Certified Information Security Manager (CISM) Training in Spain

  • Delivery Method: Online Instructor-Led / Classroom Based / Onsite
  • Participation Model: Public Training / Private / In-House Training
  • Duration: 4 Days
  • Level: Expert
  • Price: From €3,700 +TAX
  • Upcoming Date:
  • UK & Spain Based Global Training Provider
  • Build the expertise to design, deploy, and manage security architecture confidently across your organisation.
  • Designed for security managers, CISOs, and professionals who require strong governance and risk management capabilities.
  • ISACA-aligned training designed to provide comprehensive preparation for the CISM examination.


The Certified Information Security Manager (CISM) training course focuses on the development, implementation, and governance of information security operations. The CISM certification demonstrates professional knowledge, practical capability, and experience in information security management.

The course goes beyond theoretical security concepts by addressing practical areas such as developing information security programmes, managing organisational risk, and responding to security incidents. Participants learn how evolving technologies and security requirements can be managed in accordance with the needs and objectives of an organisation.

Rather than approaching information security purely as a technical discipline, CISM connects security management with wider organisational goals. This enables security professionals to understand how information security programmes can support business priorities and contribute to effective enterprise governance.

This certification is a DoD Approved 8570 Baseline Certification and meets DoD 8140/8570 training requirements.

As demand for experienced information security management professionals continues to grow, CISM has become a widely recognised professional certification within the information security field. It is particularly relevant to professionals responsible for security governance, risk management, security programme management, and incident management.

CISM is structured around four domains:

  1. Information Security Governance
  2. Information Risk Management
  3. Information Security Program Development and Management
  4. Information Security Incident Management

This course includes the official ISACA CISM Exam and the official ISACA Exam Prep Tool.


Prerequisites

There are no mandatory prerequisites for studying the CISM subject matter. However, candidates wishing to obtain the CISM certification must satisfy the certification requirements established by ISACA.

These requirements include:

  • Passing the CISM examination
  • Submitting an application for CISM certification
  • Paying a $50 application fee directly to ISACA
  • Adhering to the ISACA Code of Professional Ethics
  • Committing to the Continuing Professional Education (CPE) Programme
  • Complying with applicable information security standards

The examination is open to individuals interested in information security. However, a minimum of five years of professional information systems auditing, control, or security work experience is required before the CISM certification can be awarded.

Who Should Attend

CISM is a globally recognised professional certification within the IT and information security field. This training is particularly suitable for:

  • Security consultants and managers
  • IT directors and managers
  • Security auditors and architects
  • Security systems engineers
  • Chief Information Security Officers (CISOs)
  • Information security managers
  • IS/IT consultants
  • Chief Compliance, Privacy, and Risk Officers

The roles above represent a suggested audience rather than a restriction. Professionals may also attend according to their career aspirations, development goals, or organisational responsibilities.

What You Will Learn

The CISM course is designed to develop the skills required to design, deploy, and manage security architecture and information security programmes within an organisation.

The programme is aligned with ISACA information security management practices and structured to support participants preparing for the CISM examination.

By completing the training, participants will develop their ability to:

  • Understand and evaluate information security governance
  • Identify, assess, and manage information security risks
  • Develop and manage enterprise information security programmes
  • Monitor the effectiveness and performance of security programmes
  • Establish and manage information security incident processes
  • Align security, governance, compliance, and risk activities with organisational objectives

CISM Domain Weightings

The CISM examination is divided across four domains with the following weightings:

DomainExam Weight
Domain 1: Information Security Governance17%
Domain 2: Information Risk Management20%
Domain 3: Information Security Program Development and Management33%
Domain 4: Information Security Incident Management30%
Total100%

Training Outline

Introduction to CISM

The introductory section establishes the fundamental principles and objectives that support the remainder of the programme.

Topics include:

  • Introduction to Certified Information Security Manager (CISM)
  • Course objectives and expectations
  • What is information security?
  • Goals of information security
  • Principles for information security professionals

Domain 1 – Information Security Governance

This domain examines how information security should be governed across an organisation and how security strategy can be aligned with enterprise objectives.

Topics include:

  • Introduction to information security governance
  • Effective information security governance
  • Governance and third-party relationships
  • Information security metrics
  • Information security governance metrics
  • Information security strategy
  • Developing an information security strategy
  • Strategy resources and constraints
  • Other frameworks
  • Compliance requirements
  • Action plans for implementing strategy
  • Governance of enterprise IT

Domain 2 – Information Risk Management

This domain covers the practices organisations use to identify, assess, monitor, document, and manage information security risks.

Topics include:

  • Information risk management
  • Risk management overview
  • Risk assessment
  • Information asset classification
  • Assessment management
  • Information resource valuation
  • Recovery Time Objectives
  • Security control baselines
  • Risk monitoring
  • Training and awareness
  • Information risk management documentation

Domain 3 – Information Security Program Development and Management

This domain focuses on the development, implementation, administration, and continuous management of enterprise information security programmes.

Topics include:

  • Information security programme management overview
  • Information security programme objectives
  • Information security programme concepts
  • Technology resources for information security programmes
  • Information security programme development
  • Information security programme frameworks
  • Information security programme roadmaps
  • Enterprise Information Security Architecture (EISA)
  • Security programme management and administration
  • Security programme services and operational activities
  • Controls
  • Security programme metrics and monitoring
  • Measuring operational performance
  • Common information security programme challenges

Domain 4 – Information Security Incident Management

This domain addresses the processes and resources required to prepare for, respond to, recover from, and review information security incidents.

Topics include:

  • Incident management overview
  • Incident management procedures
  • Incident management resources
  • Incident management objectives
  • Incident management metrics and indicators
  • Defining incident management procedures
  • Business continuity and disaster recovery procedures
  • Post-incident activities and investigation

Ethics, Regulations, and Professional Responsibilities

The course also addresses professional, ethical, and regulatory considerations relevant to information security managers.

