What is the GIAC Law of Data Security & Investigations (GLEG) certification?
GLEG validates a practitioner's knowledge of the law regarding electronically stored and transmitted records. GLEG holders have demonstrated knowledge of the law of fraud, crime, policy, contracts, privacy, compliance, cybersecurity, and investigations — equipping them to navigate the legal landscape of modern data security.
What are the GLEG exam requirements?
The GLEG exam consists of 75 questions, is web-based and proctored, has a 2-hour time limit, and requires a minimum passing score of 70.7%. Proctoring is available via ProctorU (remote) or PearsonVUE (onsite).
What topics does GLEG cover?
GLEG covers Business Policies and Compliance, Contracts and Third-Party Agreements, Data Retention and E-Discovery, Fraud and Misuse, Cybersecurity and Investigations, Intellectual Property, Privacy and PII — across US federal law and major international regulatory frameworks.
Who should take the GLEG certification?
GLEG is designed for investigators, security and IT professionals, lawyers, paralegals, auditors, accountants, technology managers, vendors, compliance officers, law enforcement personnel, privacy officers, penetration testers, and cyber incident responders — anyone whose work intersects with legal aspects of information security.
Why is GLEG valuable for technical security professionals?
Technical professionals with GLEG knowledge make better decisions about data handling, evidence preservation, and incident response because they understand the legal consequences. They can collaborate more effectively with legal counsel, support regulatory responses, and avoid inadvertent legal exposure.
Is GLEG relevant outside the United States?
Yes — while GLEG covers US law extensively, the principles of data protection, privacy regulation, intellectual property, and electronic evidence are globally relevant. The certification is particularly valuable for professionals working with international clients or in multinational organisations.