Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Masterclass - CISM Exam (Updated 2025)
Rating: 4.4 out of 5(2,033 ratings)
13,839 students

Masterclass - CISM Exam (Updated 2025)

Hemang Doshi's course for ISACA's Certified Information Security Manager (CISM) Exam - Updated 2025
Last updated 7/2026
English
English [Auto],Spanish [Auto],

What you'll learn

  • Certified Information Security Manager ( ISACA - CISM) Lectures
  • This course contains all the 4 domains of CISM Review Manual
  • Candidate will able to understand practical aspects of Information Security requirements of the organizations
  • Candidate will able to confidently attempt and pass the CISM exam

Course content

4 sections177 lectures17h 3m total length
  • Information Security Governance - Video Lecture6:38

    Align information security governance with business objectives, establish a steering committee and policies, and create a roadmap using top-down governance to achieve secure, available systems.

  • Information Security Governance - QAE - Video Lecture7:04

    Explore information security governance through questions that emphasize defining security strategy, building policies and procedures, aligning with business strategy, and prioritizing projects with a steering committee in a top-down approach.

  • Information Security Governance - Notes6:45
  • Governance Framework - Video Lecture4:04

    Discover how governance frameworks provide a flexible structure and outline to support information security strategy and program development, with ISO twenty seven thousand one and Corbet as common examples.

  • Governance Framework - Notes2:58
  • Information Security Governance & Governance Framework - Practice Questions
  • Retention of Business Records - Video Lecture6:11

    Explore record retention essentials, including policy-driven data destruction, two- and three-year retention periods, and the role of electronic discovery in legal investigations.

  • Retention of Business Records - Notes5:26
  • Retention of Business Records - Practice Questions
  • Organization Structure - Video Lecture4:39

    Explore how organization structure, roles, and reporting hierarchy shape security strategy; prioritize a top-down governance approach to align policies and risk with business objectives.

  • Organization Structure - Notes3:18
  • Centralized and Decentralized Functions - Video Lecture4:15

    Compare centralized and decentralized security functions, showing centralized control yields uniform policies and slower turnaround, while decentralized units enable better alignment and faster processing with higher resource needs.

  • Centralized and Decentralized Functions - Notes7:20
  • Organization Structure & Central & Decentralized Function - Practice Questions
  • Information Security Roles & Responsibilities - Video Lecture6:36

    Define and communicate information security roles and responsibilities across the organization, including board, senior management, business process owners, steering committee, and data custodians, based on job functions.

  • Information Security Roles & Responsibilities - Key Aspects - Video Lecture8:29

    Clarify information security roles and responsibilities across board, senior management, data owners, custodians, and administrators. Prioritize risk-based access, data retention, and data classification.

  • Information Security Roles & Responsibilities - QAE - Video Lecture7:20
  • Information Security Roles & Responsibilities - Notes8:28
  • Information Security Roles & Responsibilities - Practice Questions
  • Maturity Model - Video Lecture6:13
  • Maturity Model - Notes3:45
  • Maturity Model - Practice Questions
  • Information Security Governance Metrics - Video Lecture4:34

    Explore information security governance metrics and define metrics as measurements of process performance that aid management decisions. Compare technical and governance metrics guided by SMART criteria for timely risk assessment.

  • Information Security Governance Metrics -QAE - Video Lecture5:35

    Explore practice questions on information security governance metrics, focusing on effective metrics for security-related decision making and evaluating incident occurrence, unplanned business interruptions, and alignment via the balanced scorecard.

  • Information Security Governance Metrics - Notes4:41
  • Information Security Governance Metrics - Practice Questions
  • Information Security Strategy and Plan - Video Lecture3:01

    Align information security strategy with business objectives to define what, how, and when actions. Use the security policy as the guiding document for procedures and architectures.

  • Information Security Strategy and Plan - Key Aspects - Video Lecture5:46

    Explore aligning information security strategy and plan with business objectives, justify programs, adapt policies to local laws, balance controls with user needs, and value assets by revenue potential.

  • Information Security Strategy and Plan - QAE - Video Lecture7:08

    Practice questions on information security strategy and plan emphasize alignment with the current business strategy and desired future state, including audits and the chief information security officer's role.

  • Information Security Strategy and Plan - Notes5:32
  • Information Security Strategy and Plan - Practice Question
  • Information Security Program - Practice Question
  • Enterprise Information Security Architecture - Video Lecture4:28

    Explore enterprise information security architecture within the enterprise blueprint, showing how processes, systems, data and people interrelate to support business goals and improve security posture through defined controls.

