CISSP - Solomon People Solutions

Certified in Cybersecurity (CC)

Build a Strong Foundation in Cybersecurity

The Certified in Cybersecurity (CC) certification is a globally recognized credential that validates an individual’s understanding of cybersecurity principles, best practices, and essential security concepts. It is designed for professionals who want to build or strengthen their cybersecurity knowledge.

Why Earn the CC Certification?

The CC certification demonstrates that you have the skills and knowledge needed to help protect systems, networks, and data from cyber threats. In addition, it shows employers that you understand core cybersecurity practices and can contribute to maintaining a secure organizational environment. As a result, the certification serves as an excellent starting point for a career in cybersecurity or as a way to enhance your existing IT expertise.

The Certified in Cybersecurity (CC) certification demonstrates to employers that you have the foundational knowledge, skills, and abilities required for an entry-level or junior cybersecurity role. Furthermore, it validates your understanding of essential security best practices, policies, and procedures. As a result, employers can recognize your readiness to contribute to cybersecurity initiatives while continuing to develop your expertise on the job.

Certification Domains

The CC certification exam covers five key domains:

  • Security Principles
  • Business Continuity (BC), Disaster Recovery (DR), and Incident Response Concepts
  • Access Control Concepts
  • Network Security
  • Security Operations

Who Should Attend?

The Certified in Cybersecurity (CC) certification is ideal for professionals who want to build or strengthen their cybersecurity knowledge, including:

  • Chief Information Security Officer (CISO)
  • Chief Information Officer (CIO)
  • Director of Security
  • IT Director or IT Manager
  • Security Systems Engineer
  • Security Analyst
  • Security Manager
  • Security Auditor
  • Security Architect
  • Security Consultant
  • Network Architect

Prerequisites

There are no formal prerequisites to take the Certified in Cybersecurity (CC) exam. However, having a basic understanding of information technology (IT) is recommended, as it will help you better understand the course material.

In addition, no prior cybersecurity work experience or formal diploma or degree is required. After earning the CC certification, candidates can continue developing their expertise by pursuing advanced ISC2 certifications, which require professional experience in the cybersecurity field.

Exam Information 

Exam Name Certified in Cybersecurity (CC)
Exam Type Multiple-choice Questions
Total Questions 100
Exam Duration 2 Hours
Passing Score 700 out of 1000
Languages  English, Chinese, Japanese, Korean, German, Spanish
Testing center Pearson VUE Testing Center
Course Duration : 12 Hours
Course Syllabus

Domain 1: Security Principles

This domain introduces the fundamental concepts of cybersecurity and information assurance. Participants will learn how organizations protect sensitive information, manage security risks, and establish effective security practices. Additionally, this domain provides the foundation needed to understand how security principles support overall business protection.

Understanding Information Assurance Concepts

Information assurance focuses on protecting information and ensuring that data remains secure, accurate, and accessible. Therefore, participants will explore key security concepts, including:

  • Confidentiality: Protecting information from unauthorized access or disclosure.
  • Integrity: Ensuring information remains accurate, complete, and protected from unauthorized changes.
  • Availability: Ensuring systems and data are accessible when needed.
  • Authentication: Understanding methods of verifying user identities, including Multi-Factor Authentication (MFA).
  • Non-repudiation: Ensuring that actions or transactions cannot be denied after completion.
  • Privacy: Protecting personal and sensitive information from misuse.

Understanding the Risk Management Process

Effective risk management helps organizations identify and address potential security threats. Furthermore, participants will learn how to evaluate risks and apply appropriate strategies to reduce their impact.

Key topics include:

  • Risk management principles, including risk priorities and risk tolerance
  • Risk identification, assessment, and treatment processes

Understanding Security Controls

Security controls are essential measures used to protect systems, networks, and information. In addition, participants will understand the different types of controls organizations use to strengthen cybersecurity.

These include:

  • Technical Controls: Security technologies and solutions used to protect systems and data.
  • Administrative Controls: Policies, procedures, and guidelines that support secure operations.
  • Physical Controls: Measures used to protect physical assets and facilities.

Understanding the ISC2 Code of Ethics

Cybersecurity professionals must follow ethical standards when protecting information and supporting organizations. As a result, participants will learn about the ISC2 Code of Ethics and the importance of maintaining professional conduct.

