The Certified Chief Information Security Officer (CISO) is a certification designed for professionals seeking to validate their comprehensive knowledge of information security governance, risk management, compliance, and incident management, based on ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27035, and the NIST Cybersecurity Framework (CSF 2.0).
This exam covers key topics from ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27035, and the NIST Cybersecurity Framework (CSF 2.0), including information security governance, organizational accountability, risk assessment and treatment, incident management, compliance obligations, and control objectives. It validates your comprehensive knowledge of how to govern, manage, and continuously improve an organization’s information security program, ensuring effective protection of information assets and resilience against cyber threats in accordance with widely used and globally recognized standards and frameworks.
The Certified Chief Information Security Officer certification exam is an online, closed-book, and remotely-proctored exam. This exam consists of 50 multiple-choice questions. The passing score is 70%. Candidates will have 60 minutes to complete the exam. Validate your information security leadership expertise and advance your career. Purchase your exam voucher now!
|
Exam code |
ITC-200 |
|
Launch date |
January 29, 2026 |
|
Exam description |
The Certified Chief Information Security Officer (CISO) exam validates the candidate’s knowledge of information security governance, risk management, compliance, and incident management, in accordance with internationally recognized standards and frameworks. |
|
Current version |
v1 (January 29, 2026) |
|
Exam format |
Multiple choice; computer-based; closed book (online proctored exam) |
|
Number of questions |
50 questions |
|
Passing score |
70% (35 out of 50) |
|
Exam duration |
60 minutes |
|
Level |
Advanced |
|
Languages |
English and Portuguese |
|
Exam description |
This exam covers key topics from ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27035, and the NIST Cybersecurity Framework (CSF 2.0), including information security governance, organizational accountability, risk assessment and treatment, incident management, compliance obligations, and control objectives. It validates your comprehensive knowledge of how to govern, manage, and continuously improve an organization’s information security program, ensuring effective protection of information assets and resilience against cyber threats in accordance with widely used and globally recognized standards and frameworks. |
|
RECOMMENDED HOURS OF STUDY |
32 hours |
|
BLOOM'S TAXONOMY |
Level 2 (Understanding), Level 3 (Applying), Level 4 (Analyzing), and Level 5 (Evaluating) |
|
Recommended reading |
• ISO/IEC 27001:2022 – Information security, cybersecurity and privacy protection — Information Security Management Systems (ISMS) |
|
Prerequisites |
There are no prerequisites for this certification program. |
|
Recommended experience |
Six months of work experience in Artificial Intelligence |
|
Validity period |
Lifetime |
| Domains | Weight |
|---|---|
|
1. ISO/IEC 27001 |
20% |
|
2. ISO/IEC 27002 |
20% |
|
3. ISO/IEC 27005 |
20% |
|
4. ISO/IEC 27035 |
20% |
|
5. NIST Cybersecurity Framework (CSF 2.0) |
20% |
Total | 100% |
Browse our certification programs and choose your certification.
Discover the exam objectives and prepare for your exam.
Register for your online proctored exam.
Take your online proctored exam in the comfort of your home or office.
Congratulations! You are certified!
After purchasing an exam voucher, candidates will have 180 days to take the exam.
The exam voucher includes 2 retakes in case the candidate fails the first attempt.
There are no prerequisites to take the exams. ITCERTS recommends that candidates have at least six months of work experience in the area that the certification exam covers.
If a candidate does not achieve a passing score on the first attempt, there is no waiting period between the first and the second attempt. If a candidate does not achieve a passing score on the second attempt, the candidate must wait at least 7 days before retaking the exam for a third time. A candidate may not take a given exam any more than three times per year (12 months).
Visit the Online Proctored Exam registration page to find complete instructions.
Training is recommended as part of your certification preparation, but it is not mandatory.
Our exams are currently available in English and Portuguese.
Exams are delivered online (Online Proctored Exams) and can be taken from anywhere in the world.
ITCERTS certifications are considered good-for-life and do not expire.
Your employer can verify your certification on our certification verification page. Your certification number will be needed in order to process the verification.
Subscribe to our newsletter