Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CISM Certification Exam Preparation Course
New

CISM Certification Exam Preparation Course

Exam-focused preparation covering all 4 CISM domains: Governance, Risk, Program, and Incident Management
Created byAseem Mankotia
Last updated 9/2026
English

What you'll learn

  • Align information security strategy with enterprise business objectives
  • Build and communicate security governance frameworks to boards and senior management
  • Apply qualitative and quantitative risk assessment methodologies (ALE, SLE, ARO)
  • Determine risk appetite, tolerance, and appropriate risk treatment options
  • Design and resource an information security program and justify controls from a management perspective

Course content

2 sections • 12 lectures
  • CISM Overview and Security Governance Foundations17:31
  • Governance Structures, Roles, and Regulatory Requirements16:29
  • Risk Identification and Assessment Methodologies13:23
  • Risk Appetite, Treatment, and Enterprise Risk Reporting15:04
  • Security Program Development, Frameworks, and Resourcing16:20
  • Control Design, Selection, and Security Architecture Oversight15:30
  • Third-Party Risk, Awareness, and Training Programs14:22
  • Program Metrics, KPIs/KRIs, and SDLC Integration18:47
  • Incident Response Readiness, Plans, and Classification18:31
  • Incident Detection, Response, and Business Continuity Integration18:36
  • Post-Incident Review, Root Cause, and Regulatory Communication15:31
  • Full CISM Exam Simulation and Test-Taking Strategy15:06

Requirements

  • Working experience in information security, IT risk, or IT audit (CISM certification requires 5 years, with waivers)
  • Basic familiarity with enterprise IT and security concepts; prior exposure to ISO 27001, NIST, or COBIT helpful

Description

This course contains the use of artificial intelligence.

This course by Aseem Mankotia delivers exam-focused preparation for ISACA's Certified Information Security Manager (CISM) exam, a management-track credential that complements technical certifications like CISSP and ISACA's newer AI credentials (AAIR, AAISM). CISM tests management judgment, not hands-on engineering — the exam rewards candidates who can think like a security leader, align security decisions with business objectives, and prioritize governance and risk over technical implementation. Aseem Mankotia walks through all four official CISM domains in their weighted order — Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%) — with the heaviest chapter time devoted to Program and Incident Management, which together represent nearly two-thirds of the exam content outline.

Each chapter maps directly to an exam domain and sub-topic, covers heavily-tested concepts with concrete enterprise scenarios, and includes a scenario-based exercise or worksheet — no paid tooling required — to reinforce decision-making frameworks like risk registers, RACI charts, control gap analysis, incident severity matrices, and executive KPI/KRI dashboards. Every chapter highlights common exam traps, such as choosing a technical answer over a governance one, and teaches the classic CISM answering mindset: prioritize business alignment, choose strategy over tools, and select the answer that addresses the root management issue rather than the symptom.

Before scheduling the exam, understand that passing CISM's 150-question, 4-hour exam (scored 200–800, passing score 450, approximately USD 575 for non-members and USD 460 for ISACA members, subject to change) is one step toward full certification, which also requires five years of information security work experience — at least three in security management — with allowed waivers, plus ongoing CPE maintenance. Always verify the current exam content outline, format, fees, and experience requirements on ISACA's official CISM page before scheduling. The final chapter is a full 150-question exam simulation walkthrough with a 4-hour time-management plan and the 'think like a manager' answering strategy to tie every domain together.

AI content disclosure: This course was produced with the assistance of artificial intelligence tools. Lecture narration is AI-voice generated, and lecture scripts, slides, and practice questions were drafted with AI assistance, then reviewed and curated by the instructor for technical accuracy and alignment with the official CISM exam guide.

Who this course is for:

  • Information security managers and leaders, and practitioners moving from technical roles into management
  • Aspiring and current CISOs, IT/security directors, risk and governance leads, and security consultants