Understanding Governance Processes

Cybersecurity governance provides the structure needed to manage security effectively. Therefore, participants will explore key governance elements, including:

  • Policies
  • Procedures
  • Standards
  • Regulations and laws

Together, these concepts help organizations create a secure environment while ensuring compliance with industry and legal requirements.

Domain 2: Business Continuity, Disaster Recovery, and Incident Response

This domain focuses on how organizations prepare for, manage, and recover from unexpected disruptions that may impact business operations. Additionally, participants will understand how resilience planning helps reduce risks, maintain critical services, and minimize the effects of security incidents.

Understanding Business Continuity (BC)

Business Continuity (BC) ensures that organizations can continue essential operations during disruptions. Therefore, participants will learn how BC planning helps businesses maintain stability and recover effectively from unexpected events.

Key areas include:

  • Purpose: Understanding the goals of business continuity planning.
  • Importance: Recognizing how BC supports operational resilience and reduces downtime.
  • Key Components: Exploring the essential elements required for effective continuity planning.

Understanding Disaster Recovery (DR)

Disaster Recovery (DR) focuses on restoring systems, applications, and data after a major disruption. Furthermore, participants will learn how DR strategies help organizations recover technology resources and return to normal operations.

Key areas include:

  • Purpose: Understanding the objectives of disaster recovery planning.
  • Importance: Recognizing the role of DR in minimizing data loss and operational impact.
  • Key Components: Exploring the processes and resources required for successful recovery.

Understanding Incident Response

Incident Response involves the structured approach organizations use to identify, manage, and resolve cybersecurity incidents. In addition, participants will learn how effective response procedures help limit damage and improve future security readiness.

Key areas include:

  • Purpose: Understanding why organizations need incident response plans.
  • Importance: Recognizing how quick and effective responses reduce security risks.
  • Key Components: Exploring the stages and elements involved in incident management.

By understanding business continuity, disaster recovery, and incident response, participants can better support organizations in preparing for challenges and maintaining secure, reliable operations.

Domain 3: Access Controls Concepts

This domain explains how organizations protect systems, facilities, and information by controlling access to authorized individuals. Additionally, participants will learn how access control measures help prevent unauthorized access, reduce security risks, and support effective cybersecurity practices.

Understanding Physical Access Controls

Physical access controls protect an organization’s buildings, equipment, and other physical assets from unauthorized access. Therefore, participants will explore the different methods used to secure facilities and monitor physical environments.

Key areas include:

  • Physical Security Controls: Understanding measures such as badge systems, gate entry systems, and environmental design that help restrict access.
  • Monitoring: Exploring security monitoring methods, including security guards, Closed-Circuit Television (CCTV), alarm systems, and access logs.
  • Authorized vs. Unauthorized Personnel: Recognizing the importance of verifying identities and ensuring only approved individuals can access restricted areas.

Understanding Logical Access Controls

Logical access controls protect digital resources, including systems, applications, and data. Furthermore, participants will learn how organizations manage user permissions and apply access control principles to maintain security.

Key areas include:

  • Principle of Least Privilege: Ensuring users receive only the minimum access required to perform their responsibilities.
  • Segregation of Duties: Separating critical tasks among multiple individuals to reduce the risk of errors or misuse.
  • Discretionary Access Control (DAC): Understanding access decisions based on user or resource owner permissions.
  • Mandatory Access Control (MAC): Exploring access restrictions based on predefined security policies and classifications.
  • Role-Based Access Control (RBAC): Managing permissions according to job roles and responsibilities.

By understanding physical and logical access controls, participants can help organizations establish stronger security measures and protect valuable assets from unauthorized access.

Domain 4: Network Security

This domain introduces the fundamentals of network security and explains how organizations protect their communication systems, applications, and digital infrastructure. Additionally, participants will learn how networks operate, the common threats they face, and the security measures used to maintain a safe and reliable environment.

Understanding Computer Networking

Computer networks allow devices and systems to communicate and share resources. Therefore, participants will explore key networking concepts and technologies that support modern digital environments.

Key areas include:

  • Networks: Understanding networking models and technologies, including the Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), and WiFi.
  • Ports: Learning how ports enable communication between applications and network services.
  • Applications: Understanding how applications use networks to exchange information and provide services.

Understanding Network Threats and Attacks

Networks face various cybersecurity threats that can impact confidentiality, integrity, and availability. Furthermore, participants will learn how to identify, prevent, and respond to common network attacks.

