Certified International Cybersecurity Professional
Protect Digital Systems. Detect Cyber Threats.Respond with Confidence. Build Cyber Resilience.
Cybersecurity has evolved far beyond protecting traditional networks and devices. Today's organizations operate across interconnected ecosystems of cloud platforms, digital identities, applications, APIs, endpoints, enterprise data, Artificial Intelligence, remote environments, operational technologies, and global digital supply chains—creating an increasingly complex and dynamic cyber-risk landscape.
Regulatory requirements, privacy, data protection, security audits, assessments, control effectiveness, and assurance.
7.4 Third-Party, Supply-Chain, Ethics, and Professional Responsibility
Vendor security, third-party risk, supply-chain security, professional ethics, accountability, and responsible cybersecurity practice.
Module 8: AI Security, Emerging Technologies & Professional Practice
8.1 Artificial Intelligence and Generative AI Security
AI security, GenAI risks, prompt injection, sensitive-data exposure, model vulnerabilities, and AI access controls.
8.2 AI-Enabled Cyberattacks and Cyber Defense
AI-assisted attacks, social engineering, automated threats, AI-enabled detection, security analytics, and defensive automation.
8.3 IoT, OT, Cloud-Native, Containers, and DevSecOps Security
IoT and OT security, containers, cloud-native environments, DevSecOps, APIs, automation, and software supply chains.
8.4 Emerging Cyber Risks and Professional Practice
Emerging threats, technology risk, human oversight, responsible security, professional ethics, continuous learning, and cybersecurity career development.
Career Opportunities
CICSP® can support development toward roles such as:
Cybersecurity Analyst
Security Analyst
SOC Analyst
Cyber Defense Analyst
Information Security Analyst
Network Security Analyst
Security Administrator
Vulnerability Analyst
Cloud Security Analyst
Incident Response Analyst
Cyber Risk Analyst
Security Consultant
Information Systems Security Professional
Security Operations Professional
Cybersecurity Specialist
Actual job eligibility depends on employer requirements, professional experience, education, and technical competency.
Become
a Cybersecurity professional the market trusts.
The Certified International Cybersecurity Professional (CICSP®) is a comprehensive, vendor-neutral professional certification designed to develop and validate the practical knowledge, applied skills, analytical capabilities, and professional judgment required to operate effectively across the modern cybersecurity lifecycle.
Offered by the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
CICSP® prepares cybersecurity and technology professionals to identify risks, protect critical assets, detect malicious activity, analyze threats and vulnerabilities, respond to incidents, support secure recovery, apply cybersecurity governance, and continuously strengthen organizational cyber resilience.
The certification bridges technical cybersecurity with operational defense, risk management, governance, and emerging technology security—providing professionals with an integrated understanding of how modern organizations protect their digital environments.
Build the Skills Required for Modern Cyber Defense
CICSP® integrates twelve essential cybersecurity competency areas
Security Architecture
Network Defense
Identity & Access Management (IAM)
Data Security
Cloud Security
Vulnerability Management
SOC Operations
Threat Intelligence
Incident Response
Digital Forensics
Governance, Risk & Compliance (GRC)
AI Security
Professional level — Three-year certification cycle with continuing professional education
From securing enterprise infrastructure and managing vulnerabilities to investigating cyber incidents and addressing AI-driven threats, CICSP® provides a comprehensive professional framework for today's rapidly evolving cybersecurity environment.
The result is a cybersecurity professional prepared not simply to understand security concepts, but to apply cybersecurity knowledge, make risk-informed decisions, support effective cyber defense, and contribute to sustainable enterprise resilience.
Why this credential
Why Earn the CICSP® Certification?
Cybersecurity has become an enterprise-wide responsibility.
Organizations need professionals who can see beyond individual security tools and understand how threats, vulnerabilities, identities, networks, applications, cloud environments, data, security operations, risk, governance, and human behavior interact to influence organizational security.
CICSP® is designed for professionals who want to build that broader capability.
Because CICSP® is vendor-neutral, the knowledge and competencies represented by the certification are designed to remain transferable across different technologies, platforms, organizations, industries, and cybersecurity environments.
The focus is not simply:
“Do you know cybersecurity terminology?”
The more important question is:
“Can you apply cybersecurity knowledge to make appropriate professional decisions?”
CICSP® prepares professionals to address practical questions such as:
What Must We Protect?
Identify critical systems, information, identities, applications, infrastructure, business services, and technology dependencies requiring appropriate protection.
Where Are We Vulnerable?
Recognize vulnerabilities, configuration weaknesses, attack surfaces, excessive privileges, cloud exposures, insecure applications, and other sources of cyber risk.
Which Security Controls Are Appropriate?
Evaluate preventive, detective, corrective, compensating, administrative, technical, and physical controls according to the threat and organizational context.
How Should Identities and Privileged Access Be Protected?
Apply authentication, authorization, MFA, least privilege, privileged access management, identity lifecycle, and Zero Trust principles.
How Should Cloud Environments Be Secured?
Understand cloud responsibilities, identity controls, data protection, configuration security, workloads, APIs, monitoring, and shared-responsibility considerations.
What Do Security Alerts and Events Mean?
Interpret logs, alerts, endpoint telemetry, network activity, indicators of compromise, and threat intelligence to determine whether further investigation is required.
When Does Suspicious Activity Become a Cybersecurity Incident?
Evaluate evidence, severity, business impact, affected assets, attack behavior, and risk to determine appropriate escalation and response.
How Should Cybersecurity Incidents Be Managed?
Support containment, investigation, eradication, evidence preservation, communication, recovery, documentation, and post-incident improvement.
How Can Organizations Recover Securely?
