CvCISO-1 Class and Exam

Course Description

The Certified virtual Chief Information Security Officer Course (CvCISO-1) is the intense foundational course for the SecurityStudio CvCISO Program and is the required course for all CvCISO certifications.

This course covers all the basics of what a vCISO is and what a vCISO does. Students from all backgrounds and all levels of experience will benefit from this course.

Students with no information security experience will gain an understanding of what makes a vCISO successful. These students will also attain enough knowledge to pass the CvCISO-1 exam and perform as a vCISO in limited environments with assistance (See: CvCISO Level 1).

Students with many years information security experience will gain a better, more formalized understanding of how other (possibly more) successful vCISOs perform on the job. Students on the top end of the experience scale will attain enough knowledge to pass the exam and potentially attain the CvCISO Level 3 or Expert designation.


This CvCISO-1 session begins on June 14, 2022 and runs through August 18, 2022.

This class is a prerequisite for taking (and hopefully passing) the CvCISO-1 Certification Exam. Completing the CvCISO-1 course and passing the exam earns the student the designation of “CvCISO”.

Classes are taught Tuesday, Wednesday, and Thursday evenings from 6pm - 8pm Central Time (CT). Classes on Tuesday and Thursday are LIVE, and Wednesday sessions are previously recorded.

All class sessions will be recorded for students who are unable to attend live, for whatever reason. Recorded sessions will also be available to assist students in their studies.

Course Outline

There are ten chapters in the CvCISO-1 course. Each chapter covers one or more topics that are essential to CvCISO (and vCISO) success.

Course Length

The CvCISO-1 course runs for ten weeks and includes 30 instructor-led 2-hour sessions (60 classroom hours in total). In addition to the classroom hours, students are expected to complete an additional 60 hours of practical assignments and study (to be successful).

Course Cost

The cost of the course is $3,000/student; however, SecurityStudio is committed to serving the underserved, so discounts and scholarships are available under certain circumstances.

The cost of the course includes the CvCISO-1 examination fee (and retakes, if necessary).

Course Schedule

Chapter 1 - Introduction to the CvCISO Program (1 Lesson/2 Hours)

Covers everything there is to know about the SecurityStudio Certified virtual Chief Information Security Officer Program and how to be successful with it.

Chapter 2 - Information Security Fundamentals (15 Lessons/30 Hours)

The most intense portion of the CvCISO-1 course, this chapter introduces information security fundamentals without shortcuts and builds mastery critical to vCISO success.

Chapter 3 – vCISO/Customer Relationship (1 Lesson/2 Hours)

This chapter covers setting the appropriate expectations and communicating effectively, especially with people who don’t speak the information security language natively.

Chapter 4 - Roles and Responsibilities (1 Lesson/2 Hours)

This chapter covers how to establish good governance, including how to determine the most important roles, assigning the roles, and establishing accountability.

Chapter 5 - Risk Assessment (3 Lessons/6 Hours)

In previous chapters, the vCISO should have established effective communication, determined (and assigned) roles, and established responsibilities. This chapter leverages previous work to conduct a comprehensive, objective, and measurable information security risk assessment. Students will learn how to lead an information security risk assessment and use SecurityStudio's S2Org to conduct one.

NOTE: Although S2Org is used in the class, CvCISO certification is NOT dependent upon using any SecurityStudio product.

Chapter 6 - Building a Roadmap (2 Lessons/4 Hours)

Risk assessment is only one part of the risk management process. Learning how to use a risk assessment is where skill and experience are put to the test. Risk decisions must be made and resources must be allocated to enact the decisions. This chapter teaches students how to build, communicate, and adjust information security roadmaps.

Chapter 7 - Asset Management (2 Lessons/4 Hours)

It's only logical that we can't protect what we don't know we have. Students learn how to build and maintain effective asset management programs in this chapter.

Chapter 8 - Incident Management (2 Lessons/4 Hours)

Information security incidents are a certainty that all information security leaders need to be prepared for. In this chapter, students will learn how to build functional incident management capabilities and integrate them into an organization seamlessly.

Chapter 9 - Third Party Information Security Risk Management (TPISRM) (1 Lesson/2 Hours)

More than half of all information security incidents are caused directly or indirectly by third parties. In this Chapter, students will learn how to build a comprehensive third-party information security risk management program from building an inventory of third-party relationships to risk management and contract requirements.

Students will use S2Vendor to conduct third-party information security risk management activities for demonstration; however, S2Vendor-specific skills are not required for CvCISO certification.

Chapter 10 - Maintaining Progress and Transition (2 Lessons/4 Hours)

Information security processes must be continually maintained and eventually all vCISO contracts are terminated. In this Chapter, students learn strategies to ensure that information security progress is not lost and can be maintained over the long term. Students also learn how to gracefully transition vCISO leadership from themselves to someone else.

BONUS - CvCISO-1 Examination Preparation (1 Lesson/2 Hours)

All the content has been delivered at this point. This session is dedicated to preparing the students for their certification examination.

SecurityStudio Certified virtual Chief Information Security Officer Course (CvCISO-1)

SecurityStudio created the Certified virtual Chief Information Security Officer (CvCISO) Program to establish the industry standard for vCISO quality and qualifications, ultimately to best serve the community’s need for more (and better) vCISOs.

About SecurityStudio and the CvCISO Program

SecurityStudio is 100% dedicated to the mission of serving our community by fixing the information security industry. Fixing the information security industry requires dedication to our vision, “SIMPLIFY INFORMATION SECURITY FOR ALL” and developing solutions to unsolved problems.

SecurityStudio’s Software as a Service (SaaS) platform, known as S2, has been used by thousands of organizations and individuals to help them manage information security risk and master information security fundamentals.

The CvCISO Program is the first certification program for virtual Chief Information Security Officers (vCISOs). The program was designed by SecurityStudio to develop more and better vCISOs to serve our community’s information security needs in a more credible and standardized manner.

We hope you will join us on our mission!

For more information about SecurityStudio, visit us online at