
Launch the CISM journey with a concise introduction to the credential, outlining its purpose and what to expect in upcoming chapters, then define the system and examine its structure.
Define the system and confirm you are in the right course with the right expectations, ensuring everyone is aligned on bearings and what lies ahead.
Explore how the CISM credential equips managers with technology-agnostic concepts and techniques for information security across mixed platforms. Learn to integrate business processes, budgets, and personnel management into security leadership.
Submit your test results to show the passing score and provide proof of experience, including a resume with references; check Issaka list for substitutions and pay fifty dollar processing fee.
Examine the core structure of topic B in the CISM course, outlining a straightforward, easy-to-follow framework to guide learners through key concepts.
Identify the system objectives and your role as a new mid-level manager, and introduce the four domains—governance, risk management, incident management, and related areas—that frame this course.
Master the governance concept within the DSM framework and learn how to apply it in information security management.
Discover how governance aligns business objectives with security through defined responsibilities, risk management, and resource stewardship, while setting objectives and monitoring performance to stay aligned.
Explore the objectives of IT governance and its broad, adaptable requirements, guiding tailored strategies, compliance considerations, and practical deployment through theory-to-practice examples.
Learn the distinction between tasks and knowledge statements for the information security manager, aligning duties and requirements with essential knowledge to apply theory to practice with tools and techniques.
Align your security strategy with corporate goals, regularly reassess alignment, and tailor governance like a custom suit, backed by a CISO or CIO endorsement for resources.
Understand how to align security with business motivation in CISM by assessing risk appetite, technology environment, geographic location, and people, and identify trusted experts to navigate the organization.
Secure senior management endorsement and commitments. Emphasize the value of investing now to prevent lawsuits, revenue loss, and reputational damage, and clarify legal accountability.
Establish clear, open channels of communication across departments to share information, catch anomalies, and ensure consistent vocabulary. Align terms and agreed methods to prevent miscommunication and improve operational clarity.
Information governance frames information as the core business asset, guiding how organizations manage vast digital data, tangible and intangible assets, and information security in alignment with business goals.
Private sector controls about 80 percent of critical infrastructure, making executive management responsible for governance. Laws and potential fines enforce compliance, with boards involved where present.
Explore how governance regulations, including Sarbanes-Oxley, drive transparency, compliance, investor confidence, and premium pricing by investors, while public perception shapes value.
Identify your organization's risk exposure across people, processes, and technology; prioritize threats by likelihood and impact; implement defenses to reduce residual risk to an acceptable level.
Master resource management to ensure organizational knowledge is accessible to those who need it, document processes for reproducibility, and build a secure environment aligned with available resources and talent.
Explore how to integrate components across an organization by establishing relationships, defining roles and responsibilities, assessing the current state, and planning how to rewrite or create roles as needed.
Establish effective governance by embedding responsibility in the business, ensuring transparency and clear awareness of security efforts without exposing minutiae. Align governance with multiple frameworks to meet diverse standards.
Clarify who a CISO reports to, including the CEO, board of directors, CIO, CSO, CTO, or VP, and explain how reports may be reviewed by various parties.
Understand the scope of security governance and the distinction between information security and IT security, noting that information in any form falls under governance.
Establish a core set of guiding principles to shape IT governance implementation, tailored to each business context, and align team personalities and goals for optimal outcomes.
Explore components of security metrics, focusing on results oriented metrics that quantify performance and incident response, and how policies, procedures, and management support drive and interpret these metrics.
Align information security governance with organizational objectives, monitor warning indicators and metrics to prevent security lapses, and actively manage people and processes to stay on track.
Define risk appetite and tolerance to decide exposure. Align a security strategy and program, perform risk assessments, deploy mitigations, plan for incidents and asset accountability, business continuity, and disaster recovery.
Learn to manage resources effectively within risk management, allocating people, tools, and money wisely. The course clarifies the shift from building systems to managing indicators and factors throughout the lifecycle.
Develop meaningful performance measures by tracking training, incidents, and outages to assess process efficacy and guide improvements, and benchmark against current technology.