Restore systems and services while validating security, correcting weaknesses, protecting business continuity, and reducing the likelihood of recurrence.
How Do Governance, Risk, Privacy, and Compliance Affect Security Decisions?
Understand how policies, regulations, control frameworks, risk requirements, privacy obligations, third-party relationships, and organizational governance influence cybersecurity.
How Are AI and Emerging Technologies Changing Cyber Risk?
CICSP® is designed for current and aspiring cybersecurity and technology professionals, including:
Cybersecurity Professionals
Cybersecurity Analysts
SOC Analysts
Cyber Defense Analysts
Information Security Analysts
Network Security Professionals
Network Engineers
Systems Administrators
Security Administrators
Cloud Professionals
Cloud Security Analysts
Incident Response Analysts
Vulnerability Analysts
Cyber Risk Analysts
Security Consultants
IT Auditors
GRC Professionals
Information Systems Professionals
IT Professionals
Digital Forensics Professionals
Technology professionals transitioning into cybersecurity
Graduates and students preparing for cybersecurity careers
Cybersecurity
Recommended Candidate Background
The Certified International Cybersecurity Professional (CICSP®) is positioned as a professional-level certification for individuals seeking to develop, demonstrate, and validate practical competency across modern cybersecurity environments.
CICSP® is accessible to both working technology professionals and individuals transitioning into cybersecurity. Candidates are not required to possess advanced cybersecurity expertise before beginning the program.
Recommended Foundational Knowledge
Candidates benefit from a basic understanding of one or more of the following areas:
Computer hardware and software fundamentals
Windows, Linux, or comparable operating systems
Computer networking concepts
TCP/IP fundamentals
IP addressing and basic network configuration
Common network ports and protocols
User accounts, permissions, and access controls
Internet and web technologies
Cloud-computing fundamentals
Basic data and information-security concepts
General cybersecurity terminology and practices
Helpful Technical Experience
Although not mandatory, familiarity with the following can enhance the CICSP® learning experience:
Command-line environments
Basic scripting or automation
Databases and SQL fundamentals
Virtual machines and virtualization
Cloud platforms
Network troubleshooting
System administration
Technical support
Security monitoring
Basic log analysis
Professional Experience
Advanced cybersecurity experience is not required to begin CICSP® training.
The program is appropriate for candidates with backgrounds in:
It is also suitable for qualified students, recent graduates, career-transition professionals, and individuals seeking to establish broader professional cybersecurity competency.
Information Technology
Computer Science
Information Systems
Networking
Cloud Computing
Systems Administration
Software or Application Development
Data and Analytics
IT Audit and Compliance
Risk Management
Technical Support
Digital Forensics
Cybersecurity
Related technology disciplines
Recommended Preparation
Candidates without prior technical or cybersecurity experience can strengthen their preparation by developing foundational knowledge in:
Computer Systems → Operating Systems → Networking → TCP/IP → Cloud Fundamentals → Access Control → Basic Cybersecurity
These foundations help candidates engage more effectively with CICSP® topics involving network defense, IAM, cloud security, vulnerability management, security operations, incident response, digital forensics, governance, and AI security.
CICSP®
CICSP® Course Learning Outcomes
Upon successful completion of the Certified International Cybersecurity Professional (CICSP®) program, participants will be able to demonstrate professional competency across eight integrated cybersecurity areas.
01 / 08
1. Apply Cybersecurity Principles, Threat Analysis, and Security Architecture
Apply fundamental cybersecurity principles to evaluate threats, vulnerabilities, attack surfaces, security requirements, and organizational technology environments.
Participants will be able to:
Learning Outcome: Evaluate cybersecurity environments and recommend appropriate security principles, architectural approaches, and controls based on identified threats and organizational requirements.
Apply confidentiality, integrity, and availability principles
Differentiate authentication, authorization, and accountability
Identify threats, vulnerabilities, attack vectors, and attack surfaces
Evaluate administrative, technical, and physical security controls
Apply least privilege and need-to-know principles
Explain and apply defense-in-depth
Apply Zero Trust security principles
Evaluate basic security architecture and secure-design requirements
Relate cybersecurity controls to organizational risk
Apply resilience and risk-based security principles
02 / 08
2. Secure Networks, Systems, Endpoints, and Infrastructure
Apply appropriate cybersecurity controls to protect enterprise networks, computing systems, endpoints, wireless environments, remote connections, and supporting infrastructure.
Participants will be able to:
Learning Outcome: Select and apply appropriate preventive, detective, and corrective controls to reduce network, endpoint, system, and infrastructure exposure.
Evaluate network-security architectures
Apply network segmentation principles
Evaluate firewall and access-control requirements
Explain IDS/IPS functionality and use
Identify risks associated with common ports and protocols
Apply secure communication protocols
Evaluate wireless-security controls
Apply operating-system and endpoint-hardening principles
Assess patch and configuration-management requirements
Evaluate endpoint protection and detection controls
Apply secure remote-access principles
Identify infrastructure vulnerabilities and recommend safeguards
03 / 08
3. Apply Identity, Data, Application, API, and Cloud Security
Protect organizational identities, information, applications, APIs, and cloud resources through appropriate security and access-management practices.
Participants will be able to:
Learning Outcome: Evaluate and apply identity, data, application, API, and cloud-security controls according to organizational risk, business requirements, and information sensitivity.
Apply Identity and Access Management (IAM) principles
Evaluate authentication and authorization requirements
Apply Multi-Factor Authentication (MFA)
Explain Single Sign-On (SSO) and identity federation
Apply Role-Based Access Control (RBAC)
Evaluate Privileged Access Management (PAM)
Apply identity-lifecycle and least-privilege principles
Explain fundamental cryptographic controls
Apply data-classification and protection requirements
Identify common application-security risks
Evaluate API-security requirements
Apply cloud-security principles
Interpret cloud shared-responsibility models
Evaluate cloud identity, access, configuration, and data-protection controls
04 / 08
4. Perform Vulnerability, Threat, and Cyber-Risk Assessment
Identify cybersecurity weaknesses, analyze threat information, evaluate potential impact, and support risk-based remediation decisions.
