The increasing digitalization also brings growing risks for companies of all sizes. I therefore think it's good that this certificate course specifically prepares you for the role of Information Security Officer. You learn how to identify threats, implement protective measures, and comply with legal requirements. A fundamentals section ensures that you can keep up even without deep IT knowledge.
Information Security Officers and IT Security Officers are often confused, but there is a difference. As an Information Security Officer, you bear responsibility for the entire information security within the company. IT Security Officers, on the other hand, only deal with the technical part of the IT infrastructure. In English, the term Chief Information Security Officer combines both roles. In this course, you gain the knowledge for both areas of responsibility.
In the first module, you are taught the fundamentals of information security. You learn key terms, current case studies, and the tasks of Information Security Officers and IT Security Officers. In addition, there are the responsibilities of authorities such as BSI, ENISA, and the data protection supervisory authorities. You get an overview of IT security law and current developments such as NIS-2. Contract questions on IT outsourcing, penetration tests, and insurance round off the module, along with the liability of management levels and possible sanctions.
The second module is about roles, responsibilities, and information security management. You learn how tasks are clearly distributed between executive management, department heads, and area representatives. A key focus is on building an information security management system, ISMS for short. You practice building it according to BSI IT-Grundschutz and the ISO/IEC 27001 standard. You also learn tools and best practices for introducing an ISMS.
Module three focuses on current risks to information security. You deal with risk management according to BSI Standard 200-3 and business continuity management according to BSI Standard 200-4, including emergency planning. In the fourth module, you get live insights into current attack scenarios such as ransomware, attacks on KRITIS, or social engineering. You learn to categorize risks and apply the BSI IT-Grundschutz methodology to derive organizational, technical, personnel-related, and physical protective measures.
The course runs entirely online, live with instructors over five days from 08:30 to 16:30. For participation, I recommend a webcam and headset — technically, that is not a big hurdle. For your certificate, you need at least 80 percent attendance. You also need to pass the final test, which takes place online on the last day of the course. The course is aimed at aspiring Information Security Officers, IT project managers, IT administrators, and anyone tasked with organizing information security in a company. At the end, you will hold the IHK certificate "Information Security Officer (IHK)" in your hands, and there is also a digital Open Badge.



