Cybersecurity Governance for Chief Information Security Officers Training Course
| Course code | SD-EM-033 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Executive Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Chief Information Security Officers are expected to translate a changing threat landscape, regulatory exposure and technology risk into decisions that boards and executive teams can act on. That requires more than a security strategy or a risk register: it requires defensible governance, clear accountabilities, measurable risk appetite, credible reporting and investment cases that connect cyber controls to business outcomes. This course addresses the practical challenge of establishing security governance that can withstand board scrutiny, regulatory examination, major incidents and competing transformation priorities.
Participants learn to design and operate a cybersecurity governance model aligned to enterprise strategy. The course covers board reporting, risk appetite statements, three-lines-of-defence operating models, policy architecture, control ownership, security portfolio governance, third-party oversight, regulatory mapping and executive incident decision-making. Participants practise using NIST CSF 2.0, ISO/IEC 27001:2022 and FAIR concepts to prioritise risks, quantify exposure where appropriate, assign accountable owners and build performance indicators that distinguish control activity from risk reduction.
Teaching combines instructor-led executive briefings with CISO-level case work, governance design workshops and peer challenge sessions. Working from a realistic multinational business scenario, participants develop a Cybersecurity Governance Charter and board-ready governance pack containing a decision-rights model, risk appetite measures, committee structure, reporting dashboard, policy hierarchy and 90-day implementation roadmap. The deliverable can be adapted directly to the participant's organisation after the course.
The programme is designed for experienced security leaders who already manage security functions, major risk domains or enterprise technology services and need to influence at board, executive committee and business-unit level. It is equally valuable to newly appointed CISOs establishing their operating model and established CISOs seeking to strengthen assurance, accountability and investment governance.
Course objectives
By the end of this course, participants will be able to:
- Design a cybersecurity governance operating model using decision rights, committee charters and accountable control ownership
- Draft a board-approved cyber risk appetite statement with measurable thresholds, escalation triggers and treatment boundaries
- Map NIST CSF 2.0 and ISO/IEC 27001:2022 requirements into a practical policy and control governance architecture
- Build a board cybersecurity dashboard using key risk indicators, key performance indicators and risk trend narratives
- Apply FAIR concepts to frame loss exposure and prioritise material cyber risk investment decisions
- Establish third-party cyber governance processes covering tiering, contractual controls, assurance evidence and exception approvals
- Lead executive-level incident governance through predefined decision authorities, crisis communications and post-incident accountability
- Produce a 90-day cybersecurity governance implementation roadmap with milestones, owners, dependencies and success measures
Benefits of attending
For you
- Gain a repeatable structure for presenting cyber risk and investment choices to boards and executive committees
- Build credibility as a business-oriented CISO who links security decisions to financial, operational and regulatory exposure
- Develop a governance charter and reporting pack that can accelerate a new CISO mandate or operating-model reset
- Strengthen the ability to challenge control owners, technology leaders and suppliers using clear decision rights and evidence
- Prepare for senior security leadership roles requiring accountability for enterprise risk, resilience and regulatory assurance
For your organisation
- Establish clearer accountability for cyber risk acceptance, control ownership and exception approvals across business and technology teams
- Improve board decision-making through concise reporting that shows material risk, treatment progress and investment trade-offs
- Reduce governance gaps by aligning policy, risk, assurance and incident escalation processes to recognised standards
- Prioritise security spending against material loss exposure rather than relying on tool-driven or compliance-only justifications
- Create an actionable 90-day roadmap for strengthening governance without waiting for a major incident or regulatory finding
Target competencies
Who should attend
- Chief Information Security Officers — who must establish board-confidence governance and defend cyber investment decisions
- Deputy and aspiring CISOs — who are preparing to assume enterprise-wide security leadership responsibilities
- Heads of Cybersecurity and Security Operations — who need to connect operational controls to executive risk oversight
- Directors of Information Security Risk and Compliance — who design assurance, policy and regulatory accountability structures
- Chief Risk Officers and Enterprise Risk Leaders — who need to integrate cyber risk into enterprise risk governance
- Chief Information Officers and Technology Directors — who share accountability for technology risk, resilience and security investment
Requirements and prerequisites
Participants should have at least three years of experience in cybersecurity management, technology risk, IT governance or a closely related leadership role. They should understand core concepts including security controls, risk registers, incident response, third-party risk and security policies, and be comfortable discussing risk with senior stakeholders. Familiarity with NIST CSF, ISO/IEC 27001 or an enterprise GRC platform is helpful but not essential. No programming, penetration-testing expertise, audit qualification or quantitative risk-modelling background is required. Participants should bring awareness of their organisation's governance challenges, reporting practices and major regulatory obligations.
