Course Description

The Certified Information Security Manager (CISM) program is an advanced training designed to develop professionals’ expertise in managing, designing, and governing enterprise information security programs. This course is aligned with the ISACA CISM certification domains, focusing on information security governance, risk management, program development, and incident management. Participants will gain the skills needed to lead cybersecurity strategy, align security with business objectives, manage security resources, and prepare for the globally recognized ISACA CISM certification exam.

Course Objectives

Upon the successful completion of this course, each participant will be able to:

  • Understand and apply ISACA CISM frameworks and cybersecurity governance best practices.
  • Establish and manage an enterprise information security governance structure.
  • Identify and manage information security risks aligned with business goals.
  • Develop and implement an information security program and security policies.
  • Manage security resources, performance metrics, and compliance requirements.
  • Design and oversee incident response and recovery processes.
  • Monitor and continuously improve security controls and security program maturity.
  • Prepare for the ISACA CISM exam using domain-based knowledge and practice questions.

Who Should Attend?

This course is designed for information security managers, IT managers, security consultants, risk managers, auditors, and cybersecurity professionals preparing for ISACA CISM certification.

Course Agenda

Registration

Welcome & Introduction

Pre-Test

Day 1: CISM Domain 1 – Information Security Governance

  • Introduction to CISM and ISACA frameworks
  • Governance concepts and security leadership responsibilities
  • Aligning security strategy with business objectives
  • Developing information security policies and governance structures
  • Roles of board, senior management, and security committees
  • Security metrics and reporting to management
  • Legal, regulatory, and compliance requirements overview

Day 2: CISM Domain 2 – Information Risk Management

  • Risk management principles and methodologies
  • Threats, vulnerabilities, and risk assessment techniques
  • Risk appetite, tolerance, and risk ownership
  • Risk treatment plans and mitigation strategies
  • Business impact analysis (BIA) and critical asset identification
  • Third-party and vendor risk management
  • Risk monitoring and reporting mechanisms

Day 3: CISM Domain 3 – Information Security Program Development & Management

  • Building and maintaining an enterprise security program
  • Program scope, structure, and implementation approach
  • Security awareness and training programs
  • Security architecture concepts and control frameworks (ISO 27001, NIST)
  • Budgeting, resource planning, and security investments
  • Security program KPIs and maturity models
  • Continuous improvement and audit readiness

Day 4: CISM Domain 4 – Information Security Incident Management

  • Incident response governance and lifecycle
  • Incident classification and escalation procedures
  • Detection, monitoring, and SOC integration
  • Incident containment, eradication, and recovery planning
  • Digital forensics basics and evidence preservation
  • Crisis communication and stakeholder coordination
  • Post-incident review, lessons learned, and corrective actions

Day 5: CISM Exam Readiness, Case Studies & Capstone Review

  • Integrated case studies across all 4 CISM domains
  • CISM exam structure, question patterns, and strategy
  • Common pitfalls and best answering techniques (ISACA style)
  • Full mock test / practice exam review
  • Final recap of governance, risk, program, and incident management

Post Test

End of the Course

Assessment Methodology

All courses conducted by EdTech will begin with a Pre-evaluation and end with a Post-evaluation. The instructor will evaluate the knowledge and skills of the participants according to the feedback given by participants. This will help to recognize the benefits and the level of knowledge gained by participants through the course.

Training Methodology

Facilitated by a highly qualified specialist, who has extensive knowledge and experience; this program will be conducted using extensively interactive methods, encouraging participants to share their own experiences and apply the program material to real-life work situations in order to stimulate group discussions and improve the efficiency of the subject coverage.

Percentages of the total course hour classification are:

  • ​40% Theoretical lectures, Concepts and approach
  • 20% Motivation to develop individual skill and Techniques
  • 20% Case Studies and Practical Exercises
  • 20% Topic General Discussions and interaction

Course Manual

Participants will be provided with comprehensive presentation material as reference manual. This presentation material is a compilation of core valuable information, references, presentation methods and inspiring reading which will be used as a part of the material guide.

Course Certificate

At the completion of the course, all participants who successfully accomplished the required contact hours will receive an EdTech Training Participation Certificate as a testimony to their commitment to professional development and further education.

Why Edtech ?

  • Industry Experienced; Internationally Qualified Trainers
  • Hands-on Practical Sessions & Assignments
  • Intensive Study materials
  • Flexible Schedules
  • Realistic training methodology
  • High-Quality Training in Affordable Course Fees
  • Achievement Certificate, as approved by the Ministry of Education (Abu Dhabi Center for Technical and Vocational Education Training - ACTVET), HABC, AWS, IAOSHE, SHRM, etc.