Introduction to CISM
The introductory section establishes the fundamental principles and objectives that support the remainder of the programme.
Topics include:
- Introduction to Certified Information Security Manager (CISM)
- Course objectives and expectations
- What is information security?
- Goals of information security
- Principles for information security professionals
Domain 1 – Information Security Governance
This domain examines how information security should be governed across an organisation and how security strategy can be aligned with enterprise objectives.
Topics include:
- Introduction to information security governance
- Effective information security governance
- Governance and third-party relationships
- Information security metrics
- Information security governance metrics
- Information security strategy
- Developing an information security strategy
- Strategy resources and constraints
- Other frameworks
- Compliance requirements
- Action plans for implementing strategy
- Governance of enterprise IT
Domain 2 – Information Risk Management
This domain covers the practices organisations use to identify, assess, monitor, document, and manage information security risks.
Topics include:
- Information risk management
- Risk management overview
- Risk assessment
- Information asset classification
- Assessment management
- Information resource valuation
- Recovery Time Objectives
- Security control baselines
- Risk monitoring
- Training and awareness
- Information risk management documentation
Domain 3 – Information Security Program Development and Management
This domain focuses on the development, implementation, administration, and continuous management of enterprise information security programmes.
Topics include:
- Information security programme management overview
- Information security programme objectives
- Information security programme concepts
- Technology resources for information security programmes
- Information security programme development
- Information security programme frameworks
- Information security programme roadmaps
- Enterprise Information Security Architecture (EISA)
- Security programme management and administration
- Security programme services and operational activities
- Controls
- Security programme metrics and monitoring
- Measuring operational performance
- Common information security programme challenges
Domain 4 – Information Security Incident Management
This domain addresses the processes and resources required to prepare for, respond to, recover from, and review information security incidents.
Topics include:
- Incident management overview
- Incident management procedures
- Incident management resources
- Incident management objectives
- Incident management metrics and indicators
- Defining incident management procedures
- Business continuity and disaster recovery procedures
- Post-incident activities and investigation
Ethics, Regulations, and Professional Responsibilities
The course also addresses professional, ethical, and regulatory considerations relevant to information security managers.
Topics include:
- ISACA Code of Professional Ethics
- Laws and regulations
- Organisational policy versus law
- Ethics and the Internet
- Certified Information Security Manager professional responsibilities
ISACA Product Access Period Changes
Important Update Effective 16 April 2026
Effective 16 April 2026, ISACA is reducing product access periods from 12 months to 6 months across a range of products, including Exams, QAE, Online Review Courses, non-sponsored Webinars, and Virtual Workshops.
How the New Access Windows Work
1. Assignment and Redemption Window
Products must be assigned and redeemed within six months of the purchase date.
2. Access and Completion Window
Once a product has been redeemed, learners receive six months of access to use it. Depending on the relevant product, this period includes:
- Accessing learning content
- Scheduling examinations
- Sitting examinations
What This Means for Learners
Review Manuals: Learners continue to receive long-term access.
QAE Databases & Online Review Courses: Available for six months following redemption.
Exams: Must be scheduled and completed within six months of redemption.
Learners are encouraged to redeem their products promptly and plan their study and examination schedules early to make effective use of the available access period.
Exams and Assessments
The course fee includes the official ISACA CISM Exam and the official ISACA Exam Prep Tool.
To achieve the CISM certification, candidates must successfully complete the examination and submit a certification application to ISACA. They must also pay the $50 application fee directly to ISACA, adhere to the ISACA Code of Professional Ethics, and commit to the Continuing Professional Education (CPE) Programme.
A minimum of five years of professional information systems auditing, control, or security work experience is required before the CISM certification can be awarded.
Under ISACA's updated product access policy effective 16 April 2026, learners have six months following redemption to access applicable learning content, schedule their examination, and sit the exam. Candidates are therefore encouraged to redeem their products promptly and plan their study and examination schedule accordingly.