Group Purchasing
Group Purchasing

What Is the GISF Certification?

The GISF certification validates the foundational skills every practitioner needs before going deeper into any specialty: how computers and networks function, introductory cryptography, and the core cybersecurity technologies and concepts that connect them. It's built for anyone who needs to operationalize security standards and controls to manage organizational risk.

By the numbers

2 hrs

Exam duration

75

Questions

69%

Min. passing score

What GISF Covers

The certification's 12 published objectives group into five practical domains that map directly to SEC301's five sections.

Cybersecurity and Risk Foundations

Covers Foundations of Cybersecurity, Managing and Mitigating Cyber Risk, and Security Foundations and Awareness.

Cryptography and Digital Trust

Covers Foundations of Cryptography and Digital Trust and Identity, Access and Data Protection.

Network Communication and Architecture

Covers Foundations of Network Communication and Network Security and Architecture.

Adversary Behavior and Intrusion Techniques

Covers Adversary Analysis and Threat Frameworks, Intrusion and Initial Access Techniques, and Post-Exploitation and Advanced Threat Techniques.

Defensive Technology and Cloud Security

Covers Defensive Technologies and Emerging Intelligence and Securing Connected and Cloud-Based Environments.

Prepare With This Course

SEC301: Introduction to Cybersecurity

How SEC301 Prepares You for GISF

SEC301 is built around the exam objectives that make up the GISF certification: 

  • Section 1, Cybersecurity Foundations builds skills tested under Foundations of Cybersecurity, Managing and Mitigating Cyber Risk, and Security Foundations and Awareness.
  • Section 2, Building Digital Trust: Cryptography, Identity, and Access aligns with Foundations of Cryptography and Digital Trust and Identity, Access and Data Protection.
  • Section 3, Understanding Networks and Data in Motion aligns with Foundations of Network Communication and Network Security and Architecture.
  • Section 4, Modern Attack Tactics: From Phishing to AI-Powered Threats builds skills tested under Adversary Analysis and Threat Frameworks, Intrusion and Initial Access Techniques, and Post-Exploitation and Advanced Threat Techniques.
  • Section 5, Cybersecurity Technologies and Web Security aligns with Defensive Technologies and Emerging Intelligence and Securing Connected and Cloud-Based Environments.

Across all five sections, 14 hands-on labs give you the chance to apply each skill in a live virtualized cloud environment before you sit the exam. 

Read the full GISF certification overview 

SEC301 Course Author

Rich Greene
Rich Greene

Rich Greene

Senior Solutions Engineer at SANS Institute

Rich Greene, SANS Senior Solutions Engineer and SEC301 author, brings 20+ years of cyber operations and teaching experience to the classroom. With 15+ GIAC certifications and a passion for mentorship, he equips defenders with real-world confidence and skill.

Read more about Rich Greene

Who Should Pursue GISF

Anyone New to Cybersecurity who needs an introduction to the fundamentals

Non-IT Security Managers and System Administrators

Career Changers moving into Cybersecurity

HR, Legal, Audit, and other Non-Technical Professionals who write or must follow enterprise security policy

Managers and Information Security Officers responsible for organizational risk

Frequently Asked Questions

The GISF certification proves you understand the foundations of cybersecurity: how computers and networks function, the basics of cryptography, and the core technologies and practices that reduce organizational risk. GIAC positions certification holders as informed defenders, able to apply security standards and controls in real decisions rather than just recognize terminology. 

The GISF exam is a single proctored exam of 75 questions, with a 2 hour time limit and a minimum passing score of 69% (GIAC set this passing score for exam versions released on or after March 7, 2026, using a psychometric standard-setting study). It's web-based, with remote proctoring through ProctorU or onsite proctoring through PearsonVUE. 

GIAC certifications are renewed on a recurring cycle through continuing education credits and a maintenance fee. For the current renewal requirements, see GIAC’s renewal page. 

GISF fits anyone building a foundation in cybersecurity: non-IT security managers, system administrators, career changers moving into the field, and non-technical roles like HR, legal, and audit professionals who write or must follow enterprise security policy. It also fits managers who need to understand organizational risk without going deep technical. 

SEC301: Introduction to Cybersecurity is the SANS course built to prepare you for the GISF exam. Across five days and 14 hands-on labs, it covers the same ground the certification tests: cybersecurity foundations, cryptography and identity, networking, attack techniques, and the defensive technologies that tie it together. No technical background is required to start the course. 

Ready to earn your GISF certification?

Add the GISF exam attempt when you register for SEC301.

Already trained? Register for the exam directly through GIAC here.

GISF Certification Overview | SANS Institute