CISM Certified Information Security Manager

Level: Expert

Develop Advanced Information Security Leadership Skills
Master Security Governance, Risk, Program & Incident Management
Prepare for the Globally Recognised ISACA CISM Certification
Our Exam Pass Guarantee Included*
Welsh Government Funding Accepted

Course Overview

Duration: 4 Days (9:30am-5:00pm) Accredited: Available upon request Exams: Not included Funding: ReAct Type: Classroom, Onsite, Virtual Company group booking discount available
This intensive four-day course will help you prepare for ISACA’s Certified Information Security Manager (CISM) examination. You’ll develop an understanding of information security governance, risk management, security programme development and incident management. The course focuses on the responsibilities and decisions faced by information security managers, helping you connect security strategy [...]

This intensive four-day course will help you prepare for ISACA’s Certified Information Security Manager (CISM) examination.

You’ll develop an understanding of information security governance, risk management, security programme development and incident management. The course focuses on the responsibilities and decisions faced by information security managers, helping you connect security strategy with organisational objectives.

You’ll review the four CISM domains, strengthen your understanding of key concepts and work through practice questions designed to support your examination preparation.

Please note: ISACA will introduce an updated CISM examination content outline on 3 November 2026. The examination content you need to study will depend on the date on which you intend to sit your exam.

Target Audience

This course is suitable for:

  • Information security managers
  • Cybersecurity managers and team leaders
  • Information security consultants
  • IT governance and risk professionals
  • Security programme managers
  • IT managers moving into information security leadership
  • Experienced security professionals preparing for the CISM examination

By the End of This Course, You Will Be Able To

  • Explain how information security governance supports organisational objectives.
  • Develop and maintain an information security strategy.
  • Assess, prioritise and communicate information security risks.
  • Recommend appropriate risk treatment and security controls.
  • Develop and manage an information security programme.
  • Monitor programme performance using appropriate measures.
  • Establish and maintain incident management capabilities.
  • Support incident detection, investigation, containment and recovery.
  • Approach CISM examination questions with greater confidence.
This intensive four-day course will help you prepare for ISACA’s Certified Information Security Manager (CISM) examination. You’ll develop an understanding of information security governance, risk management, security programme development and incident management. The course focuses on the responsibilities and decisions faced by information security managers, helping you connect security strategy [...]

This intensive four-day course will help you prepare for ISACA’s Certified Information Security Manager (CISM) examination.

You’ll develop an understanding of information security governance, risk management, security programme development and incident management. The course focuses on the responsibilities and decisions faced by information security managers, helping you connect security strategy with organisational objectives.

You’ll review the four CISM domains, strengthen your understanding of key concepts and work through practice questions designed to support your examination preparation.

Please note: ISACA will introduce an updated CISM examination content outline on 3 November 2026. The examination content you need to study will depend on the date on which you intend to sit your exam.

Target Audience

This course is suitable for:

  • Information security managers
  • Cybersecurity managers and team leaders
  • Information security consultants
  • IT governance and risk professionals
  • Security programme managers
  • IT managers moving into information security leadership
  • Experienced security professionals preparing for the CISM examination

By the End of This Course, You Will Be Able To

  • Explain how information security governance supports organisational objectives.
  • Develop and maintain an information security strategy.
  • Assess, prioritise and communicate information security risks.
  • Recommend appropriate risk treatment and security controls.
  • Develop and manage an information security programme.
  • Monitor programme performance using appropriate measures.
  • Establish and maintain incident management capabilities.
  • Support incident detection, investigation, containment and recovery.
  • Approach CISM examination questions with greater confidence.

