Skip to main content
Institute of Advanced Technological and Commercial Studies

Careers

Chief information security officer

Identifying what must be protected, deciding the level of protection, organising detection and preparing the response: the chief information security officer builds their organisation's digital resilience.

Protecting what actually matters

The function starts with an inventory: which data, which services, what value, what consequence if unavailable. The security policy follows from it, proportionate rather than uniform. Detection and response are then organised — logs collected, alerts qualified, an incident procedure rehearsed before it is needed. Awareness across teams holds a decisive place, because most intrusions come through an ordinary human action.

  • Map sensitive assets and run a risk analysis
  • Build a proportionate security policy and have it applied
  • Organise detection, qualify an alert, run a response
  • Raise team awareness and demonstrate compliance to third parties

Exposed organisations

  • Banks, payment operators and microfinance institutions
  • Telecom operators and internet service providers
  • Administrations holding citizen data
  • Mining and industrial groups with connected production systems
  • Digital platforms and IT services companies

What the official catalogue states

These values are not estimates: they are the very definition of the programme in the filed document. Any change goes through a catalogue update, hence through a formal decision. That is what allows a figure announced today to be found unchanged on enrolment day, then on award day.

Expert and executive

qualification level
7
months of programme
9

Led by an instructor.

taught hours
700 h

1 credit = 25 h of work, 10 of them taught.

credits
70

Framework of the « Chief Information Security Officer » qualification, code TP30.

competency blocks
5

The learning the qualification attests

The qualification attests these blocks, and it names them. A recruiter reading an application can therefore know precisely what the holder demonstrated, rather than infer it from a title. The hours shown for each block complete the picture: they state how long the skill was practised with an instructor present.

  1. 01

    Security strategy and governance

    Policy, risk analysis, frameworks, committees, budget, cyber insurance — 190 taught hours.

  2. 02

    Architecture and technical control

    Defence in depth, identities, segmentation, cloud and agent security — 180 taught hours.

  3. 03

    Detection, response and crisis

    Security operations centre, incident response, forensics, crisis management, notification — 180 taught hours.

  4. 04

    Compliance, third parties and awareness

    Compliance, data protection, supplier security, security culture — 100 taught hours.

  5. 05

    Executive conduct

    Reporting to the board, arbitrating security against business, raising alarms — 50 taught hours.

Building a security profile

Entry into this occupation runs through one or more of these programmes. They combine: a short certificate opens the door, a longer programme consolidates the position a few years later. The fees shown match the real billing unit — per year for a long programme, one-off for a short format.

ProgrammeDurationCreditsTaught hoursFees
Cybersecurity programme — Bac+5 level · Master's degree2 years1201200 h7 500 000 GNF per year
Digital Transformation Certificate · Professional certification6 months18180 h3 600 000 GNF in total

Three questions, three precise answers

Do I need a systems administration background?

It is the most solid route: you protect best what you have built. The Bac+5 cybersecurity programme opens the other way in, installing risk analysis, offensive and defensive security and the applicable regulatory framework.

Is the function technical or managerial?

It is both, and level 7 recognises precisely that articulation: understanding a vulnerability in depth, then translating it into a quantified business risk before an executive committee that decides the budget.

What does incident response cover?

Detection, qualification, containment, restoration, then post-incident analysis and the measures that prevent recurrence. The framework exercises the whole chain on realistic scenarios, because a rehearsed procedure is the only one that holds on the day.

Chief information security officer — Careers | IHETC — IHETC