Coordinate diverse security processes and technologies through proactive planning and cross-team collaboration to achieve a harmonious assurance process that integrates devices, procedures, and human review.
Define information security objectives and goals by linking them to business motivations and governance, assess risks, and steer conversations with stakeholders to capture context beyond technology.
Explore the desired state as a snapshot of a system, including technology, people, and processes, and measure security with uptime and business impact.
Explore approaches and processes to reach a desired state, and review three key resources for managing it within your environment.
Explore multiple approaches to information security management, including various balanced scorecard versions, Sapp says, and COGAT, and learn how to apply these approaches in the process.
Verify you are using the current ISO 27001 version, noting revisions shown by colon year. Discuss with customers when an older standard is required to determine feasibility and maintain compliance.
Define attainable risk objectives within the budget, evaluate the costs to reach them, and decide whether doing more measures or changing the approach reduces risk cost-effectively.
Perform an in-depth audit and assessment to determine the current state by reviewing papers and technology, then compare to the desired state to identify gaps and guide compliance decisions.
Develop a security strategy by articulating policies, standards, procedures, and guidelines; policies set direction, standards define required performance, procedures meet standards and goals, while guidelines offer optional best practices.
Governance aligns security with business goals through a steering committee, action plans, and prioritized objectives, ensuring security efforts support strategy and meet defined objectives.
Explore information risk management, defining risk management concepts, scope, and exam takeaways, then examine the risk management process and its practical steps.
Explore how risk management encompasses policies, procedures, and administrative, technical, and physical controls to identify, analyze, evaluate, treat, and monitor risk, minimizing it to an acceptable level.
Classify assets and assign ownership to establish information security baselines, applying a chosen scheme with low, medium, high, or secret classifications across soft copy, hard copy, and other formats.
Implement a systematic information risk assessment process aligned with ISO 27001 to identify and prioritize assets, perform BIA analyses, and address critical assets, risk mitigation, and business continuity.
Identify and update security controls regularly. Evaluate those that need verification in phases to ensure they perform as designed and detect configuration changes and patches, continuously mitigating risk.
Integrate new software, hardware, and network changes into lifecycle management, balancing security evaluation with hardware refresh plans to decide whether to upgrade legacy gear or replace it.
Enforce change management by identifying and reporting significant security changes, prioritizing issues for management, tracking their origin, and ensuring explanations exist for all changes.
Analyze and locate risk to gain control as the organization grows, since risk management drives disaster recovery and business continuity planning through guiding frameworks.
Define governance roles for information security, with the board and executive management, including the CEO, accountable for risk management, and a steering committee aligning security efforts with business needs.
Explore core security concepts, including threats, vulnerabilities, and exposures, and learn how risk depends on their alignment within the right environment; apply controls and safeguards to reduce risk and impact.
Learn how asset value and criticality drive controls, classify assets by sensitivity, protect personal data, and implement redundancy to maintain confidentiality, integrity, and availability.
Learn to implement risk management by classifying assets, selecting appropriate controls based on asset value and recovery time objectives, and coordinating with third-party providers, baselines, monitoring, and documentation.
Identify four risk management options—terminate, transfer, mitigate, and accept—apply to perceived risks, with examples like stopping risky actions, transferring to a third party or insurer, and accepting residual risk.
Learn to conduct risk assessment by valuing assets, evaluating threats, and determining aggregated risk; track risks in a centralized database; develop countermeasures and resource plans (manpower, money, time) accordingly.
Explore how risk mitigation uses controls and defense in depth to reduce residual risk, balancing likelihood, cost, and benefit to determine effective countermeasures.
Identify and value assets like hardware, data, and intellectual property, including patents, trademarks, and copyrights. Protect intellectual property to preserve company valuation and leverage licensing rights.
Identify risk management objectives and tasks, including what you are expected to know and what Issaka wants. Explore processes, controls, countermeasures, and frameworks to determine risk and ensure proper implementation.
Define a security program and its development, and manage day-to-day operations, outlining the structure, and the roles and responsibilities within the program management process.