CISM Certified Information Security Manager

Domain 1: Information Security Governance

  • Enterprise Governance Overview
  • Organisational Culture, Structures, Roles and Responsibilities
  • Legal, Regulatory and Contractual Requirements
  • Information Security Strategy
  • Information Governance Frameworks and Standards
  • Strategic Planning

Domain 2: Information Risk Management

  • Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment, Evaluation and Analysis
  • Information Risk Response
  • Risk Monitoring, Reporting and Communication

Domain 3: Information Security Program Development & Management

  • IS Program Development and Resources
  • IS Standards and Frameworks
  • Defining an IS Program Road Map
  • IS Program Metrics
  • IS Program Management
  • IS Awareness and Training
  • Integrating the Security Program with IT Operations
  • Program Communications, Reporting and Performance Management

Domain 4: Information Security Incident Management

  • Incident Management and Incident Response Overview
  • Incident Management and Response Plans
  • Incident Classification/Categorisation
  • Incident Management Operations, Tools and Technologies
  • Incident Investigation, Evaluation, Containment and Communication
  • Incident Eradication, Recovery and Review
  • Business Impact and Continuity
  • Disaster Recovery Planning
  • Training, Testing and Evaluation

CISM Certified Information Security Manager

Domain 1: Information Security Governance

  • Enterprise Governance Overview
  • Organisational Culture, Structures, Roles and Responsibilities
  • Legal, Regulatory and Contractual Requirements
  • Information Security Strategy
  • Information Governance Frameworks and Standards
  • Strategic Planning

Domain 2: Information Risk Management

  • Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment, Evaluation and Analysis
  • Information Risk Response
  • Risk Monitoring, Reporting and Communication

Domain 3: Information Security Program Development & Management

  • IS Program Development and Resources
  • IS Standards and Frameworks
  • Defining an IS Program Road Map
  • IS Program Metrics
  • IS Program Management
  • IS Awareness and Training
  • Integrating the Security Program with IT Operations
  • Program Communications, Reporting and Performance Management

Domain 4: Information Security Incident Management

  • Incident Management and Incident Response Overview
  • Incident Management and Response Plans
  • Incident Classification/Categorisation
  • Incident Management Operations, Tools and Technologies
  • Incident Investigation, Evaluation, Containment and Communication
  • Incident Eradication, Recovery and Review
  • Business Impact and Continuity
  • Disaster Recovery Planning
  • Training, Testing and Evaluation

The official CISM examination voucher is not included in the course price. You must register and pay for the examination directly through ISACA.

Examination Information

  • Examination: Certified Information Security Manager
  • Awarding body: ISACA
  • Number of questions: 150
  • Question format: Multiple-choice
  • Duration: Four hours
  • Passing score: 450 on ISACA’s scaled score of 200–800
  • Delivery: Remotely proctored or at an authorised PSI test centre
  • Examination voucher: Not included

The examination covers four domains:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Programme
  • Incident Management

ISACA is updating the CISM examination content outline from 3 November 2026. You should confirm that your training and study materials correspond with the examination version you will take.

Certification Requirements

Passing the CISM examination is only one part of becoming certified.

You must also:

  • Meet ISACA’s information security management experience requirements.
  • Submit a certification application and pay the applicable processing fee.
  • Agree to follow ISACA’s Code of Professional Ethics.
  • Comply with ISACA’s Continuing Professional Education policy.

You have five years from passing the examination to apply for CISM certification.

The official CISM examination voucher is not included in the course price. You must register and pay for the examination directly through ISACA.

Examination Information

  • Examination: Certified Information Security Manager
  • Awarding body: ISACA
  • Number of questions: 150
  • Question format: Multiple-choice
  • Duration: Four hours
  • Passing score: 450 on ISACA’s scaled score of 200–800
  • Delivery: Remotely proctored or at an authorised PSI test centre
  • Examination voucher: Not included

The examination covers four domains:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Programme
  • Incident Management

ISACA is updating the CISM examination content outline from 3 November 2026. You should confirm that your training and study materials correspond with the examination version you will take.

Certification Requirements

Passing the CISM examination is only one part of becoming certified.

You must also:

  • Meet ISACA’s information security management experience requirements.
  • Submit a certification application and pay the applicable processing fee.
  • Agree to follow ISACA’s Code of Professional Ethics.
  • Comply with ISACA’s Continuing Professional Education policy.

You have five years from passing the examination to apply for CISM certification.

