Skip to main content
IHETC School

Careers

Chief information security officer

Identifying what must be protected, deciding the level of protection, organising detection and preparing the response: the chief information security officer builds their organisation's digital resilience.

Protecting what actually matters

The function starts with an inventory: which data, which services, what value, what consequence if unavailable. The security policy follows from it, proportionate rather than uniform. Detection and response are then organised — logs collected, alerts qualified, an incident procedure rehearsed before it is needed. Awareness across teams holds a decisive place, because most intrusions come through an ordinary human action.

  • Map sensitive assets and run a risk analysis
  • Build a proportionate security policy and have it applied
  • Organise detection, qualify an alert, run a response
  • Raise team awareness and demonstrate compliance to third parties

Exposed organisations

  • Banks, payment operators and microfinance institutions
  • Telecom operators and internet service providers
  • Administrations holding citizen data
  • Mining and industrial groups with connected production systems
  • Digital platforms and IT services companies

What the official catalogue states

These values are not estimates: they are the very definition of the programme in the filed document. Any change goes through a catalogue update, hence through a formal decision. That is what allows a figure announced today to be found unchanged on enrolment day, then on award day.

Expert and executive

qualification level
7
months of programme
9

Led by an instructor.

taught hours
700 h

1 credit = 25 h of work, 10 of them taught.

credits
70

Framework of the « Chief Information Security Officer » qualification, code TP30.

competency blocks
5

The learning the qualification attests

The qualification attests these blocks, and it names them. A recruiter reading an application can therefore know precisely what the holder demonstrated, rather than infer it from a title. The hours shown for each block complete the picture: they state how long the skill was practised with an instructor present.

  1. 01

    Security strategy and governance

    Policy, risk analysis, frameworks, committees, budget, cyber insurance — 190 taught hours.

  2. 02

    Architecture and technical control

    Defence in depth, identities, segmentation, cloud and agent security — 180 taught hours.

  3. 03

    Detection, response and crisis

    Security operations centre, incident response, forensics, crisis management, notification — 180 taught hours.

  4. 04

    Compliance, third parties and awareness

    Compliance, data protection, supplier security, security culture — 100 taught hours.

  5. 05

    Executive conduct

    Reporting to the board, arbitrating security against business, raising alarms — 50 taught hours.

Building a security profile

Entry into this occupation runs through one or more of these programmes. They combine: a short certificate opens the door, a longer programme consolidates the position a few years later. The fees shown match the real billing unit — per year for a long programme, one-off for a short format.

ProgrammeDurationCreditsTaught hoursFees
Cybersecurity programme — Bac+5 level · Master's degree2 years1201200 h7 500 000 GNF per year
Digital Transformation Certificate · Professional certification6 months18180 h3 600 000 GNF in total

Three questions, three precise answers

Do I need a systems administration background?

It is the most solid route: you protect best what you have built. The Bac+5 cybersecurity programme opens the other way in, installing risk analysis, offensive and defensive security and the applicable regulatory framework.

Is the function technical or managerial?

It is both, and level 7 recognises precisely that articulation: understanding a vulnerability in depth, then translating it into a quantified business risk before an executive committee that decides the budget.

What does incident response cover?

Detection, qualification, containment, restoration, then post-incident analysis and the measures that prevent recurrence. The framework exercises the whole chain on realistic scenarios, because a rehearsed procedure is the only one that holds on the day.

Chief information security officer — Careers | IHETC — IHETC