Topics include:

  • ISACA Code of Professional Ethics
  • Laws and regulations
  • Organisational policy versus law
  • Ethics and the Internet
  • Certified Information Security Manager professional responsibilities


ISACA Product Access Period Changes

Important Update Effective 16 April 2026

Effective 16 April 2026, ISACA is reducing product access periods from 12 months to 6 months across a range of products, including Exams, QAE, Online Review Courses, non-sponsored Webinars, and Virtual Workshops.

How the New Access Windows Work

1. Assignment and Redemption Window

Products must be assigned and redeemed within six months of the purchase date.

2. Access and Completion Window

Once a product has been redeemed, learners receive six months of access to use it. Depending on the relevant product, this period includes:

  • Accessing learning content
  • Scheduling examinations
  • Sitting examinations

What This Means for Learners

Review Manuals: Learners continue to receive long-term access.

QAE Databases & Online Review Courses: Available for six months following redemption.

Exams: Must be scheduled and completed within six months of redemption.

Learners are encouraged to redeem their products promptly and plan their study and examination schedules early to make effective use of the available access period.

Exams and Assessments

The course fee includes the official ISACA CISM Exam and the official ISACA Exam Prep Tool.

To achieve the CISM certification, candidates must successfully complete the examination and submit a certification application to ISACA. They must also pay the $50 application fee directly to ISACA, adhere to the ISACA Code of Professional Ethics, and commit to the Continuing Professional Education (CPE) Programme.

A minimum of five years of professional information systems auditing, control, or security work experience is required before the CISM certification can be awarded.

Under ISACA's updated product access policy effective 16 April 2026, learners have six months following redemption to access applicable learning content, schedule their examination, and sit the exam. Candidates are therefore encouraged to redeem their products promptly and plan their study and examination schedule accordingly.

Why Choose Us

Experience Certified Information Security Manager (CISM) in Spain through Bilginç IT Academy's live and interactive virtual classroom environment. Join a Public course as an individual delegate or arrange a dedicated Private / In-house online training program exclusively for your organization.

  • Delivery Method: Online Instructor-Led
  • Participation Model: Public / Private (In-house)
  • Live and Interactive Training: Connect with your instructor in real time and actively participate through discussions, Q&A sessions, practical exercises, and group activities.
  • Flexible Participation: Join the training from your home, office, or any location with a suitable internet connection.
  • Expert Trainer Network: Learn from experienced trainers with strong industry backgrounds and practical field expertise.
  • Over 30 Years of Training Expertise: Benefit from Bilginç IT Academy's professional training experience since 1995.
  • Worldwide Access: Join our live virtual classrooms from Spain or anywhere else in the world, or arrange a dedicated online training program for your organization.

Experience Certified Information Security Manager (CISM) through face-to-face Classroom Based training in Spain. Training can be delivered as a Public course open to individual delegates or as a dedicated Private / In-house class for your organization.

  • Delivery Method: Classroom Based
  • Participation Model: Public / Private (In-house)
  • Face-to-Face Learning: Interact directly with your instructor and fellow delegates in an engaging classroom environment.
  • Experienced Trainers: Learn from specialists with extensive industry experience and practical real-world knowledge.
  • Professional Training Environment: Attend training in comfortable, well-equipped classrooms designed to support effective learning.
  • Practical Learning: Depending on the course, reinforce your knowledge through hands-on exercises, scenarios, case studies, and instructor-led activities.

Arrange Certified Information Security Manager (CISM) in Spain as a dedicated Onsite training program for your organization. Bilginç IT Academy trainers can deliver the training at your office or another location of your choice, with the program planned around your team's requirements and business objectives.

  • Delivery Method: Onsite
  • Participation Model: Private (In-house)
  • Training at Your Preferred Location: Organize the training at your company's office or another location selected by your organization.
  • Tailored Course Content: Adapt the training program to your projects, team structure, existing skill levels, and specific business requirements.
  • Team-Focused Learning: Develop your team around a shared knowledge base while strengthening internal collaboration and knowledge transfer.
  • Flexible Scheduling: Plan the training dates, location, and program according to your organization's operational requirements.
  • Worldwide Onsite Delivery: Arrange the training in Spain or at another preferred location worldwide. Bilginç IT Academy trainers can travel to your selected location to deliver the dedicated training program.


Contact us for more detail about our trainings and for all other enquiries!

Certified Information Security Manager (CISM) Training Course in Spain Schedule

Join our public courses in our Spain facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

We can organize this training at your preferred date and location.
11 octubre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
25 octubre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
31 octubre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
08 noviembre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
15 noviembre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
22 noviembre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
26 noviembre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX
30 noviembre 2026 (4 Days)
Madrid, Barcelona, Valencia, Seville
€3,700 +TAX

Blog posts related to Certified Information Security Manager (CISM) Training Course in Spain

Other trainings and courses related to the Certified Information Security Manager (CISM)

Spain has rapidly transformed into one of Europe's most vibrant technology ecosystems, with Madrid, Barcelona, and Valencia emerging as major global innovation hubs. The country is home to prestigious institutions like the Polytechnic University of Catalonia and IE Business School, which fuel the growth of sectors ranging from telecommunications to renewable energy tech. As a leading destination for digital nomads and multinational tech headquarters, Spain prioritizes digital literacy and high-level software engineering skills. Our training programs in Spain are designed to support this flourishing market, providing certifications in Cloud Computing, Cybersecurity, and Data Science. We help professionals across the Iberian Peninsula stay ahead of industry trends and drive the digital transformation of Spain’s increasingly diversified and high-tech economy.

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.