Third-party products and services, including course instructors have helped many candidates to close knowledge and skill gaps. Lunarline does not endorse any particular provider and encourages candidates to use a variety of tools and resources that will enhance their understanding of relevant principles and the exam’s concentration area.
Certification Description
Successful completion of this exam will demonstrate a candidates ability to understand the processes and procedures required to prevent, detect, investigate, contain, eradicate, and recover from incidents that impact the organizational mission. The candidate shall demonstrate their knowledge and understanding of the required authority to formally assume responsibility and be held fully accountable for operating an information system at an acceptable level of risk.
The candidate shall demonstrate and understand the processes and procedures required to appropriately categorize and report cybersecurity incidents as dictated by policy as well as coordinate and communicate incident response actions with Law Enforcement Agencies, Federal agencies, and/or external governmental entities.
Authoritative Sources
- NIST SP 800-37 Rev. 1 – Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
- NIST SP 800-39 – Managing Information Security Risk: Organization, Mission, and Information System View
- NIST SP 800-53 Rev. 4 – Security and Privacy Controls for Federal Information Systems and Organizations
- DoDI 8510.01 Risk Management Framework for DoD IT
- DoE O 205.1B Department of Energy Cyber Security Program
Requirements
Candidates must possess at least 3 years of experience as a Representative or Designated AO in order to obtain the expert level credential. The associate level credential will be awarded to those who pass the exam, but do not have the required experience. The credential can be elevated to expert level upon attaining the required experience. Simply email [email protected] to start the experience verification process.
Mapping to the NICE Framework
NICE Work Role Name:
Authorizing Official/Designating Representative
NICE Framework Category
CCE® Concentration Area:
Securely Provision (SP)
NICE Specialty Area:
Risk Management (RSK)
NICE Work Role ID:
SP-RSK-001
OPM Code | DCWF Code:
611
NICE Work Role Description:
Senior official or executive with the authority to formally assume responsibility for operating an information system at an acceptable level of risk to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation (CNSSI 4009).
Lunarline Training Courses:
Continuing Education: The Lunarline SCS Training Program and other third-party vendors offer activities, products and services across the country that qualify as Professional Development Credits (PDCs) that target the same NICE category, specialty area, work role, and/or authoritative sources as our certifications. We encourage candidates to use a variety of tools and resources that will enhance their understanding of relevant principles and reflect their learning styles and needs.
- Authorizing Official - Designating Representative (SP301-RBT)
- NASA AO RMF (SP330-NASA)
- Risk Management Framework (RMF) for Executives (SP321)
- RMF for C-Suite (SP350)
NICE Work Role Name:
Information Systems Security Manager
NICE Framework Category
CCE® Concentration Area:
Oversee and Govern (OV)
NICE Specialty Area:
Cybersecurity Management (MGT)
NICE Work Role ID:
OV-MGT-001
OPM Code | DCWF Code:
722
NICE Work Role Description:
Responsible for the cybersecurity of a program, organization, system, or enclave
Lunarline Training Courses:
Continuing Education: The Lunarline SCS Training Program and other third-party vendors offer activities, products and services across the country that qualify as Professional Development Credits (PDCs) that target the same NICE category, specialty area, work role, and/or authoritative sources as our certifications. We encourage candidates to use a variety of tools and resources that will enhance their understanding of relevant principles and reflect their learning styles and needs.
- Cloud Security and FedRAMP (PR108)
- Cloud Security and FedRAMP - SP (PR108-SP)
- Cloud Security Fundamentals (PR109)
- Common Controls Provider (SP062-WBT)
- Continuous Monitoring and Security Operations (CO266)
- Counterintelligence for IT and Cybersecurity Professionals (AN209)
- Counterintelligence for IT and Cybersecurity Professionals - SP (AN209-SP)
- Cybersecurity Bootcamp (CYB101)
- Cybersecurity Fundamentals (CYB101)
- Cybersecurity Fundamentals - SP (CYB101-SP)
- Cybersecurity Fundamentals - WBT (CYB001-WBT)
- Cybersecurity Fundamentals for Managers - WBT (OV053-WBT)
- Cybersecurity Operations and Planning (AN165)
- Cybersecurity Operations and Planning - SP (AN165-SP)
- FISMA Overview (SP106)
- FISMA Overview - SP (SP106-SP)
- Healthcare Security & Privacy for IT Professionals (OV105)
- Implementing and Securing Your Virtual Environment (OM112)
- Implementing and Securing Your Virtual Environment - WBT (OM012-WBT)
- Information Security Risk Assessments (SP130)
- Information Systems Continous Monitoring for Philips (CO131-PHI)
- Information Systems Continuous Monitoring (CO212)
- Information Systems Security Manager (OV303-RBT)
- Insider Threat Awareness - WBT (AN002-WBT)
- Network and Packet Analysis (OM207)
- NIST 800-171 (SP105b)
- NIST 800-171 - Remote (SP105a)
- NIST 800-171 - SP (SP105-SP)
- Privacy for IT/ISS Professionals (OV231)
- Privacy for IT/ISS Professionals - SP (OV231-SP)
- Risk Management Framework (RMF) Common Controls (SP111)
- Risk Management Framework (RMF) Common Controls - SP (SP111-SP)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - In-Depth (SP101-3)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - In-Depth - SP (SP101-3-SP)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - Intensive (SP101-4)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - Intensive - SP (SP101-4-SP)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - Overview (SP101-1)
- Risk Management Framework (RMF) for DoD & Intelligence Communities - Overview - SP (SP101-1-SP)
- Risk Management Framework (RMF) for Federal Systems - In-Depth (SP102-3)
- Risk Management Framework (RMF) for Federal Systems - In-Depth - SP (PR102-3-SP)
- Risk Management Framework (RMF) for Federal Systems - Intensive (PR102-4)
- Risk Management Framework (RMF) for Federal Systems - Intensive - SP (PR102-4-SP)
- Risk Management Framework (RMF) for Federal Systems - Overview (SP102-1)
- Risk Management Framework for Federal Systems Overview - SP (SP102-1-SP)
- RMF for Medical Devices (SP222)
- RMF for NASA (PR102-NASA)
- RMF for SAPCOs (SP225)
- RMF Rev5 Process Change - WBT (SP001-WBT)
- Securing Wireless Networks (OM210)
- Securing Your Digital Environment (SP144)
- Securing Your Digital Environment - WBT (OM044-WBT)
- Social Media and Privacy - WBT (CYB080-WBT)
- USCG War Game Exercise (CYB302)
- Windows System Security Auditing (OM208)
- Windows System Security Auditing - SP (OM208-SP)