CISM Certified Information Security Manager

Course 2036

  • Duration: 4 days
  • Exam Voucher: Yes
  • Language: English
  • 23 NASBA CPE Credits (live, in-class training only)
  • Level: Intermediate

This four‑day exam preparation course equips learners with the essential knowledge and concepts needed to succeed on the CISM certification exam. Participants explore key domains, including Information Security Governance, Risk Management, Security Program Development, and Incident Management, strengthening their understanding of enterprise‑level security practices. Case studies and targeted practice questions reinforce learning and help participants confidently apply concepts in ways that directly support exam readiness.

 This course covers the four CISM domains:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Program
  • Incident Management

U.S. DoDM 8140.03 APPROVED BY DEPARTMENT OF DEFENSE

CISM Certified Information Security Manager Training Delivery Methods

  • In-Person

  • Online

CISM Certified Information Security Manager Training Information

  • In this course, you will:

    • Establish an information security governance framework

    • Develop an information security strategy and business case

    • Assess threats, vulnerabilities, control deficiencies, and business impacts within the organization’s risk appetite.

    • Recommend and monitor risk treatment strategies that assign ownership and reduce risk to acceptable levels.

    • Develop an information security program integrating security architecture, policies, resources, controls, and performance metrics.

    • Manage and evaluate program effectiveness, including control testing, security awareness, third-party security, and stakeholder reporting.

    • Establish incident management capabilities aligned with business continuity and disaster recovery requirements.

    • Direct incident response activities and use exercises and post-incident reviews to strengthen organizational resilience.

  • Training Prerequisites

    There are no formal prerequisites to take the CISM exam or attend a CISM preparation course. However, to earn the CISM certification, candidates must:

    • Have at least five years of professional information security management experience across at least three of the four CISM domains.
  • Certification Information

    The ISACA Exam Candidate Information Guide provides valuable information regarding exam day rules and information, as well as exam dates and deadlines. You can find the most recent version at: https://www.isaca.org/credentialing/exam-candidate-guides

CISM Certified Information Security Manager Training Outline

  • Describe the role of governance in creating value for the enterprise.
  • Explain the importance of information security governance in the context of overall enterprise governance.
  • Identify the relevant legal, regulatory, and contractual requirements that impact the enterprise.
  • Describe the influence of enterprise leadership, structure, and culture on the effectiveness of an information security strategy.
  • Describe the effects of the information security strategy on enterprise risk management.
  • Explain the relationship between enterprise architecture (EA) and effective enterprise governance.
  • Evaluate the common frameworks and standards used to govern an information security strategy.
  • Explain why metrics are critical in developing and evaluating the information security strategy.

 Topics:

  • Organizational Purpose and Culture
  • Legal, Regulatory, and Contractual Requirements
  • Organizational Structures, Roles, and Responsibilities
  • Information Security Strategy Development
  • Enterprise Architecture
  • Information Governance Frameworks and Standards
  • Apply risk assessment strategies to reduce the impact of information security risk.
  • Assess the types of threats faced by the enterprise.
  • Explain how security control baselines affect vulnerability and control deficiency analysis.
  • Differentiate between the application of risk treatment types from an information security perspective.
  • Describe the influence of risk and control ownership on the information security program.
  • Outline the process of monitoring and reporting information security risk.

 Topics:

  • Emerging Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment and Analysis
  • Risk Treatment/Risk Response Options
  • Risk and Control Ownership
  • Risk Monitoring and Reporting
  • Describe the goals and objectives of an information security architecture.
  • Outline the components and resources used to build an information security program.
  • Distinguish between common information security standards and frameworks available for building an information security program.
  • Explain how to align information security policies, procedures, and guidelines with the needs of the enterprise.
  • Describe the process of defining an information security program road map.
  • Outline key information security program metrics used to track and report progress to senior management.
  • Explain how to manage the information security program using controls.
  • Create a strategy to enhance awareness and knowledge of the information security program.
  • Describe the process of integrating the security program with IT operations and third-party providers.
  • Communicate key security program information to relevant stakeholders.

 Topics:

  • Information Security Architecture
  • Information Security Program Resources
  • Information Security Industry Standards and Frameworks
  • Information Security Policies, Standards, Procedures, and Guidelines
  • Information Asset Identification and Classification
  • Information Security Control Design and Selection
  • Information Security Program Metrics Development
  • Information Security Control Implementation and Integrations
  • Information Security Control Testing and Evaluation
  • Information Security Awareness and Training
  • Management of External Services
  • Information Security Program Metrics, Communications, and Reporting
  • Distinguish between incident management and incident response.
  • Outline the requirements and procedures necessary to develop an incident response plan.
  • Explain the relationship between business impact, continuity, and incident response.
  • Describe the processes and outcomes related to disaster recovery.
  • Explain the impact of metrics and testing when evaluating the incident response plan.
  • Identify techniques used to classify or categorize incidents.
  • Outline the types of roles and responsibilities required for an effective incident management and response team.
  • Distinguish between the types of incident management tools and technologies available to an enterprise.
  • Describe the processes and methods used to investigate, evaluate, and contain an incident.
  • Identify the types of communications and notifications used to inform key stakeholders of incidents and tests.
  • Outline the processes and procedures used to eradicate and recover from incidents.

 Topics:

  • Incident Response Plan
  • Business Impact Analysis (BIA)
  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Incident Classification/Categorization
  • Incident Management Training, Testing, and Evaluation
  • Incident Management Tools and Techniques
  • Incident Investigation and Evaluation
  • Incident Containment Methods
  • Incident Response Communications
  • Incident Eradication and Recovery
  • Post-incident Review Practices

Need Help Finding The Right Training Solution?

Our training advisors are here for you.

CISM Certified Information Security Manager Training FAQs

You have 6 months access to the course content (including the QAE) from the date of redemption. Exams must be taken within 6 months of voucher redemption.

The course is designed for information security managers, cybersecurity professionals, risk and compliance leaders, security consultants, and experienced practitioners preparing for security management roles.

No formal prerequisites are required to attend the course or take the exam. However, candidates must meet ISACA’s professional experience requirements before earning the certification.

Candidates must pass the CISM exam and demonstrate at least five years of professional information security management experience across three or more CISM domains. They must also submit an application, verify their experience, pay the application fee, and follow ISACA’s Code of Professional Ethics.

No. The course prepares learners for the exam but does not include or automatically grant certification. Candidates must independently pass the exam and meet all ISACA experience and application requirements.