Training methodology
The course uses facilitated CISO-level discussions, short instructor briefings and structured workshops rather than technical lab work. Participants analyse board papers, regulatory findings, control exceptions and incident scenarios drawn from a realistic enterprise case. Small groups construct governance artefacts including committee terms of reference, risk appetite thresholds, dashboard measures and investment decision papers, then defend them in executive simulation sessions. Each participant adapts the work to their own context and completes a 90-day implementation plan, with instructor feedback on feasibility, stakeholder sequencing and evidence of success.
Course outline
Day 1: The CISO Governance Mandate
- Cybersecurity governance versus security management
- Board, executive and management accountability structures
- Three lines model for cyber risk oversight
- Decision-rights matrices using RACI and RAPID
- CISO mandate definition and delegation boundaries
- Governance failure patterns from major incidents
- Cybersecurity Governance Charter components
Workshop: Participants assess a fragmented governance scenario and produce a draft decision-rights matrix and CISO Governance Charter outline.
Day 2: Risk Appetite, Measurement and Board Reporting
- Cyber risk taxonomy and aggregation methods
- Risk appetite statements and tolerance thresholds
- FAIR loss event frequency and magnitude concepts
- Key risk indicators versus key performance indicators
- Risk register quality and treatment accountability
- Board dashboard design and narrative reporting
- Escalation triggers for material cyber risk
Workshop: Participants build a board dashboard and risk appetite scorecard for a simulated organisation facing ransomware, supplier and cloud risks.
Day 3: Control, Policy and Assurance Governance
- NIST CSF 2.0 Govern function application
- ISO/IEC 27001:2022 leadership and governance clauses
- Policy hierarchy from board policy to technical standard
- Control ownership and control attestation models
- Exception management and risk acceptance workflows
- Internal audit, second-line and independent assurance coordination
- Evidence-based control effectiveness reporting
Workshop: Participants design a policy hierarchy, control-owner model and exception approval workflow for a regulated digital business.
Day 4: Strategic Oversight of Suppliers, Resilience and Incidents
- Third-party cyber risk tiering criteria
- Contractual security requirements and assurance evidence
- Cloud shared-responsibility governance
- Cyber resilience governance and recovery objectives
- Executive incident command decision authorities
- Regulatory notification and stakeholder communication governance
- Post-incident review and remediation accountability
Workshop: Teams run an executive incident governance simulation and produce a decision log, stakeholder escalation plan and remediation oversight structure.
Day 5: Investment Governance and Implementation
- Cybersecurity strategy alignment to business objectives
- Security portfolio prioritisation and investment cases
- Cost, risk reduction and residual risk trade-offs
- Security programme steering committee design
- GRC platform workflow and reporting requirements
- Maturity roadmaps and governance operating cadence
- Ninety-day governance implementation planning
Workshop: Participants consolidate their work into a board-ready governance pack and present a prioritised 90-day implementation roadmap for peer and instructor review.
Tools & standards covered
NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, FAIR (Factor Analysis of Information Risk), ServiceNow Integrated Risk Management
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Executive Management
Strategic Portfolio Reporting with Microsoft Project Training Course
Senior leaders need portfolio reports that show more than a list of projects. They need reliable answers to questions about strategic alignm…
Diligent Boards Governance Administration for Executive Teams Training Course
Executive teams depend on timely, controlled board information, yet many governance processes still rely on emailed papers, inconsistent age…
Advanced Enterprise Portfolio Governance for Senior Executives Training Course
Enterprise portfolios fail when executives approve initiatives individually but lack a disciplined way to compare strategic value, capacity …
Management of Portfolios MoP for Executive Investment Governance Training Course
Executive teams often approve initiatives one business case at a time, only to find that the combined change load exceeds available funding,…