Course Description
General Information
Designed for IT professionals with technical expertise and experience in IS/IT security and control looking to transition from
team player to manager. CISM can add credibility and confidence to interactions with internal and external stakeholders, peers
and regulators.
This certification indicates expertise in information security governance, program development and management, incident
management and risk management. If you are a mid-career IT professional aspiring to senior management roles in IT security
and control, CISM can get you the visibility you need.
There are 150 Questions on the exam which must be completed in four hours. It is available online via remote proctoring and
at in-person testing centers where available.
CISM Certification Candidates CPE Overview
CISM is intended for information security professionals with at To maintain your CISM, you must earn and report a minimum
least five years of relevant work experience and at least three years of 120 CPE hours every three-year reporting cycle and at least
in the role of information security manager. Job titles include: 20 hours annually. CISM awards up to one hour of CPE for every
CISO one hour of instructor led training. Online review course earns 20
CPEs and Virtual Instructor-Led Training (VILT) earns 14 CPEs.
CSO
Security Director/Manager/Consultant Course Duration
IT Director/Manager/Consultant Online Course: Approximately 16 hours
Compliance/Risk/Privacy Director and Manager In-person training or VILT: 2–4 days
Course Topics
Domain 1: Information Security Governance Domain 3: Information Security Program, continued
Enterprise Governance Overview IS Program Metrics
Organizational Culture, Structures, Roles IS Program Management
and Responsibilities IS Awareness and Training
Legal, Regulatory and Contractual Requirements Integrating the Security Program with IT Operations
Information Security Strategy Program Communications, Reporting and Performance
Information Governance Frameworks and Standards Management
Strategic Planning Domain 4: Incident Management
Domain 2: Information Security Risk Management Incident Management and Incident Response Overview
Risk and Threat Landscape Incident Management and Response Plans
Vulnerability and Control Deficiency Analysis Incident Classification/Categorization
Risk Assessment, Evaluation and Analysis Incident Management Operations, Tools and Technologies
Information Risk Response Incident Investigation, Evaluation, Containment and
Risk Monitoring, Reporting and Communication Communication
Incident Eradication, Recovery and Review
Domain 3: Information Security Program
Business Impact and Continuity
IS Program Development and Resources
Disaster Recovery Planning
IS Standards and Frameworks
Training, Testing and Evaluation
Defining an IS Program Road Map
I S A C A G L O B A L | 1700 E. Golf Road | Suite 400 | Schaumburg, IL 60173 | USA | [Link] © 2022 ISACA. All Rights Reserved.
R2022-04