Participants will be able to:
Learning Outcome: Transform vulnerability and threat information into prioritized, risk-informed security recommendations and remediation actions.
Identify common vulnerabilities and security weaknesses
Interpret vulnerability-assessment findings
Evaluate vulnerability severity and organizational context
Analyze threat actors, motivations, capabilities, and techniques
Assess attack surfaces and potential exposure
Apply basic threat-modeling concepts
Evaluate likelihood and potential impact
Prioritize vulnerabilities according to risk
Recommend appropriate remediation or compensating controls
5. Apply Security Monitoring, Threat Detection, and Cyber Defense
Analyze cybersecurity information to identify suspicious activity, investigate potential threats, and support defensive-security operations.
Participants will be able to:
Learning Outcome: Analyze security telemetry, alerts, logs, and threat intelligence to identify potentially malicious activity and support effective cyber-defense decisions.
Interpret security logs and event information
Analyze network-security activity
Evaluate endpoint telemetry
Interpret security alerts
Recognize Indicators of Compromise (IOCs)
Apply threat-intelligence information
Perform basic alert triage
Identify anomalous or suspicious behavior
Explain SIEM capabilities and workflows
Apply event-correlation concepts
Support threat-hunting activities
Differentiate false positives from potentially significant events
Escalate security events appropriately
Document cyber-defense findings
06 / 08
6. Support Incident Response, Investigation, Digital Forensics, and Recovery
Apply structured incident-response and forensic practices to investigate cybersecurity incidents, preserve evidence, support containment, and restore secure operations.
Participants will be able to:
Learning Outcome: Support the complete cybersecurity incident lifecycle from identification and containment through investigation, evidence preservation, recovery, and post-incident improvement.
Recognize and classify cybersecurity incidents
Perform incident triage and prioritization
Support containment activities
Identify appropriate eradication actions
Support secure recovery
Identify and preserve potential digital evidence
Apply chain-of-custody principles
Explain forensic-readiness requirements
Analyze basic endpoint, network, log, and cloud evidence
Develop incident timelines
Document incident-response activities
Support root-cause analysis
Participate in lessons-learned reviews
Relate incident recovery to business continuity and cyber resilience
07 / 08
7. Apply Cybersecurity Governance, Risk, Compliance, Privacy, and Responsible Security
Integrate technical cybersecurity practices with organizational governance, risk-management requirements, privacy obligations, compliance expectations, and professional responsibility.
Participants will be able to:
Learning Outcome: Integrate cybersecurity controls with governance, risk, compliance, privacy, third-party security, and professional accountability requirements.
Explain cybersecurity governance structures
Apply organizational security policies and standards
Support cybersecurity risk assessments
Relate security controls to organizational risk
Interpret relevant control frameworks
Recognize regulatory and contractual security requirements
Apply privacy and data-protection principles
Support security audits and assessments
Evaluate control effectiveness
Identify third-party and vendor cybersecurity risks
Recognize digital supply-chain security concerns
Apply cybersecurity ethics and professional responsibility
Document and communicate governance and risk findings
Support continuous security improvement
08 / 08
8. Evaluate AI Security, Emerging Technologies, and Evolving Cyber Threats
Assess cybersecurity opportunities and risks associated with Artificial Intelligence and other rapidly evolving technologies.
Participants will be able to:
Learning Outcome: Evaluate emerging cybersecurity risks and recommend appropriate safeguards for AI-enabled, cloud-native, connected, automated, and rapidly evolving technology environments.
Explain fundamental AI and Generative AI security considerations
Identify cybersecurity risks affecting AI-enabled systems
Recognize prompt-injection and AI-manipulation risks
Evaluate sensitive-data exposure through AI systems
Identify AI identity and access-control concerns
Evaluate AI-assisted cyberattack techniques
Explain AI-assisted cyber-defense applications
Recognize AI model and application vulnerabilities
Evaluate AI supply-chain and third-party risks
Identify security considerations involving AI agents and automation
Evaluate cloud-native security risks
Recognize container and DevSecOps security considerations
Evaluate IoT and Operational Technology (OT) security risks
Identify software supply-chain threats
Assess emerging attack techniques
Apply human-oversight and responsible-security principles to emerging technologies
Swipe or scroll sideways to see each part →
Learning outcomes
CICSP® Integrated Learning Outcome
Collectively, the eight learning outcomes prepare participants to integrate:
Cybersecurity Foundations + Architecture + Network Defense + IAM + Data Protection + Application Security + Cloud Security + Vulnerability Management + Threat Intelligence + SOC Operations + Incident Response + Digital Forensics + GRC + AI Security
Participants completing the CICSP® program develop the capability to move progressively through the professional cybersecurity lifecycle:
What is assessed
CICSP® Certification Testing Outcomes
The CICSP® certification assessment evaluates a candidate’s ability to apply cybersecurity knowledge, analyze security situations, assess risk, and make appropriate professional decisions across eight competency domains.
1
1. Cybersecurity Foundations and Security Architecture
Evaluate cybersecurity principles, threats, vulnerabilities, security controls, Zero Trust, defense-in-depth, and secure architecture.
2
2. Network, Infrastructure, and Endpoint Security
Select appropriate controls for networks, systems, endpoints, wireless environments, remote access, protocols, and infrastructure.