Learn what a security program is and how it frames information security management in topic a of the CISM course.
Define components and activities of a security program, establish policies and strategies, classify critical assets and their sensitivity, and quantify risks to guide secure operations.
Coordinate a security program with the business, governance, and other security functions, using change management, steering committee sign-off, and documented reporting to address recurring issues and drive alignment.
Learn to balance internal resources and third-party needs for a security program, prioritize critical tasks, and allocate resources efficiently to maximize value while avoiding costly misallocations.
Keep security management actively involved in evolving the existing security architecture, plan for disaster recovery and business continuity, and document architecture with version control to stay ahead of future requirements.
Review and define security policy to articulate intent, goals, and direction, while excluding implementation details, and regularly update policies to reflect evolving threats and business requirements.
Design and implement a training and education program that distinguishes security awareness for everyday non-technical staff from formal training for technical and management personnel, ensuring proper deployment of security tools.
Establish metrics to measure how well we are doing our job, justify the impact, and emphasize the importance of measurement within this domain.
Using frameworks, define, develop, implement, and roll out a unified security program that monitors metrics, refines processes, and continually optimizes enterprise security.
Translate risk analysis into tangible security program outcomes that realize policy goals set by executive staff and confirm deliverables are completed on a regular schedule.
Define asset ownership and sensitivity to shape a security program. Codify risk assessments for consistency, and include business impact, threat and vulnerability evaluations, legal requirements, and system monitoring.
Apply the risk-reward trade-off when developing a security program to decide mitigation needs. Exploitation does not always cause damage, and patches and backups, plus buffer overflow considerations, guide defense choices.
Leverage the assurance function to implement a trust but verify approach that integrates monitoring, auditing, and plan-do-check-act cycles across planning and implementation.
Define a security road map by forming a steering committee to align business and security goals, draft policy, standards, procedures, assess gaps, and implement prevention, detection, correction, and disaster recovery.
Define clear objectives and scope for security reviews, then map constraints and environment to create a roadmap for the overall security program and its components.
Evaluate an existing system's architecture against a baseline design to ensure secure data handling, clear configuration, and objective results within the network and operating system.
Learn how to perform a security spot check on a small, discrete portion of a system, yielding a simple yes-or-no assessment of whether it works.
Integrate the security program across the business by involving appropriate external personnel, sharing essential context, and securing executive support for cross-department legitimacy.
Assign the right people with technical, resource, and diplomatic skills to lead security management, enabling ramp-up, team communication, and a well-oiled program with favorable investor perception.
Establish a continuous security program that adapts to changing assets and threats, educate leaders as champions of best practices, and base decisions on operational metrics and compliance.
Clarify the steering committee's role, ensuring IT and information security align with the business, support safe, stable operations, and adapt to leadership changes, mergers and acquisitions, or divestitures.
Forge a strong partnership with the information technology unit through clear communication and collaboration, since information security outcomes depend on IT practices.
Business unit managers, non-security personnel, monitor security incidents, escalate issues, and liaise with the security team, while receiving security awareness training and collaborating with the security manager.
Collaborating with legal and security teams, HR designs policies and educational plans, plus response protocols, to ensure training aligns with safety and legal standards and protects all stakeholders.
The legal department ensures compliance through due diligence and proper attention, known as do care, guiding cyber risk decisions, monitoring employee actions with consent, and collaborating on the steering committee.
Explore the roles of program manager and biosecurity manager, their objectives, and governance responsibilities, including steering committees, boards of directors, and executive staff, within the overall security program.
Learn the purpose of incident handling in information security, outline basic tasks, and orient yourself to what incident handling aims to achieve within a CISM framework.
Identify security incidents, analyze root causes and impact, and eradicate threats as part of the information security manager's responsibilities. Master incident management tools and response techniques to handle security events.
Form the instant response team to detect, investigate, and identify root causes of incidents, develop rapid, comprehensive responses, and establish incident reporting, escalation, and lines of authority.
