Bridging HR, Cybersecurity and Governance: My Journey to ISC2 Certified in Cybersecurity (CC)

Written by

in

,

I am pleased to share that I have recently earned the ISC2 Certified in Cybersecurity (CC) credential after about five months of self-paced e-learning and an in-person exam at a Pearson VUE testing centre in Kuala Lumpur. It was an exhilarating experience, especially as it was my first formal certification exam since sitting for the TOEFL iBT more than a decade ago.

ISC2 is a global nonprofit association best known for leading cybersecurity certifications such as CISSP, CCSP and CC, which validate professionals’ knowledge in areas like security principles, network security, incident response and security operations. The CC certification specifically targets entry level and early career professionals, establishing a solid baseline in cybersecurity concepts and supporting organisations that want to build secure by design cultures.

This CC programme sits under the One Million Certified in Cybersecurity (1MCC) initiative, where ISC2 pledged to provide one million individuals with free access to foundational cybersecurity training and a no cost attempt at the CC exam. The initiative’s goal is to reduce financial and educational barriers, help close the global cybersecurity workforce gap and develop a more diverse pipeline of cyber talent across industries and regions.

In my current role in Human Resources, I have been deeply involved in Learning and Development, digital learning ecosystems and organisational governance, including internal audit roles for ISO 9001 Quality Management Systems (QMS) and ISO 27001 Information Security Management Systems (ISMS). ISO 9001 provides a framework for consistent, customer focused quality processes, while ISO 27001 sets out a risk based approach to protecting the confidentiality, integrity and availability of information assets through a structured ISMS. Together, these standards emphasise the importance of robust processes, continuous improvement and clear accountability, which are principles that align closely with the mindset required for effective cybersecurity. As my organisation has recently obtained ISMS 27001 certification, I believe I can play a bigger role in ensuring continuous improvements in information security practice.

From an HR and Learning and Development perspective, cybersecurity is no longer just an IT issue; it is a leadership and culture issue. Leaders and project owners who oversee digital transformation, HRIS or low code applications are responsible for ensuring that processes and systems are designed with security and compliance in mind. Understanding how people, processes and technology interact within ISO 27001 and ISO 9001 frameworks helps us embed security, data integrity and quality into everyday workflows, rather than treating these as add ons.

Earning the CC certification is one way for me to demonstrate a tangible commitment to this intersection of HR, technology and governance. The continuing professional education (CPE) structure of ISC2 requires members to keep updating their knowledge in line with evolving threats, regulatory requirements and best practices. This complements the continuous improvement cycles inherent in both ISO 9001 and ISO 27001 and reinforces a habit of learning, adapting and refining controls over time.

Looking ahead, I am excited to explore how CC, ISO based governance experience and my background in digital learning and HR technology can contribute to more resilient organisations. Whether it is designing secure onboarding processes, strengthening awareness programmes or supporting ISMS and QMS initiatives, I see significant value in integrating people development with security and quality frameworks. I look forward to engaging with cybersecurity, Learning and Development and project management professionals to exchange ideas and co create safer and more human centred digital workplaces.