3
3. Identity, Data, Application, and Cloud Security
Evaluate IAM, authentication, privileged access, cryptography, data protection, application and API security, and cloud-security controls.
4
4. Vulnerability, Threat, and Cyber-Risk Assessment
Interpret logs, alerts, endpoint telemetry, threat intelligence, security events, and indicators of compromise to support threat detection and defense.
6
6. Incident Response, Digital Forensics, and Recovery
Evaluate cybersecurity incidents, select response actions, preserve evidence, support investigations, and recommend secure recovery measures.
7
7. Governance, Risk, Compliance, and Privacy
Apply cybersecurity governance, risk management, privacy, compliance, audit, third-party security, and professional ethics principles.
The CICSP®–IBACTP® Cybersecurity Professional Competency Model
The CICSP®–IBACTP® Cybersecurity Professional Competency Model defines the integrated knowledge, applied skills, analytical capabilities, and professional judgment required of a modern cybersecurity professional.
The model is organized around eight interconnected professional competency dimensions that collectively represent the cybersecurity lifecycle—from understanding threats and protecting digital assets to detecting attacks, responding to incidents, governing cyber risk, and addressing emerging technologies.
Rather than treating cybersecurity disciplines as isolated technical functions, the CICSP® model connects technology, security operations, risk, governance, resilience, and professional decision-making within a unified competency framework.
01 / 08
1. Cybersecurity Foundations and Security Architecture
Establish the foundational knowledge required to understand and evaluate modern cybersecurity environments.
Competency includes:
Professional Competency:
Evaluate cybersecurity environments and identify appropriate architectural principles and security controls for protecting organizational assets.
Confidentiality, integrity, and availability
Authentication, authorization, and accountability
Threats, vulnerabilities, exploits, and attack surfaces
Security controls and control categories
Defense-in-depth
Least privilege
Zero Trust principles
Security architecture
Secure design principles
Risk-based security
Cyber resilience
Security policies and standards
Physical, administrative, and technical safeguards
02 / 08
2. Network, Infrastructure, and Endpoint Defense
Protect the technology infrastructure through which organizational information, applications, users, and services operate.
Competency includes:
Professional Competency:
Assess network, endpoint, and infrastructure exposures and apply appropriate preventive, detective, and corrective safeguards.
Network architecture and segmentation
TCP/IP and secure protocols
Firewalls
IDS/IPS
VPN and secure remote access
Wireless security
Network access controls
Endpoint protection
Endpoint detection and response
Operating-system security
System hardening
Patch and configuration management
Virtualization security
Infrastructure monitoring
03 / 08
3. Identity, Data, Application, and Cloud Protection
Protect users, digital identities, sensitive information, applications, APIs, and cloud environments through appropriate security controls.
Competency includes:
Professional Competency:
Select and apply appropriate identity, data, application, API, and cloud-security controls according to organizational requirements and risk.
Identity and Access Management (IAM)
Authentication and authorization
Multi-Factor Authentication (MFA)
Single Sign-On (SSO)
Federation
Role-Based Access Control (RBAC)
Privileged Access Management (PAM)
Least privilege
Identity lifecycle management
Cryptography
Encryption and key-management concepts
Data classification and protection
Application security
Secure software principles
API security
Cloud security
Shared-responsibility models
Cloud identity and access controls
04 / 08
4. Threat, Vulnerability, and Cyber-Risk Management
Identify, assess, prioritize, and support the treatment of cybersecurity threats, vulnerabilities, exposures, and organizational risks.
Competency includes:
Professional Competency:
Translate technical vulnerabilities and threat information into prioritized, risk-informed remediation and security decisions.
Threat actors and attack techniques
Threat modeling
Attack surfaces
Vulnerability identification
Vulnerability scanning
Vulnerability assessment
Security misconfigurations
Exposure analysis
Risk identification
Likelihood and impact
Risk prioritization
Vulnerability severity
Remediation prioritization
Risk treatment
Compensating controls
Continuous vulnerability management
Threat-informed risk assessment
05 / 08
5. Security Operations and Cyber Defense
Detect, analyze, investigate, and support defensive actions against malicious activity within organizational environments.
Competency includes:
Professional Competency:
Interpret security information, distinguish meaningful threats from routine activity, and support timely defensive action.
Security Operations Center (SOC) practices
Security monitoring
SIEM concepts
Log collection and analysis
Endpoint telemetry
Network-security monitoring
Security alerts
Indicators of Compromise (IOCs)
Threat intelligence
Threat hunting
Detection engineering concepts
Behavioral analysis
Alert triage
Event correlation
Cyber-defense workflows
Security automation concepts
Escalation and documentation
06 / 08
6. Incident Response, Digital Forensics, and Cyber Resilience
Respond effectively to cybersecurity incidents while preserving evidence, supporting investigation, restoring secure operations, and improving organizational resilience.
Competency includes:
Professional Competency:
Support the complete incident lifecycle from detection and investigation through containment, recovery, evidence preservation, and post-incident improvement.
Incident preparation
Detection and identification
Incident classification
Triage and prioritization
Containment
Eradication
Recovery
Incident documentation
Escalation and communication
Evidence identification
Evidence preservation
Chain of custody
Digital-forensics principles
Forensic readiness
Root-cause analysis
Lessons learned
Business continuity
Disaster recovery
Cyber resilience
07 / 08
7. Governance, Risk, Compliance, Privacy, and Professional Responsibility
Connect cybersecurity activities with organizational governance, enterprise risk, regulatory requirements, privacy obligations, accountability, and responsible professional practice.
Competency includes:
Professional Competency:
Apply governance, risk, compliance, privacy, and professional-responsibility principles to support secure and accountable organizational operations.
