Skills
Running a penetration test and reporting it
Penetration testing assesses a defence by exercising it, within an authorised and documented scope. Reconnaissance, exploitation, privilege escalation, then a prioritised report: this is the skill that turns vague worry into a costed remediation plan.
Testing a defence, then explaining it
A penetration test is judged by its report as much as by its findings. A chief executive reads a ranking of risks, a cost of remediation and a deadline; an administrator reads the exact reproduction of the flaw. Writing both is half the job. The other half is the framing: written scope, signed authorisation, intervention window, data preservation. The programme teaches both, because a test conducted outside its scope commits whoever runs it.
- Frame an engagement: written scope, authorisation, intervention window
- Map an exposed attack surface and rank the entry points
- Reproduce an exploit and measure its real impact
- Write a report readable by both the board and the technical teams
Where you practise it
Each block combines input, workshop and assessed output. The year shown tells you when in the programme the skill actually comes into play.
| Teaching block | Programme | Taught hours | Year |
|---|---|---|---|
| Penetration testing | Cybersecurity programme — Bac+5 level | 220 h | Year 2 |
| Application security | Cybersecurity programme — Bac+5 level | 120 h | Year 1 |
| Security fundamentals | Cybersecurity programme — Bac+5 level | 220 h | Year 1 |
Your level of command, stated plainly
You run a full penetration test under written mandate and deliver a prioritised remediation plan from it. A skill is best stated by what it lets you carry out on your own, on completion.
- teaching blocks
- 3
- of taught instruction
- 560 h
- credits in total
- 56
- professional qualifications concerned
- 2
Catalogue rule: one credit is twenty-five hours of work, ten of them taught.
The programmes that teach it
Durations, levels and real fees, read from the official catalogue when this site is built.
| Programme | Level | Duration | Fees |
|---|---|---|---|
| Cybersecurity programme — Bac+5 level | Master's degree | 2 years | 7 500 000 GNF per year |
The frameworks that carry it
The framework lists the blocks to be validated. This skill appears there as a professional requirement.
| Professional qualification | Target occupation | Level | Taught volume |
|---|---|---|---|
| Chief Information Security Officer | CISO | 7 · Expert and executive | 700 h |
| Enterprise Architect | IS architect | 7 · Expert and executive | 700 h |
Before you decide
Is the legal framework covered during the training?
It opens the block: written authorisation from the client, scope, confidentiality of findings and the fate of collected data. That is what makes the exercise professional.
What do the practical exercises run against?
Against dedicated laboratory environments reproducing complete enterprise architectures, with their network equipment and their applications.
Does this skill lead to a specific role?
It forms one block of the information systems security manager qualification, at level 7, prepared over 700 taught hours.
Explore next
- Application securityApplication security at IHETC: vulnerability families, authentication, permissions, secrets and secure code review. Blocks, taught hours and target roles.
- Digital forensicsDigital forensics at IHETC: trace preservation, timeline reconstruction, log analysis and a defensible incident report. 180 taught hours in cybersecurity.
- Data governanceData governance at IHETC: ownership, access rights, retention periods, sovereignty and compliance. Teaching blocks, taught hours and roles.
- Security managementInformation security management at IHETC: governance, risk, compliance and standards frameworks. Taught hours, programmes and target qualifications.
- Framing AI use casesFraming artificial intelligence use cases at IHETC: identification, expected value, available data, governance and adoption. Blocks and target roles.
- User researchUser research at IHETC: interviews, observation, usability testing and reporting. 200 taught hours in user experience design.