Certified Information Security Manager (CISM)

September 14-17, 2026  -  Hybrid - Colorado Springs, CO, (in person & online)

About the Course

Certified Information Security Manager® (CISM®) affirms your ability to assess risks, implement effective governance, and proactively respond to incidents. With a highlight on emerging technologies such as AI and blockchain, it guarantees your skillset meets evolving security threats and industry requirements. By addressing top-of-mind concerns like data breaches and ransomware attacks, crucial for IT professionals, this certification ensures you are staying ahead of the pace of change.

CISM, launched in 2002, remains one of the few certifications that emphasizes security management rather than just technical proficiency. The program is designed for professionals aiming to bridge the gap between cybersecurity operations and broader business objectives. It is especially relevant today as organizations face evolving threats, compliance pressures, and increased demand for cybersecurity expertise at the executive level.

ISACA’s Certified Information Security Manager (CISM) certification has been named the Best Professional Certification Program at the 2025 SC Awards, recognized for its pivotal role in preparing cybersecurity professionals for leadership in an increasingly complex threat landscape.

Why Take It

Certified Information Security Manager® (CISM®) affirms your ability to assess risks, implement effective governance, and proactively respond to incidents. With a highlight on emerging technologies such as AI and blockchain, it guarantees your skillset meets evolving security threats and industry requirements. By addressing top-of-mind concerns like data breaches and ransomware attacks, crucial for IT professionals, this certification ensures you are staying ahead of the pace of change.

CISM-certified professionals are in demand globally, with more than 101,000 certifications issued across 188 countries. The credential requires five years of work experience and focuses on governance, risk management, and incident response. According to Skillsoft’s 2024 list of top-paying IT certifications, CISM continues to deliver high career value for professionals.

Cost

$3,495.00

What to Expect

The Certified Information Security Manager® (CISM®) exam consists of 150 questions covering 4 job practice domains, all testing your knowledge and ability on real-life job practices leveraged by expert professionals. NOTE: Students will receive an exam voucher as part of the course price. The voucher will be used to schedule your exam through ISACA at an authorized testing center based on availability.

Below are the key domains, subtopics and tasks candidates will be tested on:

DOMAIN 1 (17% of the exam)
Information Security Governance

This domain will provide you with a thorough insight into the culture, regulations and structure involved in enterprise governance, as well as enabling you to analyze, plan and develop information security strategies. Together, this will affirm high-level credibility in information security governance to stakeholders.

A–ENTERPRISE GOVERNANCE
Organizational Culture
  1. Legal, Regulatory and Contractual Requirements
  2. Organizational Structures, Roles and Responsibilities

B–INFORMATION SECURITY STRATEGY
Information Security Strategy Development
  1. Information Governance Frameworks and Standards
  2. Strategic Planning (e.g., Budgets, Resources, Business Case)

DOMAIN 2 (20% of the exam)
Information Security Risk Management

This domain empowers you to analyze and identify potential information security risks, threats and vulnerabilities as well as giving you all the information about identifying and countering information security risks you will require to perform at management level.

A–INFORMATION SECURITY RISK ASSESSMENT
Emerging Risk and Threat Landscape
  1. Vulnerability and Control Deficiency Analysis
  2. Risk Assessment and Analysis

B–INFORMATION SECURITY RISK RESPONSE
Risk Treatment / Risk Response Options
  1. Risk and Control Ownership
  2. Risk Monitoring and Reporting

DOMAIN 3 (33% of the exam)
Information Security Program

This domain covers the resources, asset classifications and frameworks for information security as well as empowering you to manage information security programs, including security control, testing, comms and reporting and implementation.

A–INFORMATION SECURITY PROGRAM DEVELOPMENT
Information Security Program Resources (e.g., People, Tools, Technologies)
  1. Information Asset Identification and Classification
  2. Industry Standards and Frameworks for Information Security
  3. Information Security Policies, Procedures and Guidelines
  4. Information Security Program Metrics

B–INFORMATION SECURITY PROGRAM MANAGEMENT
Information Security Control Design and Selection
  1. Information Security Control Implementation and Integrations
  2. Information Security Control Testing and Evaluation
  3. Information Security Awareness and Training
  4. Management of External Services (e.g., Providers, Suppliers, Third Parties, Fourth Parties)
  5. Information Security Program Communications and Reporting

DOMAIN 4 (30% of the exam)
Incident Management

This domain provides in-depth training in risk management and preparedness, including how to prepare a business to respond to incidents and guiding recovery. The second module covers the tools, evaluation and containment methods for incident management.