Cybersecurity governance
Security policies and standards
Enterprise risk management
Security-risk assessment
Control frameworks
Compliance requirements
Privacy and data protection
Security audits and assessments
Control effectiveness
Third-party cybersecurity
Vendor risk
Supply-chain risk
Security awareness
Professional ethics
Accountability
Documentation and reporting
Continuous improvement
08 / 08
8. AI Security and Emerging Technology Protection
Evaluate and address cybersecurity risks introduced by Artificial Intelligence and rapidly evolving digital technologies.
Competency includes:
Professional Competency:
Assess emerging technology risks, identify appropriate safeguards, and integrate new security requirements into established cybersecurity practices.
Artificial Intelligence security
Generative AI security
Large Language Model security
Prompt injection
Sensitive-data exposure
AI access controls
AI-enabled cyberattacks
AI-assisted cyber defense
Model and application vulnerabilities
AI supply-chain risk
AI agents and automation
Cloud-native security
Container security
DevSecOps
IoT security
Operational Technology (OT) security
API ecosystems
Software supply-chain security
Emerging attack techniques
Human oversight of AI-enabled security
Responsible use of emerging technologies
Swipe or scroll sideways to see each part →
CICSP®
CICSP® Professional Competency Standard
A CICSP® credential holder is positioned to connect:
CICSP® evaluates more than cybersecurity knowledge. Candidates demonstrate the ability to apply controls, analyze threats, assess risk, respond to incidents, and make sound cybersecurity decisions.
The Certified International Cybersecurity Professional (CICSP®) is a comprehensive, vendor-neutral professional certification designed to validate the knowledge, applied technical competency, analytical judgment, risk awareness, and professional capabilities required to protect modern digital environments.
CICSP® recognizes that cybersecurity professionals must do more than understand individual technologies. They must understand how people, identities, data, applications, networks, cloud platforms, endpoints, security operations, governance, and emerging technologies interact across the enterprise cybersecurity ecosystem.
The certification therefore provides an integrated professional framework spanning the complete cybersecurity lifecycle—from identifying risks and protecting critical assets to detecting threats, investigating incidents, supporting recovery, applying governance, and continuously strengthening cyber resilience.
A Comprehensive Cybersecurity Certification for the Modern Digital Enterprise
CICSP® develops and validates competency across eight integrated areas:
Apply identity and access management, authentication, authorization, privileged access, cryptography, data protection, application security, API security, and cloud-security principles.
4. Vulnerability, Threat & Cyber-Risk Management
Identify vulnerabilities, analyze threats, assess exposure, prioritize remediation, and support risk-informed cybersecurity decisions.
CICSP® is vendor-neutral, but practical training can expose candidates to representative tools and technologies such as:
01 / 06
Network and Traffic Analysis
Wireshark
Packet-analysis tools
TCP/IP utilities
Network scanners
02 / 06
Vulnerability Assessment
Nmap
Vulnerability scanners
Configuration-assessment tools
Security-baseline tools
03 / 06
Security Operations
SIEM platforms
Log-analysis tools
Endpoint-detection technologies
Threat-intelligence tools
Security dashboards
04 / 06
Systems and Platforms
Windows
Linux
Virtual machines
Cloud environments
Containers
05 / 06
Incident Response and Forensics
Log-analysis platforms
Endpoint artifacts
Network evidence
Digital-forensics tools
Incident timelines
06 / 06
Automation and Scripting
All tools are intended for use only within authorized training, laboratory, and professional environments.
Python
PowerShell
Shell environments
Security automation concepts
Swipe or scroll sideways to see each part →
Applied practice
Hands-On Practical Labs
Lab 1: Network and Endpoint Security Assessment
Candidates assess a simulated enterprise environment for network, endpoint, and configuration weaknesses.
Deliverable: Network and Endpoint Security Assessment.
Lab 2: Vulnerability Assessment and Remediation
Candidates interpret vulnerability findings, prioritize risks, and recommend corrective actions.
Deliverable: Vulnerability Prioritization and Remediation Report.
Lab 3: SOC Monitoring and Threat Investigation
Candidates analyze logs, alerts, endpoint events, and indicators to investigate suspicious activity.
Deliverable: Security Investigation Report.
Lab 4: Incident Response and Digital Forensics
Candidates investigate a simulated cybersecurity incident, preserve evidence, construct a timeline, and recommend containment and recovery.
Deliverable: Incident Investigation and Response Report.
Lab 5: Enterprise Cybersecurity Risk and Defense Assessment
Candidates conduct an integrated cybersecurity review involving assets, threats, vulnerabilities, cloud, access, monitoring, governance, and emerging risks.
Deliverable: Executive Cybersecurity Assessment and Improvement Plan.
Assessment
Flexible CICSP® Certification Assessment Options
The CICSP® certification provides two assessment pathways for candidates to demonstrate professional cybersecurity competency. Candidates complete either the Certification Examination or, where eligible, the Applied Cybersecurity Capstone.
Option 1
Option 1 — CICSP® Certification Examination
The examination evaluates cybersecurity knowledge, application, analytical reasoning, and professional judgment across the eight CICSP® competency domains.
The examination emphasizes the candidate's ability to apply cybersecurity concepts to realistic technical and organizational scenarios.
Questions: 100
Question Types: Multiple-choice and scenario-based multiple-choice
Duration: 90 minutes
Format: Closed book
Delivery: Secure online proctoring or approved testing center
Passing Score: 70%
Option 2
Certification Examination
Best suited for candidates seeking to demonstrate competency through a structured, proctored assessment.
OR
Option 3
Applied Cybersecurity Capstone
Best suited for eligible instructor-led candidates seeking to demonstrate competency through practical cybersecurity analysis and professional application.
Both pathways assess competency against the CICSP® Body of Knowledge and certification requirements.