  • Four days of instructor-led training and examination preparation delivered by an experienced CISM trainer.
  • Course notes and presentation slides.
  • Access to CISM practice questions, answers and explanations through an online voucher, normally valid for up to 12 months.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISACA.
  • Four days of instructor-led training and examination preparation delivered by an experienced CISM trainer.
  • Course notes and presentation slides.
  • Access to CISM practice questions, answers and explanations through an online voucher, normally valid for up to 12 months.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISACA.

There are no formal prerequisites for attending this course or sitting the CISM examination.

However, CISM is designed for experienced information security professionals and managers. You should have a good understanding of information security, risk, governance and incident management.

Passing the examination does not automatically make you CISM certified. You must also satisfy ISACA’s professional experience and application requirements.

There are no formal prerequisites for attending this course or sitting the CISM examination.

However, CISM is designed for experienced information security professionals and managers. You should have a good understanding of information security, risk, governance and incident management.

Passing the examination does not automatically make you CISM certified. You must also satisfy ISACA’s professional experience and application requirements.

Does this course include an Exam Pass Guarantee?

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Who is the CISM course suitable for?

Our course is designed for experienced information security professionals who want to move into, or develop within, management and leadership roles. It is particularly relevant to security managers and professionals responsible for governance, risk, security programmes or incident management.

Do I need security management experience to attend?

We do not state a formal prerequisite for attending the training. However, this is an expert-level, intensive exam-preparation course, so relevant information security knowledge and professional experience are strongly recommended.

Attending the course and meeting ISACA’s certification requirements are separate matters. Passing the exam alone does not automatically make you CISM certified.

View all FAQs

Does this course include an Exam Pass Guarantee?

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Who is the CISM course suitable for?

Our course is designed for experienced information security professionals who want to move into, or develop within, management and leadership roles. It is particularly relevant to security managers and professionals responsible for governance, risk, security programmes or incident management.

Do I need security management experience to attend?

We do not state a formal prerequisite for attending the training. However, this is an expert-level, intensive exam-preparation course, so relevant information security knowledge and professional experience are strongly recommended.

Attending the course and meeting ISACA’s certification requirements are separate matters. Passing the exam alone does not automatically make you CISM certified.

View all FAQs

Dates & Prices

Upcoming Courses
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 23 November 2026
£1,995.00 excl. VAT
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 07 December 2026
£1,995.00 excl. VAT

Can't find the course dates, location or delivery type you are looking for?

Fill out the request dates form above and we'll try our best to accommodate or contact us directly.

"*" indicates required fields

Name*
Number of Delegates*
Course Delivery Format*

How we deliver our courses

Virtual

Our virtual courses allow you to access live instructor-led training from the same expert instructors that deliver our classroom courses, without leaving the comfort of your home or office. All virtual courses are fully interactive, and learners can communicate with their trainer and peers at any time.

Many of our virtual courses are also recorded, so you can recap over the content you learnt as many time as you wish.

Find out more about Virtual learning

Classroom

Our classroom courses allow you to learn and interact face-to-face with our expert instructors in a comfortable and modern training environment. All of our classroom based courses take place at NILC centers, or high quality training facilities, and include all required IT and physical equipment.

We also limit our class sizes to help promote better discussions and to ensure your learning experience is comfortable as possible.

Find out more about Classroom learning

Onsite

Save time and hassle by arranging for one of our expert instructors to come to you. Our onsite courses allow you to learn in a location of your choosing, and you can train as many or as few people as you want – from a single person or team to whole departments. We can also fully customize the course content to the specific requirements of your business or project.

We offer onsite courses throughout the UK and it can be a great team building opportunity for colleagues to come together, bond and discuss.

Find out more about Onsite learning

Online

Our Online Self Paced courses allow you to learn new skills from our expert instructors, in your own time and at your own pace. Our flexible online learning platform allows you to access content on your computer, tablet or mobile device, whether you’re on the move or at home. All our online courses come with immediate access and you can start learning straight away, from any internet enabled compatible device.

