{"id":563,"date":"2025-05-07T09:05:20","date_gmt":"2025-05-07T08:05:20","guid":{"rendered":"https:\/\/cyberphil.azurewebsites.net\/?p=563"},"modified":"2025-05-07T09:05:21","modified_gmt":"2025-05-07T08:05:21","slug":"taking-time-out-to-flex-with-the-ec-council-cciso-boxset","status":"publish","type":"post","link":"https:\/\/www.cyberphil.co.uk\/?p=563","title":{"rendered":"Taking time out to flex with the EC Council CCISO boxset!"},"content":{"rendered":"\n<p>Those of you who are close to me will know that I have been off my feet for a few weeks following knee surgery.&nbsp; It forced me to take sick leave \u2013 which is something that I rarely do, and you could probably count on one hand the number of days I have been off work over the past 15 years or so.&nbsp; Admittedly \u2013 I have been lucky in this respect.<\/p>\n\n\n\n<p>However, the prospect of taking a long period of time off work filled me with dread \u2013 not least as to what was I going to do with my time.&nbsp; The good news is that if you have ever had knee replacement surgery \u2013 your mind is kept quite busy with how much it hurts and how sadistic physiotherapists are.<\/p>\n\n\n\n<p>Six weeks in and my knee is still not flexing well &#8211; and I am not sure if I will be able to do my old dance routines ever again!&nbsp; Which is going to be more of a shame for the general public.<\/p>\n\n\n\n<p>After a couple of weeks of feeling sore and gradually getting more bored (I did the whole series of Star Wars) \u2013 I started to attack some reading material to get some new certs underway and this helped keep me busy.&nbsp; My wife complained that I shouldn\u2019t be working but it was more reading and research \u2013 so wasn\u2019t too taxing.&nbsp; I still had plenty of time to put my feet up and sleep (which still evades me!)<\/p>\n\n\n\n<p>But despite being off work \u2013 I still needed to keep my mind active on something cybersecurity related and decided to flex the grey matter and have a go at the EC Council CCISO study.&nbsp; This has been on my \u2018to do\u2019 list for a while and having completed CISSP with Firebrand, earlier this year \u2013 I thought it would be a good opportunity to compare and contrast.<\/p>\n\n\n\n<p>I used the official study book from EC Council and read through the 5 domains \u2013 stopping and researching the bits that I either didn\u2019t understand or needed some form of clarification on.&nbsp; As with all certification vendors \u2013 there is often a difference in the terminology and focus of a course but luckily never a change of tack on the intended outcomes.&nbsp; Nobody needs to re-invent the wheel.<\/p>\n\n\n\n<p>The course material was difficult to read through and I found breaking it up into small areas rather than hitting each large domain in a \u2018oner\u2019 worked for me.&nbsp; There were areas that I knew well and others that I needed to take more time over.&nbsp;<\/p>\n\n\n\n<p>Domain 5 is particularly odd (for me at least) \u2013 \u2018Strategic Planning, Finance, Procurement and Vendor Management\u2019.&nbsp; I would imagine that this was also a particularly difficult module to write the courseware author.&nbsp; There are so many if\u2019s, but\u2019s and maybe\u2019s in this area that it really only scratches the surface in a lot of areas &#8211; and although it gives some guidance \u2013 for me was quite a handful. Every organisation I have worked with does this differently and has different terms for stuff relevant to this domain.<\/p>\n\n\n\n<p>The one thing that I didn\u2019t really like about the EC Council course was the focus was sometimes on US-based legislation and processes.&nbsp; I am fine with NIST standards and guidance and a lot of other great US-centric frameworks that have been adopted internationally \u2013 but there were a few moments when I thought \u2013 hold on a minute \u2013 we don\u2019t do that here.<\/p>\n\n\n\n<p>Luckily the exam was very neutral in this respect.&nbsp; So if you do the course or read the book \u2013 don\u2019t fret when it goes all weird and foreign.<\/p>\n\n\n\n<p>The NDA for the exam means I can\u2019t really tell you if it was all relevant, but a few odd questions did come up.<\/p>\n\n\n\n<p>There is no secret in the fact that the CCISO exam is 150 multiple choice questions and 150 minutes long.&nbsp; So even with my level of maths \u2013 that\u2019s 1 minute per question.&nbsp; Some of the questions are fairly straightforward and you will know the answer as soon as you read the question \u2013 others take a bit longer to digest.&nbsp; So it all averages out.&nbsp; I didn\u2019t find time an issue.<\/p>\n\n\n\n<p>As with all EC Council exams \u2013 there is no set passing percentage and you won\u2019t know until the final tot up if you have passed or not.<\/p>\n\n\n\n<p>You can take the exam at home using the remote proctor (unlike CISSP) which is handy &#8211; and the exam portal is simple and easy to navigate.&nbsp; You can mark questions for review and come back to them which also helps.&nbsp; I used this feature.<\/p>\n\n\n\n<p>Another big difference between the CCISO and CISSP is that EC Council expect you to know a few ISO\u2019s and Frameworks (which the CISSP alludes to but remains quite neutral on).&nbsp; But the good news is that if you have been knocking around information security for a while \u2013 these will be old hat to you.&nbsp; I guess that\u2019s the point.<\/p>\n\n\n\n<p>The CCISO had a lot of mini-scenario type questions which I quite liked but there were always 2 answers which could have been correct.&nbsp; CISSP is a bit like that \u2013 so as soon as you have got rid of the blatantly obvious wrong answers \u2013 it is a question of taking your time to pick up what they are after.<\/p>\n\n\n\n<p>I also found that a few questions on processes came up but again these were straightforward if you have done incident response, forensics and project management before.<\/p>\n\n\n\n<p>The CCISO exam and course is not technically deep (the same as CISSP) but there were a couple of questions on cryptography, network defence mechanisms, zero trust and cloud-technologies that made me stop and think. Mostly because all the answers looked the same or could have been correct and the well-used \u2018choose the BEST answer\u2019 questions are always my least favourite.