Key areas include:

  • Types of Threats: Understanding attacks such as Distributed Denial-of-Service (DDoS), viruses, worms, Trojans, Man-in-the-Middle (MITM) attacks, and side-channel attacks.
  • Identification: Exploring detection methods, including Intrusion Detection Systems (IDS), Host-Based Intrusion Detection Systems (HIDS), and Network Intrusion Detection Systems (NIDS).
  • Prevention: Learning about protective measures such as antivirus solutions, security scans, firewalls, and Intrusion Prevention Systems (IPS).

Understanding Network Security Infrastructure

Network security infrastructure provides the foundation for protecting organizational systems and data. In addition, participants will explore how organizations design and manage secure network environments.

Key areas include:

  • On-Premises Infrastructure: Understanding physical requirements such as power, data centers, heating, ventilation and air conditioning (HVAC), environmental controls, fire suppression, redundancy, and Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA).
  • Network Design: Exploring security approaches such as network segmentation, Demilitarized Zones (DMZ), Virtual Local Area Networks (VLAN), Virtual Private Networks (VPN), micro-segmentation, defense in depth, and Network Access Control (NAC).
  • Cloud Infrastructure: Understanding cloud service models and agreements, including Service-Level Agreements (SLA), Managed Service Providers (MSP), Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and hybrid environments.

By understanding network security concepts, participants can better support organizations in protecting digital infrastructure and reducing cybersecurity risks.

Domain 5: Security Operations

This domain focuses on the daily practices and processes used to protect organizational systems, data, and users. Additionally, participants will learn how security operations support data protection, system reliability, policy compliance, and overall cybersecurity awareness.

Understanding Data Security

Data security involves protecting information from unauthorized access, loss, or misuse. Therefore, participants will explore methods used to secure, manage, and monitor organizational data.

Key areas include:

  • Encryption: Understanding security methods such as symmetric encryption, asymmetric encryption, and hashing to protect sensitive information.
  • Data Handling: Learning best practices for data destruction, retention, classification, and labeling.
  • Logging and Monitoring Security Events: Understanding how organizations track and analyze security activities to identify potential risks.

Understanding System Hardening

System hardening strengthens security by reducing vulnerabilities and improving system protection. Furthermore, participants will learn how proper configuration management helps maintain secure technology environments.

Key areas include:

  • Configuration Management: Understanding security practices such as establishing baselines, applying updates, and managing patches.

Understanding Best Practice Security Policies

Security policies provide guidelines for protecting information and ensuring consistent security practices across an organization. In addition, participants will explore common policies that support effective cybersecurity management.

Key areas include:

  • Data Handling Policy: Defining how information should be accessed, stored, and protected.
  • Password Policy: Establishing requirements for secure password creation and management.
  • Acceptable Use Policy (AUP): Setting rules for appropriate use of organizational systems and resources.
  • Bring Your Own Device (BYOD) Policy: Managing security requirements for personal devices used for work purposes.
  • Change Management Policy: Understanding documentation, approval processes, and rollback procedures for system changes.
  • Privacy Policy: Defining how personal and sensitive information is collected, used, and protected.

Understanding Security Awareness Training

Security awareness training helps employees recognize and respond to cybersecurity risks. As a result, organizations can reduce human-related security threats and promote a stronger security culture.

Key areas include:

  • Purpose and Concepts: Understanding topics such as social engineering, phishing awareness, and password protection.
  • Importance: Recognizing how employee awareness contributes to protecting organizational systems and information.

By understanding security operations, participants can support stronger cybersecurity practices and help organizations maintain a secure digital environment.

  • Career Advancement: Boost your credibility and open doors to lucrative job opportunities in the rapidly growing field of cybersecurity.
  • Skill Validation: Demonstrate your expertise and proficiency in safeguarding digital assets, enhancing your professional reputation.
  • Industry Recognition: Gain recognition from employers, clients, and peers as a trusted cybersecurity professional with a certified skill set.
  • Stay Ahead of Threats: Stay updated with the latest security trends, techniques, and best practices, equipping you to tackle evolving cyber threats effectively.
  • Networking Opportunities: Connect with a vibrant community of cybersecurity experts, fostering collaboration, knowledge sharing, and career growth.

Up-coming Schedule: 

Please contact us to know about the upcoming schedule.