  • Enterprise Information Security Architecture - Notes4:06
  • Enterprise Information Security Architecture - Practice Questions
  • Awareness and Education - Video Lecture2:10

    Enhance information security through awareness and education by delivering customized training tailored to roles, such as secure coding for developers and security basics for data-entry operators.

  • Awareness and Education - Notes3:08
  • Governance, Risk and Compliance - Video Lecture4:38

    Explore governance, risk and compliance (GRC) integration to align assurance activities, improve risk management, and avoid duplication across finance and legal processes.

  • Governance, Risk and Compliance - Notes1:50
  • Governance, Risk and Compliance - Practice Questions
  • Senior Management Commitment - Video Lecture2:25

    Drive information security success through strong senior management commitment and sponsorship. Align governance with business objectives and justify security investments with cost-benefit analysis.

  • Senior Management Commitment -- Key Aspects - Video Lecture2:13

    Senior management commitment requires a clear cost-benefit analysis and value analysis, showing how security risks affect key business objectives to secure budget approval for information security projects.

  • Senior Management Commitment - QAE- Video Lecture6:49

    Senior management commitment drives information security success through cost-benefit analysis for budgets. It supports policies, funding, and strategic alignment with key business stakeholders, and aligns with risk management methodology.

  • Senior Management Commitment - Notes2:56
  • Senior Management Commitment - Practice Questions
  • Business Case and Feasibility Analysis - Video Lecture2:47

    Define the need and justification via a business case to support project initiation. Assess feasibility by evaluating economic, technical, and legal factors to confirm practicality within budget and security requirements.

  • Business Case and Feasibility Analysis - Key Aspects - Video Lecture2:02

    Justify a new project with a business case and visibility analysis. Use gap analysis, legal requirements, and expected losses; define the need and issues via a visibility and value report.

  • Business Case and Feasibility Analysis - QAE 1 - Video Lecture6:18

    Explore how to craft a business case and visibility analysis, defining the need, justification, and expected value, to secure senior management support for security initiatives by comparing benefits to costs.

  • Business Case and Feasibility Analysis - Notes4:17
  • Business Case and Feasibility Analysis - Practice Questions
  • Governance of Third-Party - Video Lecture2:15

    The information security manager guides alignment of culture, technology compatibility, incident management, and disaster recovery to manage third-party risk and protect data access.

  • Governance of Third-Party - Key Aspects - Video Lecture2:30

    Govern third-party relationships by defining control processes for new regulatory requirements with input from affected departments, assess impacts on processes and controls, and protect identifiable personal data per organizational goals.

  • Governance of Third-Party - QAE 1 - Video Lecture6:17

    Discusses governance of third-party relationships and practice questions for BYOD, regulatory impacts, and retention policy considerations in information security.

  • Governance of Third-Party - Notes4:22
  • Governance of Third-Party - Practice Questions

Requirements

  • No prior knowledge or experience is required. We will teach you everything from basics to pass the CISM Exam.

Description

(Note: CISA Exam is conducted by ISACA. This course is private course and not affiliated with ISACA)

This course is designed on the basis of official resources of ISACA. It covers all the 4 domains of CISM Review Manual. Topics are arranged segment wise and aligned with latest CISM Review Manual.


Course is designed specifically for candidates from non-technical background. Video contents are designed after considering three major aspects:


(1) Whether content has capability to engage the audience throughout?

(2) Whether content is able to convey the meaning of CISM Review Manual (CRM) in a effective manner.

(3) Whether video has capability to make audience understand and retain the key aspects for a longer duration.


Features of this course are as follow:


  • This course is designed on the basis of official resources of ISACA.


  • Course is designed specifically for candidates from non-technical background.


  • Topics are arranged segment wise and aligned with latest CISM Review Manual.

  • Exam oriented practice questions and practical example for CISM aspirants.


  • Flashcards based learning mode.


  • Use of smartarts for easy learning


  • More than 700 plus practice questions


Please use this course as a supplement to ISACA's resources. This course will help you to decipher the technicities used in official resources. This course is specfically designed for the candidates from non IT background. We have used simple and plain English for the  benefits of the candidates from non - English speaking countries.



Who this course is for:

  • Information Security Professionals
  • IT Auditors
  • Risk Manager