CICSP®
Option 2 — CICSP® Applied Cybersecurity Capstone
Eligible candidates participating in an approved instructor-led program may demonstrate competency through the CICSP® Applied Cybersecurity Capstone.
The Capstone consists of three integrated parts:
01 / 03
Part 1 — Cybersecurity Risk and Environment Assessment
Certification Validity · 3 Years · Professional Designation
Certification Validity
The recommended CICSP® certification cycle is:
3 Years
Recommended recertification requirement:
Professional Designation
Successful candidates earn:
Cybersecurity
Standards and International Framework Alignment
The CICSP® Body of Knowledge is aligned with internationally recognized cybersecurity, risk, privacy, AI, workforce, and professional certification frameworks. These references strengthen the certification's focus on practical, risk-based, and globally relevant cybersecurity competency.
Key standards and frameworks include:
ISO/IEC 17024 — Personnel certification and competency principles
ISO/IEC 27001 & 27002 — Information security management and security controls
ISO/IEC 27005 — Information security risk management
ISO/IEC 27701 — Privacy information management
ISO 31000 — Enterprise risk-management principles
ISO/IEC 42001 — AI management systems and governance
ISO/IEC 23894 — AI risk-management guidance
NIST Cybersecurity Framework (CSF) — Cybersecurity risk management and resilience
Recognized Industry Practices — Secure development, cloud security, incident response, software supply-chain security, and cyber resilience
Practical Standards Application
CICSP® does not emphasize memorization of standards. Candidates develop the ability to understand how and when recognized frameworks apply to real cybersecurity environments.
This enables CICSP® professionals to connect internationally recognized cybersecurity practices with technical controls, cyber risk, organizational requirements, incident response, governance, and resilience.
Framework alignment does not constitute accreditation, certification, endorsement, or approval by the organizations responsible for these standards and frameworks.
Cybersecurity
Global and Vendor-Neutral Design
The CICSP® certification is built around globally transferable cybersecurity knowledge, skills, and professional competencies rather than any single technology vendor or product ecosystem.
CICSP® is independent of any specific:
This vendor-neutral approach enables CICSP® professionals to apply cybersecurity principles across different technologies, organizations, industries, architectures, and operating environments.
Firewall or network-security vendor
SIEM or SOC platform
Cloud-service provider
Endpoint-security technology
Operating system
Network manufacturer
Cybersecurity product or proprietary solution
One Professional Framework. Multiple Technologies. Transferable Cybersecurity Competency.
Cybersecurity
Accreditation and Credentialing Quality Alignment
The CICSP® certification framework is structured around internationally recognized principles for professional certification, competency assessment, examination quality, and credential governance.
Its design reflects relevant credentialing principles associated with:
ISO/IEC 17024 — Certification of persons
ANSI National Accreditation Board (ANAB) — Personnel-certification accreditation practices
National Commission for Certifying Agencies (NCCA) — Certification program quality standards
Institute for Credentialing Excellence (I.C.E.) — Professional credentialing practices
International personnel-certification and conformity-assessment principles
CICSP® Quality Lifecycle
CICSP® Credentialing Quality Framework
The CICSP® certification lifecycle incorporates:
Job Task Analysis • Defined Competencies • Eligibility Requirements • Validated Body of Knowledge • Examination Blueprint • Subject Matter Expert (SME) Validation • Psychometric Principles • Examination Security • Candidate Identity Verification • Impartial Certification Decisions • Appeals and Complaints • Professional Ethics • Continuing Professional Education • Recertification • Credential Verification • Periodic Review • Continuous Improvement
This structured approach supports the validity, reliability, fairness, integrity, relevance, security, and continuing professional value of the CICSP® credential.
Commitment to International Credentialing Quality
IBACTP® positions CICSP® as a competency-based professional certification built around rigorous assessment, transparent credentialing requirements, continuing professional competence, and continuous program improvement.
The objective is to maintain a certification framework capable of supporting professional credibility, employer confidence, international portability, and long-term credential value.
Accreditation Disclosure
Alignment is not accreditation.
IBACTP® represents CICSP® as formally accredited, recognized, approved, or endorsed by an external organization only after such status has been officially awarded by the applicable authorized body.
CICSP®
CICSP®
CICSM® Certification Pathway
Professional Level
CICSP®
Choose Your Path to CICSP®
Learn → Prepare → Demonstrate Competency → Earn the Credential → Maintain Professional Excellence
Protect Digital Systems. Detect Cyber Threats. Respond with Confidence. Build Cyber Resilience.
Become a Certified International Cybersecurity Professional
APPLY NOW | REGISTER FOR THE EXAM | ENROLL IN TRAINING | EXPLORE THE CAPSTONE
CICSP®
The CICSP® Professional Advantage
CICSP® brings together competencies that are frequently treated as separate cybersecurity disciplines:
Protect
Secure identities, data, applications, endpoints, networks, infrastructure, and cloud environments.
Detect
Recognize malicious activity through monitoring, security analytics, threat intelligence, and cyber-defense capabilities.
Analyze
Evaluate vulnerabilities, alerts, attack activity, evidence, and organizational cyber risk.
Respond
Support effective containment, investigation, eradication, communication, and incident management.
Recover
Restore secure operations and strengthen organizational resilience following cyber disruption.
Govern
Connect cybersecurity with risk, compliance, privacy, policies, ethics, accountability, and organizational objectives.
Improve
Apply assessments, threat intelligence, metrics, lessons learned, emerging technologies, and professional development to continuously strengthen security.
CICSP®
What CICSP® Represents
The CICSP® designation represents an integrated cybersecurity professional capable of connecting:
For professionals seeking to move beyond isolated cybersecurity skills and develop a broader understanding of how modern organizations defend their digital environments, CICSP® provides a structured pathway toward comprehensive cybersecurity competency.
