Course Description

The Certified Information Security Manager (CISM) – Aligned Preparation Program is an intensive course designed to reflect the domains and competency areas of the globally recognized ISACA CISM certification.

CISM focuses on governance, risk management, information security program development, and incident management from a leadership perspective. This program prepares security professionals to move beyond technical operations into strategic security management and executive oversight roles.

Course Objectives

 Upon the successful completion of this course, each participant will be able to:

  • Design and implement an enterprise information security governance framework
  • Align security strategy with business objectives
  • Conduct and manage enterprise security risk assessments
  • Develop and manage an information security program
  • Establish effective incident management and response processes
  • Measure and report security performance to executive leadership
  • Integrate compliance, regulatory, and governance requirements
  • Prepare strategically for CISM-aligned knowledge domains

Who Should Attend?

This course is designed for information security managers, IT directors, cybersecurity leaders, risk and compliance professionals, and senior IT auditors transitioning into security management roles.

Course Agenda

Registration

Welcome & Introduction

Pre-Test

Day 1 – Information Security Governance

  • Establishing security governance frameworks
  • Aligning information security strategy with business goals
  • Security policies, standards, and procedures
  • Roles, responsibilities & accountability models
  • Security metrics and board-level reporting

Day 2 – Information Risk Management

  • Risk management frameworks & methodologies
  • Risk identification, analysis & evaluation
  • Risk response strategies (mitigate, transfer, accept, avoid)
  • Integrating security risk into enterprise risk management (ERM)
  • Third-party & supply chain security risk
  • Case Study: Conducting a Risk Assessment Simulation

Day 3 – Information Security Program Development & Management

  • Building a comprehensive security program
  • Security architecture & control frameworks
  • Resource planning & budgeting for security
  • Security awareness & training programs
  • Performance measurement & continuous improvement

Day 4 – Incident Management & Response

  • Incident response lifecycle
  • Cyber crisis management
  • Business continuity & disaster recovery alignment
  • Digital forensics overview (management perspective)
  • Post-incident review & lessons learned

Day 5 – Integration, Compliance & Executive Leadership

  • Regulatory & compliance considerations (global overview)
  • Security audits & assurance
  • Governance reporting to executives & boards
  • Ethical considerations in information security
  • CISM Domain Review & Practice Question Workshop

Post Test

End of the Course

Assessment Methodology

All courses conducted by EdTech will begin with a Pre-evaluation and end with a Post-evaluation. The instructor will evaluate the knowledge and skills of the participants according to the feedback given by participants. This will help to recognize the benefits and the level of knowledge gained by participants through the course.

Training Methodology

Facilitated by a highly qualified specialist, who has extensive knowledge and experience; this program will be conducted using extensively interactive methods, encouraging participants to share their own experiences and apply the program material to real-life work situations in order to stimulate group discussions and improve the efficiency of the subject coverage.

Percentages of the total course hour classification are:

  • ​40% Theoretical lectures, Concepts and approach
  • 20% Motivation to develop individual skill and Techniques
  • 20% Case Studies and Practical Exercises
  • 20% Topic General Discussions and interaction

Course Manual

Participants will be provided with comprehensive presentation material as reference manual. This presentation material is a compilation of core valuable information, references, presentation methods and inspiring reading which will be used as a part of the material guide.

Course Certificate

At the completion of the course, all participants who successfully accomplished the required contact hours will receive an EdTech Training Participation Certificate as a testimony to their commitment to professional development and further education.

Why Edtech ?

  • Industry Experienced; Internationally Qualified Trainers
  • Hands-on Practical Sessions & Assignments
  • Intensive Study materials
  • Flexible Schedules
  • Realistic training methodology
  • High-Quality Training in Affordable Course Fees
  • Achievement Certificate, as approved by the Ministry of Education (Abu Dhabi Center for Technical and Vocational Education Training - ACTVET), HABC, AWS, IAOSHE, SHRM, etc.