We also offer online email support from our expert instructors, so they’re always on hand and happy to help you with any questions which may arise.

Find out more about Online learning

Why choose NILC for your training?

Award-Winning Training with Industry-Leading Customer Satisfaction

Trusted Training Partner by Colleges, Government Organisations and Businesses

UK-Based Trainers with Real-World Industry Experience

Family-Run Business with Customer Service at Its Core

Rated Excellent on Trustpilot with 950+ Customer Reviews

Our learners rate us 'Excellent' on Trustpilot

Frequently Asked Questions

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Our course is designed for experienced information security professionals who want to move into, or develop within, management and leadership roles. It is particularly relevant to security managers and professionals responsible for governance, risk, security programmes or incident management.

We do not state a formal prerequisite for attending the training. However, this is an expert-level, intensive exam-preparation course, so relevant information security knowledge and professional experience are strongly recommended.

Attending the course and meeting ISACA’s certification requirements are separate matters. Passing the exam alone does not automatically make you CISM certified.

We cover the four CISM domains:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Programme
  • Incident Management

The training explores security strategy, risk assessment, programme development, performance, incident response, recovery and business continuity.

CISM focuses primarily on managing information security rather than developing detailed technical implementation skills. It examines how organisations govern security, manage risk, develop security programmes and prepare for and respond to incidents.

Our course runs for four days, normally from 9 am to 5 pm. We offer classroom, live virtual and on-site delivery. Contact our team to discuss available dates or group training.

We provide course notes, presentation slides and access to CISM practice questions through an online voucher. The practice-question voucher is valid for up to 12 months and can be used during and after the course.

You should also allow time for independent revision and practice before attempting the examination.

No. The official CISM examination and exam voucher are not included in our course fee. You must register and pay for the exam separately through ISACA.

You can take the computer-based exam remotely under supervision or at an authorised PSI testing centre. Funded learners may be required to complete their exam within an earlier timeframe to comply with funding requirements, where examination funding applies.

No. Passing the exam is only one part of the certification process. You must also submit an application demonstrating that you meet ISACA’s experience requirements, pay the application fee, and comply with its professional ethics and continuing education policies.

You have five years from the date you pass the exam to apply for certification.

Frequently Asked Questions

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Our course is designed for experienced information security professionals who want to move into, or develop within, management and leadership roles. It is particularly relevant to security managers and professionals responsible for governance, risk, security programmes or incident management.

We do not state a formal prerequisite for attending the training. However, this is an expert-level, intensive exam-preparation course, so relevant information security knowledge and professional experience are strongly recommended.

Attending the course and meeting ISACA’s certification requirements are separate matters. Passing the exam alone does not automatically make you CISM certified.

We cover the four CISM domains:

  • Information Security Governance
  • Information Security Risk Management
  • Information Security Programme
  • Incident Management

The training explores security strategy, risk assessment, programme development, performance, incident response, recovery and business continuity.

CISM focuses primarily on managing information security rather than developing detailed technical implementation skills. It examines how organisations govern security, manage risk, develop security programmes and prepare for and respond to incidents.

Our course runs for four days, normally from 9 am to 5 pm. We offer classroom, live virtual and on-site delivery. Contact our team to discuss available dates or group training.

We provide course notes, presentation slides and access to CISM practice questions through an online voucher. The practice-question voucher is valid for up to 12 months and can be used during and after the course.

You should also allow time for independent revision and practice before attempting the examination.

No. The official CISM examination and exam voucher are not included in our course fee. You must register and pay for the exam separately through ISACA.

You can take the computer-based exam remotely under supervision or at an authorised PSI testing centre. Funded learners may be required to complete their exam within an earlier timeframe to comply with funding requirements, where examination funding applies.

No. Passing the exam is only one part of the certification process. You must also submit an application demonstrating that you meet ISACA’s experience requirements, pay the application fee, and comply with its professional ethics and continuing education policies.

You have five years from the date you pass the exam to apply for certification.

Trusted By

0