Applicants must provide the following information:
- the organization's operating license and, where applicable and available, its accreditation certificate;
- details of the administrative, technical, and professional personnel who will participate in the Program, as required;
- CVs of the specialists who will develop and deliver the training program, including education, professional experience, current employment, and any professional certificates;
- a description of the technical and physical resources available for delivery; and
- the proposed approach to curriculum development, delivery, improvement after the pilot, and subsequent sustainability and institutionalization.
Minimum Requirements for Participating Trainers and Curriculum Developers
The applicant must propose a multidisciplinary team of three to four people to develop and teach the Program, indicating each person's proposed role or roles, subject areas, and form of participation.
Each curriculum developer or trainer must:
1. Have practical English proficiency, evidenced by at least one example of work, research, teaching, training, or international cooperation conducted in English;
2. Have five years of professional experience in at least one of the following areas: development or implementation of cybersecurity policies and requirements; implementation or assessment of security controls; audit; risk management; risk and compliance; development of secure infrastructure or systems; or operational cybersecurity management (SOC); and
3. Have completed training relevant to their role in the Program within the past three years or hold a current professional certification relevant to that role. ISAA will assess the certification's relevance to the Program. A copy of any such certificate must be attached to the application.
Collectively, the proposed team must include:
- At least one specialist with two years of experience auditing, assessing, or implementing cybersecurity controls or programs, including application of NIST SP 800-53, ISO/IEC 27001, CIS Controls, NIST CSF, or NIS 2 requirements; and
- At least one specialist with practical professional experience in risk management or governance, risk, and compliance (GRC).
- All curriculum developers who will teach must have two years of teaching experience in technical or management subjects relevant to the Program, including risk management; cybersecurity audit and assessment; governance, risk, and compliance (GRC); infrastructure or systems engineering; or security operations management.
- The same specialist may satisfy more than one team requirement.
Supporting documents: For each specialist, provide a CV; descriptions of relevant work or projects identifying the organization, dates, individual role, and outcome; a list of courses taught, if applicable; and documents evidencing relevant training or a current certification.
Universities must also submit a summary matrix showing which team member meets each requirement.