Start Your Exciting Cybersecurity Career with CC.
Take the first step to a rewarding career with Certified in Cybersecurity (CC) from ISC2, the world’s leading cybersecurity professional organization known for the CISSP. You don’t need experience — just the passion and drive to enter a field that opens limitless opportunities around the globe.
- Best for: Absolute beginners who want to test their interest in cybersecurity with a low-cost, foundational certification.
- Key domains covered: Security principles, incident response, disaster recovery, access control concepts and security operations.
- Growth and Learning: Develop new skills you can apply in day-to-day work.
- Pathway to Cybersecurity Careers and Advanced Certifications: Build a strong foundation for an infosec career and become familiar with exam formats for advanced ISC2 certifications.
Cybersecurity is not optional. It’s Operational. Don’t wait for a breach. Build the skills. Earn the badge. Lead the defense. Explore our Top Cybersecurity Skills for Malaysia’s Digital Future campaign.
Be the reason your organization survives the next cyberattack.

Overview
As cyberthreats continue to escalate worldwide, the need for security experts is at an all-time high. Yet talent is scarce. Research shows the cybersecurity workforce needs an influx of 3.4 million professionals to meet global demand.
That’s where the ISC2 Certified in Cybersecurity (CC) certification comes in. From the global leader in information security credentials, this new certification creates a clear pathway to an exciting and rewarding career in cybersecurity. It breaks down traditional barriers to entry, enabling you to build confidence and enter your first cybersecurity role ready for what’s next.
Why Earn the CC?
If you’re looking to join a dynamic and rewarding workforce, get Certified in Cybersecurity and demonstrate to employers you have the foundational knowledge and passion to join their team. This certification is ideal for:
- IT professionals
- Career changers looking to transition into cybersecurity
- College students or recent graduates
Skills Covered
- Discuss the foundational concepts of cybersecurity principles.
- Recognize foundational security concepts of information assurance.
- Define risk management terminology and summarize the process.
- Relate risk management to personal or professional practices.
- Classify types of security controls.
- Distinguish between policies, procedures, standards, regulations and laws.
- Demonstrate the relationship among governance elements.
- Analyze appropriate outcomes according to the canons of the ISC2 Code of Ethics when given examples.
- Practice the terminology of and review security policies.
- Explain how organizations respond to, recover from and continue to operate during unplanned disruptions.
- Recall the terms and components of incident response.
- Summarize the components of a business continuity plan.
- Identify the components of disaster recovery.
- Practice the terminology and review concepts of business continuity, disaster recovery and incident response.
- Select access controls that are appropriate in a given scenario.
- Relate access control concepts and processes to given scenarios.
- Compare various physical access controls.
- Describe logical access controls.
- Practice the terminology and review concepts of access controls.
- Explain the concepts of network security.
- Recognize common networking terms and models.
- Identify common protocols and port and their secure counterparts.
- Identify types of network (cyber) threats and attacks.
- Discuss common tools used to identify and prevent threats.
- Identify common data center terminology.
- Recognize common cloud service terminology.
- Identify secure network design terminology.
- Practice the terminology and review concepts of network security.
- Explain concepts of security operations.
- Discuss data handling best practices.
- Identify key concepts of logging and monitoring.
- Summarize the different types of encryption and their common uses.
- Describe the concepts of configuration management.
- Explain the application of common security policies.
- Discuss the importance of security awareness training.
- Practice the terminology and review concepts of network operations
Prerequisites
There are no prerequisites required to attend this course.
Target Audience
CC training is for:
- IT professionals
- career changers
- college students
- recent college graduates
- advanced high school students
- recent high school graduates

Module 1: Security Principles
1.1: Understand Cybersecurity Concepts
- Confidentiality
- Integrity
- Availability
- Authentication, Authorization, Accounting (AAA)
- Non-repudiation
- Privacy
1.2: Understand Risk Management Concepts
- Risk management lifecycle
- Risk management processes
1.3: Understand Governance Concepts
- Regulations and laws
- Frameworks and guidelines
- Policies, standards (e.g., International Organization for Standardization (ISO), Center for Internet Security), procedures
1.4: Understand Cybersecurity Controls
- Technical controls
- Administrative controls
- Physical controls
1.5: Maintain Professional and Ethical Conduct
- Professional code of conduct
- Due care and due diligence
- ISC2 Code of Ethics
Module 2: Security Governance
2.1: Plan Governance, Risk, and Compliance (GRC)
- Purpose
- Importance
- Frameworks and tools
2.2: Understand Redundancy
- Business Continuity (BC)
- Disaster Recovery (DR)
2.3: Understand Security Awareness
- Organizational culture (e.g., importance of security, security leadership)
- Concepts (e.g., social engineering, password protection, phishing)
2.4: Measure Cybersecurity Effectiveness
- Key metrics, Key Risk Indicators (KRI)
- Dashboards, score cards, reports
Module 3: Identity and Access Management (AIM) Concepts
3.1: Understand Identity Life Cycle Management
- Roles definition
- Provision
- Review
- Deprovision
- Frameworks and tools
3.2: Understand Logical Access Controls
- Principle of Least Privilege (PoLP)
- Separation of Duties (SoD)
- Access control models
- CC Certification Exam Outline
Module 4: Network and Cloud Security Concepts
4.1: Understand Network Security
- Concepts (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), Virtual Private Network (VPN))
- Firewalls (e.g., ports, applications)
- Wireless (e.g., Wi-Fi, Bluetooth)
- Embedded systems (e.g., Industrial Control System (ICS)), Internet Of Things (IoT)
4.2: Understand Network Security Architecture
- Comprehending network segmentation (e.g., Firewall zones, Virtual Local Area Network (VLAN), micro-segmentation)
- Defense in Depth
- Zero Trust (ZT)
4.3: Understand Cloud Security
- Characteristics (e.g., Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling)
- Service models
- Deployment models
- Shared security model (e.g., roles and responsibilities)
Module 5: Security Operations and Incident Response
5.1: Understand Data Security
- Data handling (e.g., classification, labeling, masking, and sanitization)
- Encryption (e.g., symmetric, asymmetric, hashing, quantum resistant cryptography)
5.2: Understand Security Operations
- Logging and monitoring security events
- Security event triage (e.g., incident use cases, prioritization, correlation)
- Threat actors (e.g., types, motivations)
- Cyber threat intelligence
- Threat frameworks
5.3: Understand Incident Response (IR)
- Data handling policy implementing Incident Response Plan (IRP)
- Incident Response (IR) exercises (e.g., testing, tabletop)
5.4: Understand Asset Protection
- Asset lifecycle management (e.g., End Of Life (EOL) software and devices)
- Configuration and change management
5.5: Understand Security Testing
- Security readiness testing (e.g., blue teaming, purple teaming, red teaming)
- Application testing (e.g., vulnerability scanning, static analysis, dynamic analysis, threat modeling)
- Physical penetration testing (e.g., phishing, tailgating, impersonation)
Dates & Locations
October 5, 2026 - October 7, 2026
October 5, 2026 - October 7, 2026
December 14, 2026 - December 16, 2026
December 14, 2026 - December 16, 2026

Exam & Certification
ISC2 CC: Certified in Cybersecurity.
Proves you have the foundational knowledge, skills and abilities for an entry- or junior-level cybersecurity role. The CC exam evaluates expertise across five security domains:
- Domain 1: Security Principles
- Domain 2: Security Governance
- Domain 3: Identity and Access (AIM) Concepts
- Domain 4: Network and Cloud Security Concepts
- Domain 5. Security Operations and Incident Response
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631
