Develop and implement processes for information security incidents, from scratch or by optimizing existing ones, and engage stakeholders to prepare policies and ensure personnel are ready to use them.
Define and maintain clear escalation procedures and lines of authority, supported by an org chart, to prevent communication roadblocks and resolve incidents quickly and completely.
Develop a dedicated incident communication process that coordinates internal and external authorities, assigns resources to keep processes up to date, and avoids senior executives handling external communications.
Define ready teams with the proper resources to handle security incidents, using classroom and hands-on training plus regular drills to retain skills and respond promptly.
Learn to manage information security incidents as a prepared manager, delegating tasks, coordinating communications, and reallocating resources across teams, while staying ready to step in if hands-on work is required.
Conduct regular reviews of security incidents with a set of eyeballs to prevent recurrence and reduce risk. Identify improvements to security controls when incidents arrive on your desk.
Break down the components of incident management, from finding incidents to mobilizing resources, containment, eradication, and recovery, and highlight what’s different to prepare for the CISM exam.
Discover how incident management ensures readiness for evolving vulnerabilities and unplanned incidents. This approach includes continual testing, refinement, and regulatory compliance in contexts like payment card industry and health care.
Track evolving regulations shaping incident management, with legal input, cross-government coordination, standardized terminology, and trained personnel to improve post-9/11 response.
Explore incident handling steps from detection to reporting, triage, analysis, and response, and understand how incident management moves pieces to a successful resolution.
Technology aids incident management by automating processes and letting the team focus on interpreting data, with tablets, ruggedized devices, and satellite phones supporting field operations within budget constraints.
Define the incident management team's scope and charter by establishing its mission, responsibilities, and reporting structure, and outline the roles and org charts that justify the team's purpose.
Develop a proactive incident response plan with detection triggers, triage, and containment to stabilize systems and protect infrastructure, escalating to formal response as information evolves.
Coordinate outsourced security providers for incident response and forensics. Establish partnerships and clear response times to ensure hardware replacement or repair during incidents.
Explain three distinct incident response roles—senior security group, information security manager, and response manager—and outline how incident handlers bring incidents to resolution.
Investigators examine incidents to determine what happened and why, revealing risks beyond the initial event. Security, business managers, and IT specialists collaborate to assess potential losses and protect critical functions.
Coordinate legal, HR, and PR involvement during incidents through a dedicated PR representative. Keep executives out of the firing line and rely on risk management data to guide the response.
Identify IRT team skills needed, including interpersonal and presentation skills, integrity, and stress resilience. Emphasize problem-solving, following procedures, clear communication, technical skills, and prior support experience to handle incidents unsupervised.
Audits verify adherence to policies through structured examinations, both internal and external. They help teams address issues promptly and document findings to demonstrate compliance.
Apply business impact assessment concepts to determine asset loss impact on the business, prioritize outages, and use risk management and assessment data to guide decisions.
Assess asset responsibilities and prioritize incident response by evaluating recovery time objectives and recovery point objectives to guide resource allocation and data restoration timing and backup choices.
Recognize that incident response plans vary by guidance and phase. Align your IRP with a chosen framework, tailor it to your organization, and train teams to coordinate resources.
The Certified Information Security Manager (CISM) course helps the candidates to achieve the CISM certification. The certification is offered by the Information Systems Audit and Control Association (ISACA) to validate the expertise and knowledge of the candidates regarding the relationship between an information security program and the broader business targets. The certification also validates that the candidate has the hands-on knowledge of developing, managing and implementing an information security program for an organization.
CISM certification is a certification by ISACA for experienced Information security management professionals with work experience in developing and managing information security programs. The CISM course covers the four domains of the CISM certification exam. The course is an ideal preparatory course for the students seeking to gain CISM certification as well as the IT security and information security professionals looking to build on their practical experience.
As the case with the CISM certification exam, the candidates are required to have a minimum of five years of experience in information security management. Experience in the fields of information security governance, risk management, compliance, and incident management is also preferable.
The course includes following topics
Introduction to the CISM
IT Governance
Information Risk Management
Security Program Management and Development
Incident Management and Response