Build the Knowledge. Apply the Skills. Demonstrate the Competency. Earn CICSP®.
CICSP®
CICSP® Certification Value Proposition
CICSP® integrates:
CICSP® Professional Value Chain
Security Architecture + Network Defense + IAM + Data Security + Cloud Security + Vulnerability Management + SOC Operations + Threat Intelligence + Incident Response + Digital Forensics + GRC + AI Security
Unlike credentials that focus on one technology or vendor, CICSP® combines technical security, cyber defense, incident response, governance, risk, and emerging technology security into one comprehensive professional certification.
AI Security, Emerging Technologies & Continuous Cybersecurity Improvement
CICSP®
CICSP® Professional Competency Objective
The ultimate objective of the CICSP®–IBACTP® Cybersecurity Professional Competency Model is to develop and validate professionals capable of transforming cybersecurity knowledge into effective organizational protection:
Knowledge
Security Controls
Detection
Analysis
Response
Recovery
Governance
Resilience
The CICSP® professional applies this integrated competency to help organizations:
Together, the 8 modules and 32 submodules provide an integrated professional cybersecurity curriculum spanning technical security, cyber defense, incident response, governance, risk, resilience, and emerging technology security.
CICSP®
60-Hour Professional Certification Program
Module
Cybersecurity Foundations & Architecture
Network, Infrastructure & Endpoint Security
Identity, Data, Application & Cloud Security
Vulnerability, Threat & Risk Assessment
Security Operations & Cyber Defense
Incident Response, Forensics & Resilience
Governance, Risk, Compliance & Privacy
AI Security, Emerging Technologies & Practice
Total
CICSP®
AI Security and Emerging Technology Focus
CICSP® recognizes that Artificial Intelligence is creating both new cybersecurity capabilities and new cybersecurity risks.
Candidates study security implications involving:
Here is a more concise, polished version suitable for the CICSP® landing page while retaining the important credentialing language.
AI systems
Generative AI
Prompt injection
Sensitive-data exposure
AI-assisted cyberattacks
AI-assisted defense
Model and application vulnerabilities
AI access controls
AI supply-chain risk
Human oversight
AI incident management
Cloud-native technologies
IoT
OT
DevSecOps
Containers
Software supply chains
Emerging threats
CICSP®
Certified International Cybersecurity Professional (CICSP®)
Example:
Jane Smith, CICSP®
The designation represents professional competency across modern cybersecurity protection, detection, analysis, incident response, governance, risk, and resilience.
CICSP®
CICSP®
Certified International Cybersecurity Professional
Certified International Cybersecurity Professional (CICSP®)
Credential holders may use the CICSP® designation in accordance with applicable IBACTP® credential-use policies.
Example:
Jane Smith, CICSP®
Professional Level
Is CICSP® aligned with recognized cybersecurity frameworks?
The CICSP® Body of Knowledge incorporates relevant principles from internationally recognized standards and frameworks, including ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27701, ISO 31000, ISO/IEC 42001, ISO/IEC 23894, the NIST Cybersecurity Framework, NIST NICE Workforce Framework, NIST AI RMF, and relevant CISA and NIST cybersecurity guidance.
These frameworks are addressed through practical cybersecurity application rather than simple memorization.
Is CICSP® accredited by ANAB or NCCA?
Reference to credentialing principles associated with ISO/IEC 17024, ANAB, NCCA, I.C.E., or international conformity-assessment practices does not by itself constitute accreditation, recognition, approval, or endorsement.
IBACTP® represents CICSP® as formally accredited or recognized by an external organization only after such status has been officially awarded by the applicable authorized body.
Is CICSP® internationally applicable?
CICSP® is designed as a vendor-neutral and internationally applicable professional cybersecurity certification.
Its competency framework focuses on cybersecurity principles and professional practices that can be applied across industries, technologies, and organizational environments.
Acceptance of any professional credential remains subject to individual employer, regulatory, governmental, institutional, and jurisdictional requirements.
How long is the CICSP® certification valid?
The recommended CICSP® certification cycle is three years, subject to applicable IBACTP® certification and recertification policies.
Credential holders maintain professional competency through applicable Continuing Professional Education (CPE) and recertification requirements.
What career areas can CICSP® support?
CICSP® can support professional development in areas such as:
Take the next step toward earning the Certified International Cybersecurity Professional (CICSP®) designation and demonstrating practical competency across the modern cybersecurity lifecycle.
Whether you are beginning your certification journey, preparing for the examination, enrolling in instructor-led training, or selecting the applied Capstone pathway, choose the option that best matches your professional goals.
Apply for CICSP® Certification
Ready to begin your certification process?
Start your application and review the current eligibility, assessment, and credentialing requirements for the Certified International Cybersecurity Professional (CICSP®) designation.
APPLY FOR CERTIFICATION →
Register for the CICSP® Certification Examination
Already prepared to demonstrate your cybersecurity competency?
Register for the CICSP® Certification Examination and validate your knowledge and professional judgment across the eight CICSP® cybersecurity domains.
REGISTER FOR THE CICSP® EXAM →
Enroll in CICSP® Training
Build the knowledge and applied skills required for professional cybersecurity practice.
CICSP® training develops competency across:
ENROLL IN CICSP® TRAINING →
Cybersecurity foundations and architecture
Network and infrastructure defense
Identity, data, application, and cloud security
Vulnerability and threat management
Security operations and cyber defense
Incident response and digital forensics
Governance, risk, compliance, and privacy
AI security and emerging technologies
Choose the Applied Cybersecurity Capstone Pathway
Prefer an applied, project-based assessment experience?
