Certified Information Security Manager (CISM)

Skip to Scheduled Dates

Course Overview

This four-day exam preparation course equips learners with the essential knowledge and concepts needed to succeed on the CISM certification exam. Participants explore key domains, including Information Security Governance, Risk Management, Security Program Development, and Incident Management, strengthening their understanding of enterprise-level security practices. Case studies and targeted practice questions reinforce learning and help participants confidently apply concepts in ways that directly support exam readiness.

Who Should Attend

The intended audience for this course is information security and IT professionals, such as network administrators and engineers, IT managers, and IT auditors, and other individuals who want to learn more about information security, who are interested in learning in-depth information about information security management, who are looking for career advancement in IT security, or who are interested in earning the CISM certification.

Course Objectives

    By the end of this course, participants will be able to:

    • Develop, implement, and manage an enterprise information security program.

    • Establish governance frameworks for information security policies and procedures.

    • Conduct risk assessments and implement risk mitigation strategies.

    • Ensure compliance with industry regulations and legal requirements.

    • Oversee security incident management and response strategies.

    • Align information security with business objectives and IT governance.

Course Outline

Domain 1: Information Security Governance

  • Organizational Purpose and Culture
  • Legal, Regulatory, and Contractual Requirements
  • Organizational Structures, Roles, and Responsibilities
  • Information Security Strategy Development
  • Enterprise Architecture
  • Information Governance Frameworks and Standards
  • Strategic Planning

Domain 2: Information Security Risk Management

  • Emerging Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment and Analysis
  • Risk Treatment/Risk Response Options
  • Risk and Control Ownership
  • Risk Monitoring and Reporting

Domain 3: Information Security Program

  • Information Security Architecture
  • Information Security Program Resources
  • Information Security Industry Standards and Frameworks
  • Information Security Policies, Standards, Procedures, and Guidelines
  • Information Asset Identification and Classification
  • Information Security Control Design and Selection
  • Information Security Program Metrics Development
  • Information Security Control Implementation and Integrations
  • Information Security Control Testing and Evaluation
  • Information Security Awareness and Training
  • Management of External Services
  • Information Security Program Metrics, Communications, and Reporting

Domain 4: Incident Management

  • Incident Response Plan
  • Business Impact Analysis (BIA)
  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Incident Classification/Categorization
  • Incident Management Training, Testing, and Evaluation
  • Incident Management Tools and Techniques
  • Incident Investigation and Evaluation
  • Incident Containment Methods
  • Incident Response Communications
  • Incident Eradication and Recovery
  • Post-incident Review Practice

 Back to Course Search

Class Dates & Times

Class times are listed Central time

This is a 4-day class

Price : $2,595.00

Register When Time
 Register 10/05/2026 8:00AM - 4:00PM
 Register 11/17/2026 8:00AM - 4:00PM
 Register 01/25/2027 8:00AM - 4:00PM
 Register 03/29/2027 8:00AM - 4:00PM
 Register 05/24/2027 8:00AM - 4:00PM
 Register 07/26/2027 8:00AM - 4:00PM
 Register 09/27/2027 8:00AM - 4:00PM
 Register 11/29/2027 8:00AM - 4:00PM