By the end of this course, participants will be able to:
- Develop, implement, and manage an enterprise information security program.
- Establish governance frameworks for information security policies and procedures.
- Conduct risk assessments and implement risk mitigation strategies.
- Ensure compliance with industry regulations and legal requirements.
- Oversee security incident management and response strategies.
- Align information security with business objectives and IT governance.
Upcoming Schedules
| Date | Time | Enroll |
|---|---|---|
| Oct 05 - Oct 08, 2026 | 9:00 AM - 5:00 PM America/New_York | Add To Cart |
| Nov 17 - Nov 20, 2026 | 9:00 AM - 5:00 PM America/New_York | Add To Cart |
| Jan 25 - Jan 28, 2027 | 9:00 AM - 5:00 PM America/New_York | Add To Cart |
Who should attend Certified Information Security Manager (CISM) Course
The intended audience for this course is information security and IT professionals, such as network administrators and engineers, IT managers, and IT auditors, and other individuals who want to learn more about information security, who are interested in learning in-depth information about information security management, who are looking for career advancement in IT security, or who are interested in earning the CISM certification.
Prerequisites for Certified Information Security Manager (CISM) Course
Certified Information Security Manager (CISM) Course Outline
- Enterprise Governance Overview
- Organizational Culture, Structures, Roles and Responsibilities
- Legal, Regulatory and Contractual Requirements
- Information Security Strategy
- Information Governance Frameworks and Standards
- Strategic Planning
- Risk and Threat Landscape
- Vulnerability and Control Deficiency Analysis
- Risk Assessment, Evaluation and Analysis
- Information Risk Response
- Risk Monitoring, Reporting and Communication
- IS Program Development and Resources
- IS Standards and Frameworks
- Defining an IS Program Road Map
- IS Program Metrics
- IS Program Management
- IS Awareness and Training
- Integrating the Security Program with IT Operations
- Program Communications, Reporting and Performance Management
- Incident Management and Incident Response Overview
- Incident Management and Response Plans
- Incident Classification/Categorization
- Incident Management Operations, Tools and Technologies
- Incident Investigation, Evaluation, Containment and Communication
- Incident Eradication, Recovery and Review
- Business Impact and Continuity
- Disaster Recovery Planning
- Training, Testing and Evaluation
Resources
FAQs on Certified Information Security Manager (CISM)
This course is designed for information security and IT professionals, including network administrators, engineers, IT managers, and IT auditors, who want to deepen their knowledge of information security management, advance their careers, or earn the CISM certification.
Candidates should have at least five years of relevant information security work experience, including a minimum of three years serving in an information security manager role.
Participants will learn to develop and manage enterprise information security programs, establish governance frameworks, conduct risk assessments, ensure regulatory compliance, oversee incident response, and align security initiatives with business goals.
The course covers four main domains: Information Security Governance, Information Security Risk Management, Information Security Program Development and Management, and Incident Management, including topics like risk assessment, compliance, and incident response planning.
No, this course is designed for experienced professionals with substantial background in information security management, not those new to the field.


