attestation framework developed by the AICPA, built around the Trust Services Criteria. The course covers preparing for and supporting a SOC 2 engagement — the criteria themselves, evidence and control design, and the readiness work that precedes an audit. Note that SOC 2 reports are issued by licensed CPA firms.

Is there a course for industrial or operational technology security?

Yes. The SCADA security course addresses supervisory control and data acquisition systems and the wider operational technology environment, where availability and safety constraints make conventional IT security approaches unsuitable.

Do these courses require a technical background?

The Foundation levels do not — they are aimed at anyone needing a working command of the subject. The Lead Manager and Lead Implementer levels assume professional familiarity with security concepts and are pitched at practitioners.