A–INCIDENT MANAGEMENT READINESS
Incident Response Plan
  1. Business Impact Analysis (BIA)
  2. Business Continuity Plan (BCP)
  3. Disaster Recovery Plan (DRP)
  4. Incident Classification/Categorization
  5. Incident Management Training, Testing and Evaluation

B–INCIDENT MANAGEMENT OPERATIONS
Incident Management Tools and Techniques
  1. Incident Investigation and Evaluation
  2. Incident Containment Methods
  3. Incident Response Communications (e.g., Reporting, Notification, Escalation)
  4. Incident Eradication and Recovery
  5. Post-Incident Review Practices

SUPPORTING TASKS
Identify internal and external influences on the organization that impact the information security strategy.
  1. Establish and/or maintain an information security strategy in alignment with organizational goals and objectives.
  2. Establish and/or maintain an information security governance framework.
  3. Integrate information security governance into corporate governance.
  4. Establish and maintain information security policies to guide the development of standards, procedures and guidelines.
  5. Develop business cases to support investments in information security.
  6. Gain ongoing commitment from senior leadership and other stakeholders to support the successful implementation of the information security strategy.
  7. Define, communicate and monitor information security responsibilities throughout the organization and lines of authority.
  8. Compile and present reports to key stakeholders on the activities, trends and overall effectiveness of the information security program.
  9. Evaluate and report information security metrics to key stakeholders.
  10. Establish and/or maintain the information security program in alignment with the information security strategy.
  11. Align the information security program with the operational objectives of other business functions.
  12. Establish and maintain information security processes and resources to execute the information security program.
  13. Establish, communicate and maintain organizational information security policies, standards, guidelines, procedures and other documentation.
  14. Establish, promote and maintain a program for information security awareness and training.
  15. Integrate information security requirements into organizational processes to maintain the organization’s security strategy.
  16. Integrate information security requirements into contracts and activities of external parties.
  17. Monitor external parties' adherence to established security requirements.
  18. Define and monitor management and operational metrics for the information security program.
  19. Establish and/or maintain a process for information asset identification and classification.
  20. Identify legal, regulatory, organizational and other applicable compliance requirements.
  21. Participate in and/or oversee the risk identification, risk assessment and risk treatment process.
  22. Participate in and/or oversee the vulnerability assessment and threat analysis process.
  23. Identify, recommend or implement appropriate risk treatment and response options to manage risk to acceptable levels based on organizational risk appetite.
  24. Determine whether information security controls are appropriate and effectively manage risk to an acceptable level.
  25. Facilitate the integration of information risk management into business and IT processes.
  26. Monitor for internal and external factors that may require reassessment of risk.
  27. Report on information security risk, including noncompliance and changes in information risk, to key stakeholders to facilitate the risk management decision-making process.
  28. Establish and maintain an incident response plan, in alignment with the business continuity plan and disaster recovery plan.
  29. Establish and maintain an information security incident classification and categorization process.
  30. Develop and implement processes to ensure the timely identification of information security incidents.
  31. Establish and maintain processes to investigate and document information security incidents in accordance with legal and regulatory requirements.
  32. Establish and maintain incident handling process, including containment, notification, escalation, eradication and recovery.
  33. Organize, train, equip and assign responsibilities to incident response teams.
  34. Establish and maintain incident communication plans and processes for internal and external parties.
  35. Evaluate incident management plans through testing and review, including table-top exercises, checklist review and simulation testing at planned intervals.
  36. Conduct post-incident reviews to facilitate continuous improvement, including root-cause analysis, lessons learned, corrective actions and reassessment of risk.

Location

Murray Security Services Training Academy
455 E Pike Peak Ave, Suite 306
Hybrid - Colorado Springs, CO, (in person & online) 80903
United States

Hybrid classes are held online and in person at our academy.

Have a Question?

Let's Talk

Phone: 1-719-645-8504

Fax: 1-800-375-8167

Visit Us

455 Pikes Peak Ave, Suite 306

Colorado Springs, CO

Email

info@murraysecurityservices.com

Support

Phone: 1-719-645-8504

Fax: 1-800-375-8167