Skip to main content
AI-Focused

GIAC Security Leadership (GSLC)

Practitioner Certification
GIAC Security Leadership (GSLC)
anab
dod_8140
dora
nis2

Demonstrate readiness to lead security teams, implementing technical guardrails and blending practical skill with strategic governance.

The GIAC Security Leadership (GSLC) certification validates a practitioner's ability to employ governance and technical controls to protect, detect, and respond to security issues. GSLC certification holders are equipped with key management topics that address the overall security lifecycle, and with deep knowledge of data, network, host, application, and user controls.

Areas Covered

  • Building a security program that meets business needs
  • Managing security operations and teams
  • Managing security projects and the lifecycle of the program

Who is GSLC for?

  • Information security managers
  • Security professionals with leadership responsibilities
  • IT and other managers

Exam Format

  • 1 proctored exam
  • 115 questions
  • 3 hours
  • Minimum passing score of 70%

Note: GIAC periodically reviews and may update certification specifications to ensure fairness, validity, and reliability. Using a psychometric standard-setting study, GIAC has set the passing score for the GSLC exam at 70% for all candidates who receive the exam version released on or after June 17, 2023.

To confirm the exam format and passing score that apply to your specific attempt, please refer to the Certification Information section of your GIAC account: https://exams.giac.org/pages/attempts.

Certification Delivery

GIAC certification attempts will be activated in your GIAC account after your application has been approved and according to the terms of your purchase. Details on delivery will be provided along with your registration confirmation upon payment. You will receive an email notification when your certification attempt has been activated in your account. You will have 120 days from the date of activation to complete your certification attempt.

NOTE: All GIAC Certification exams are web-based and required to be proctored. There are two proctoring options: remote proctoring through ProctorU, and onsite proctoring through PearsonVUE. Click here for more information.

Woman Staring at Tablet

Exam Certification Objectives & Outcome Statements

  • Cryptography Concepts for ManagersThe candidate will demonstrate knowledge of common cryptographic terminology, and an understanding of how symmetric, asymmetric, and hashing encryption works
  • Incident Response and Business ContinuityThe candidate will demonstrate an understanding of the phases of incident response, and managing business continuity and disaster recovery programs
  • Managing a Security Operations CenterThe candidate will demonstrate an understanding of the components, structure, and management of a Security Operations Center (SOC)
  • Managing Application SecurityThe candidate will demonstrate an understanding of security issues affecting software, including infrastructure as code, as well as integrating security into the software development lifecycle (SDLC) and DevOps processes
  • Managing Artificial IntelligenceThe candidate will demonstrate an understanding of the different types of AI technologies for business and security use, as well as the high level risks and benefits of AI.
  • Managing Cloud SecurityThe candidate will demonstrate an understanding of cloud-based services and platforms, and managing the security and risks of cloud-based infrastructure
  • Managing Encryption and PrivacyThe candidate will demonstrate an understanding of using encryption to secure data in transit or at rest, and how to identify and address privacy and compliance requirements
  • Managing Negotiations and VendorsThe candidate will demonstrate an understanding of effective negotiation and vendor management techniques
  • Managing ProjectsThe candidate will demonstrate familiarity with project management methodology, terminology, and how to gain support from the business
  • Managing Security AwarenessThe candidate will demonstrate an understanding of how to assess an organization's human risks and build a security awareness program that can mature with the organization's security program
  • Managing Security PolicyThe candidate will demonstrate an understanding of the role of security policies, standards, guidelines, processes, and baselines in meeting an organization's security needs and risk appetite
  • Managing System SecurityThe candidate will demonstrate an understanding of common types of client-side attacks and malicious code, and the strategies used to monitor and protect endpoints
  • Managing the Program StructureThe candidate will be able to design a security program with an understanding of organizational culture and reporting structures, program governance, and managing personnel
  • Network Monitoring for ManagersThe candidate will demonstrate an understanding of centralized logging and monitoring strategies and tools, including SIEM, SOAR, and machine learning technologies
  • Network Security ArchitectureThe candidate will demonstrate an understanding of security architecture, trust models, and security controls for addressing common network threats and vulnerabilities
  • Networking Concepts for ManagersThe candidate will demonstrate an understanding of network protocols, technologies, and common network threats
  • Risk Management and Security FrameworksThe candidate will demonstrate the ability to evaluate and manage risk in alignment with business objectives and adopting security frameworks and risk management techniques to help mature the security program
  • Vulnerability ManagementThe candidate will demonstrate an understanding of how to build a vulnerability management program for identifying, prioritizing, and remediating both technical and physical system vulnerabilities

Practice Tests

  • Practice exams are a simulation of the real exam, allowing you to become familiar with the test engine and style of questions
  • Practice exams can serve as a gauge to determine if your preparation methods are sufficient
  • The bank of practice questions is limited, so you may encounter the same question on multiple practice tests
  • Practice exams never include actual exam questions
  • Purchase a GSLC practice test here

How To Prepare

Other Resources

  • Training is available  in a variety of modalities including live training and OnDemand
  • Practical work experience can help ensure that you have mastered the skills necessary for certification
  • College level courses or self-paced study through other programs or materials may meet the needs for mastery
  • Understand the procedure to contest exam results
  • Use this justification letter to share key details of this certification opportunity with your boss

Find Affiliate Training

Explore affiliate training options to prepare for your GIAC certification exam.

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.