Eligible candidates participating through an approved instructor-led pathway may demonstrate competency through the CICSP® Applied Cybersecurity Capstone.
Find answers to common questions about the Certified International Cybersecurity Professional (CICSP®) certification, including eligibility, curriculum, assessment, training, cybersecurity domains, and professional progression.
What is the CICSP® certification?
The Certified International Cybersecurity Professional (CICSP®) is a comprehensive, vendor-neutral professional certification designed to validate practical cybersecurity knowledge, applied technical competency, analytical judgment, risk awareness, and professional decision-making.
CICSP® covers the modern cybersecurity lifecycle, including security architecture, network and endpoint defense, IAM, data and application security, cloud security, vulnerability management, SOC operations, threat intelligence, incident response, digital forensics, governance, risk, compliance, privacy, AI security, and emerging technologies.
Who is CICSP® designed for?
CICSP® is designed for current and aspiring cybersecurity and technology professionals, including cybersecurity analysts, SOC analysts, network and systems professionals, cloud professionals, security administrators, incident-response personnel, GRC professionals, IT auditors, consultants, and individuals transitioning into cybersecurity.
It can also provide a structured professional pathway for qualified students and graduates seeking broader cybersecurity competency.
Is CICSP® vendor-neutral?
Yes. CICSP® is not tied to a specific cybersecurity vendor, firewall, SIEM platform, cloud provider, operating system, endpoint solution, or network manufacturer.
The certification focuses on transferable cybersecurity principles and professional competencies that can be applied across different technologies and organizational environments.
Do I need previous cybersecurity experience?
Advanced cybersecurity experience is not required to begin CICSP® training.
Candidates benefit from foundational familiarity with computer systems, operating systems, networking, TCP/IP, cloud computing, user accounts, access controls, and basic cybersecurity concepts.
Professional IT, networking, systems administration, technical support, cloud, programming, audit, risk, or related technology experience can also be beneficial.
Does CICSP® cover network and infrastructure security?
Yes. Network and infrastructure security are major components of the CICSP® curriculum.
Topics include network architecture, segmentation, TCP/IP security, ports and protocols, firewalls, IDS/IPS, secure communications, wireless security, remote access, system hardening, endpoint protection, patching, configuration management, and infrastructure defense.
Does CICSP® cover cloud security?
Yes. CICSP® addresses cloud-security principles within modern enterprise environments.
Candidates learn about cloud architectures, shared-responsibility models, cloud identity and access management, configuration security, data protection, workloads, APIs, monitoring, and cloud-related cybersecurity risks.
Because CICSP® is vendor-neutral, these concepts are designed to remain applicable across different cloud platforms.
Does CICSP® cover Identity and Access Management (IAM)?
The program covers authentication, authorization, Multi-Factor Authentication (MFA), Single Sign-On (SSO), federation, Role-Based Access Control (RBAC), identity lifecycle management, Privileged Access Management (PAM), least privilege, and Zero Trust access principles.
Yes. Identity security is a core CICSP® competency.
Does CICSP® cover vulnerability management?
Yes. Candidates learn how to identify vulnerabilities, interpret assessment findings, evaluate exposure, consider asset criticality and business impact, prioritize remediation, apply compensating controls, and support continuous vulnerability-management programs.
The emphasis is on converting technical findings into risk-informed remediation decisions.
Does CICSP® cover SOC operations and cyber defense?
Yes. Security operations and cyber defense form a major CICSP® competency domain.
Candidates study SOC functions, SIEM concepts, security monitoring, logs, endpoint telemetry, alert triage, Indicators of Compromise (IOCs), threat intelligence, threat hunting, event correlation, escalation, and defensive-security operations.
Does CICSP® cover threat intelligence?
Yes. CICSP® introduces candidates to threat actors, attack techniques, Indicators of Compromise, threat intelligence sources, threat analysis, attack patterns, and the application of threat information to monitoring, vulnerability management, risk assessment, and cyber defense.
Does CICSP® cover incident response?
Yes. Incident response is an essential component of the certification.
Yes. CICSP® includes practical digital-forensics concepts relevant to cybersecurity professionals.
Topics include digital evidence, evidence preservation, chain of custody, forensic readiness, investigation procedures, incident timelines, and basic endpoint, network, log, and cloud evidence.
The focus is on enabling cybersecurity professionals to appropriately support investigations and preserve the integrity of potential evidence.
Does CICSP® cover governance, risk, and compliance?
Yes. CICSP® connects technical cybersecurity with organizational governance and enterprise risk.
Candidates study cybersecurity policies, security governance, risk assessment, control frameworks, privacy, compliance, audit, third-party security, supply-chain risk, professional ethics, accountability, and continuous improvement.
Does CICSP® cover AI and Generative AI security?
Yes. AI security is an integrated component of the CICSP® Body of Knowledge.
AI Security, Emerging Technologies & Professional Practice
How long is CICSP® training?
The recommended CICSP® instructor-led program is approximately 60 instructional hours.
Training duration and delivery schedules can vary depending on the approved training provider, delivery format, laboratory activities, and candidate pathway.
How is CICSP® assessed?
CICSP® provides flexible assessment options.
Option 1 — CICSP® Certification Examination
The recommended examination structure includes:
100 questions
Multiple-choice and scenario-based questions
90-minute duration
Closed-book format
Secure online proctoring or approved testing center
70% recommended passing score
Option 2 — CICSP® Applied Cybersecurity Capstone
Eligible candidates participating through an approved instructor-led pathway may demonstrate competency through a structured three-part applied cybersecurity Capstone.
What does the CICSP® examination test?
The examination evaluates more than cybersecurity terminology.
Candidates are assessed on their ability to demonstrate: