Overview
Globally Recognized Expertise in the Field of Information Security if you plan to build a career in information security – one of today’s most visible professions – the Certified Information Systems Security Professional (CISSP®) credential should be your next career goal.
A CISSP® is an information assurance professional who defines the architecture, design, management and/or controls that assure the security of business environments. The vast breadth of knowledge and the experience it takes to pass the exam is what sets a CISSP® apart. They credential demonstrates a globally recognized level of competence provided by the (ISC)²® CBK, which covers critical topics in security today, including cloud computing, mobile security, application development security, risk management and more.
CISSP® was the first credential in the field of information to meet the stringent requirements of ISO/IEC Standard 17024. Not only is the CISSP® an objective measure of excellence, but also a globally recognized standard of achievement.
Private in-house training
Apart from public, instructor-led classes, we also offer private in-house trainings of this program for organizations. Call us at +852 2116 3328 or email us at [email protected] for more details.
Why Choose KORNERSTONE
- Leading training providers of Cybersecurity
- Multiple master trainers – each trainer has their own area of expertise which allows them to share their experiences on different topics
- Unique Style of Training – real case studies analysis, mock exam & exam drill, small class teaching and explain profound theories in simple language
- Endorsement provided after successfully passed the exam
- Guaranteed passing scheme for members
*Continuing Education Fund
Course Title: Foundation Certificate in Information Security Practices
Course Code: 33C159597
(i) This course has been included in the list of reimbursable courses under the Continuing Education Fund
(ii) This course / The mother course (Title of Qualification) of this module is recognised under the Qualifications Framework (QF Level 2)

About The Certification
- Awarded by ISC²®, the world’s leading nonprofit association for cybersecurity professionals, with a global community of more than 675,000 members across over 175 countries.
- Founded in 1989, ISC²® is globally recognized as the Gold Standard in cybersecurity certification and professional development.
- Covers all 8 domains of the latest ISC²® CISSP® Common Body of Knowledge (CBK®), aligned with the current CISSP Exam Outline.
- Globally recognized for experienced cybersecurity professionals, validating expertise in security leadership, architecture, engineering, governance, risk, and compliance.
- Accelerates career advancement into senior cybersecurity and IT leadership roles, including Security Consultant, Security Architect, IT Director, and Chief Information Security Officer (CISO).
Skills Covered
- Design secure architectures and robust security engineering solutions
- Implement identity, access, and network protection controls
- Lead security assessments, testing, and incident management efforts
- Embed risk management and compliance into organizational processes
- Ensure software development practices follow security best practices
Chartered Requirements
- Possess five years of direct full-time professional security work experience in two or more of the eight domains of the (ISC)²® CISSP® CBK, or four years of direct full-time professional security work experience in two or more of the eight domains of the CISSP® CBK with a college degree
- Pass the CISSP examination with a scaled score of 700 points or greater out of 1000 points
Read the Exam Scoring FAQs at www.isc2.org - Complete the Endorsement Process
Once you are notified that you have successfully passed the examination, you will have nine months from the date you took the exam to complete the following endorsement process:
1. Complete an Application Endorsement Form
2. Subscribe to the (ISC)²® code of ethics
3. Have your form endorsed by an (ISC)²® member - Maintain the Certification
Recertification is required every three years, with ongoing requirements to maintain your credentials in good standing. This is primarily accomplished through earning 120 Continuing Professional Education (CPE) credits every three years, with a minimum of 40 CPEs earned each year after certification. If the CPE requirements are not met, CISSP® holders must retake the exam to maintain certification. CISSP® holders must also pay an Annual Maintenance Fee (AMF) of US$135
Target Audience
This program is designed for experienced security practitioners, managers, and executives who design and manage enterprise-wide security programs. It is ideal for professionals seeking to validate their competence across eight security domains and achieve one of the world’s most respected cybersecurity credentials.
Training Highlights
- Over 10 years of CISSP® Professional Training experience.
- Study matierials, practice exercises and mock exam provided
- Multiple instructors with different expertise, all experienced in CISSP® professional training
- Free re-sitting for those who fail the exam and have 80% of attendance or above
Training Outlines
Module 1: Security and Risk Management (Security, Risk, Compliance, Law, Regulations, Business Continuity)
Module 2: Asset Security (Protecting Security of Assets)
Module 3: Security Architecture and Engineering (Engineering and Management of Security)
Module 4: Communications and Network Security (Designing and Protecting Network Security)
Module 5: Identity and Access Management (Controlling Access and Managing Identity)
Module 6: Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
Module 7: Security Operations (Foundational Concepts, Investigations, Incident Management, Disaster Recovery)
Module 8: Software Development Security (Understanding, Applying, and Enforcing Software Security)
Dates & Locations
September 12, 2026 - October 24, 2026
October 23, 2026 - December 18, 2026

Examination Highlights
- 100 – 150 multiple choice and advanced innovative questions
- 3 hours exam
- Computerized Adaptive Testing (CAT)
- More about the certification: www.isc2.org/cissp
Trainer for this course
Mr. S Cheung
AAIA, CISSP, CCSP, CISA, CDPSE, ISO 27001 Lead Auditor, ISO 20000 Lead Auditor, ISO 9001 Lead Auditor, ITIL
- Over 10 years of diverse experience in information security and cybersecurity fields, covering cloud security, network security, security operations, red & blue team assessment, and SRAA.
- Skilled in providing advisory services on information security management systems, security operations, and cybersecurity defense strategies by leveraging extensive knowledge and experience.
- Proficient in offering consultancy on industrial and government security standards like C-RAF, ISO27001, CSA CCM, PCIDSS, and SRAA, and assisting clients in designing and implementing security controls.
- Certified Kornerstone trainer for CISSP (Certified Information Systems Security Professional) and CCSP (Certified Cloud Security Professional) certifications.
Mr. R Lou, MSc.
CISSP®-ISSAP, CCSP®, CISM, CCIE, ISO27001 Auditor, ISO20000 Auditor
- Co-founder of a credit card payment processor in Hong Kong since 2005
- Founder of an IT security consultation company in Hong Kong since 2003
- Co-founder of an Internet Service Provider (ISP) from 1994 to 2002
- CISSP Trainer since 1999
Mr. H Ng
CISSP®-ISSAP, CISA
- Former Managing Director of Cybersecurity APAC, Thales Critical Information and Cybersecurity Business Unit
- Former Head of Professional Services for Verizon Business leading the Asia consulting practice specialized in delivering information security and other consulting services
- Former Team Lead of HP Security Team
- Project manager and team lead for many security assessment, governance and consultancy projects for Hong Kong Government agencies, large enterprises and major banking and financial customers within APAC region






