Cybersecurity gets treated as a purely technical problem — firewalls, encryption, incident response. But a security control that nobody in the business understands or follows correctly fails just as often as a missing one, which is exactly the gap IIBA-CCA was built to close.
A Joint Certification, Deliberately
IIBA-CCA is offered jointly with IEEE Computer Society specifically because it needs credibility on both sides — the analysis discipline and the technical security discipline — rather than being a watered-down security credential for non-technical staff.
The Actual Problem It Solves
Security requirements written by engineers for engineers routinely get implemented incorrectly by business teams who don’t understand the underlying risk. A business analyst trained in cybersecurity concepts can translate technical security requirements into workflows people actually follow correctly.
Who This Fits
- BAs working on projects with significant compliance or data protection requirements
- Analysts who regularly translate between security teams and business stakeholders
- Anyone documenting security requirements who wants those requirements to actually get followed
Starting Point
As with the other specializations, core BA competency comes first — see ECBA, CCBA, and CBAP.
Full Details
Eligibility and program details are on the official IIBA website.