\u00a0 The problem I find with courses which are not technical is that when they discuss the technology at such a high level it all gets very confusing and often poorly described.\u00a0 There are few courses out there that are like this.<\/p>\n\n\n\n<p>The whole point of CCISO is to layer on top or alongside CISSP a bit more of the executive officer angle of attack and so there is an emphasis on the Domain 5 stuff.&nbsp; Finance, legislation, procurement processes and \u2018what would the board do\u2019 type situations.&nbsp; I did find these tough and probably where I lost marks in the exam.<\/p>\n\n\n\n<p>Just like CISSP if the answer has something in it that benefits the business objectives \u2013 it is probably the right answer.&nbsp; However these are very ambiguous in the real-world.<\/p>\n\n\n\n<p>I am pleased to say that I passed the test but more importantly \u2013 I learned some stuff along the way.&nbsp; Do I ever want to be a CISO?&nbsp; Nope.&nbsp; Do I want to get a better understanding of how a business can maintain a good security posture and support operations at all levels?&nbsp; Yep.&nbsp; That\u2019s what this course puts in place.<\/p>\n\n\n\n<p>If you do want to be a CCISO or consider the knowledge and skills required for such a role \u2013 then this is a great option.<\/p>\n\n\n\n<p>This course and others from EC Council have recently been re-accredited by the NCSC in the UK which gives them a great stamp of approval at the highest level. This is not to be sniffed at. I know this first hand as I have been involved in the accreditation process with the NCSC for the Firebrand law enforcement courses we deliver and understand the process and rigour that is put in place to get on this list.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.ncsc.gov.uk\/information\/certified-training\">https:\/\/www.ncsc.gov.uk\/information\/certified-training<\/a><\/p>\n\n\n\n<p>I self-studied for this course as the good people at EC Council gave me an exam voucher and access to the book and the good people at Firebrand gave me the time and support to study it all.&nbsp; However, this is definitely a good course to do with an instructor in front of you \u2013 as I had questions and Google didn\u2019t always help.&nbsp; I also missed having the experience of all of the other delegates around me \u2013 who add value in bucket loads to courses like this.<\/p>\n\n\n\n<p>I know the instructors at Firebrand who deliver this (and in the future I might take this one on also) and I understand how top-drawer they are in what they do and how they do it.&nbsp; Check it out and add it to your \u2018to do\u2019 list as there is some learning to be had.<\/p>\n\n\n\n<p>I understand that in some respects \u2013 EC Council certifications are a bit like Marmite.&nbsp; But that\u2019s not the point.&nbsp; If you attend or study for any vendor accredited course and complete a tricky exam to verify your knowledge and in the case of the CCISO exam \u2013 your experience in the field (as the answers are not in the book) &#8211; then you have achieved something good.&nbsp; The fact that it is also nationally and internationally accredited at a high level helps to ratify this.<\/p>\n\n\n\n<p>Whether it is for professional growth or personal development \u2013 the EC Council courses are worth taking a look at \u2013 but as with all training courses, do your homework first.<\/p>\n\n\n\n<p>Some tips and tricks:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Download the \u2018blueprint\u2019 for the exam or course and understand the learning objectives.<\/li>\n\n\n\n<li>Make sure the learning objectives match to what YOU want to achieve and even better if it goes beyond your objectives (but never opt for something below your expectations).<\/li>\n\n\n\n<li>Consider the amount of time that you can spend learning (not just reading) \u2013 even better to get in a classroom and dedicate your time solely to study.<\/li>\n\n\n\n<li>Be realistic about your level of experience and course expectations.&nbsp; No exams are easy (if they are \u2013 they are probably not worth much in the real world).<\/li>\n\n\n\n<li>The CCISO exam (just like CISSP) tests you outside of the course material and expects you to be able to apply theoretical knowledge.<\/li>\n\n\n\n<li>Focus on the bits you don\u2019t know and try to get enthusiastic about learning something outside of your comfort zone \u2013 even if it is a dull as ditchwater!<\/li>\n\n\n\n<li>Talk to somebody who knows about vendor credentials and how the real world operates.&nbsp; That could be your training provider or a member of the team that works in their training delivery department.<\/li>\n\n\n\n<li>Celebrate success and be proud of what you achieve.<\/li>\n<\/ul>\n\n\n\n<p>Learn long and prosper!<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Those of you who are close to me will know that I have been off my feet for a few weeks following knee surgery.&nbsp; It forced me to take sick leave \u2013 which is something that I rarely do, and &hellip; <\/p>\n","protected":false},"author":1,"featured_media":566,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-563","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised","grid-sizer"],"_links":{"self":[{"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/563","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=563"}],"version-history":[{"count":2,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/563\/revisions"}],"predecessor-version":[{"id":567,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/563\/revisions\/567"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=\/wp\/v2\/media\/566"}],"wp:attachment":[{"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=563"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=563"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyberphil.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=563"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}