Information Security Management: Principles and Practices

Wishlist Share
Share Course
Page Link
Share On Social Media

About Course

Certified Information Security Manager indicates expertise in information security governance, program development and management, incident management and risk management. If you are a mid to advanced-career IT professional aspiring to senior management roles in IT security and control, CISM can get you the visibility you need.

What Will You Learn?

  • Understand the principles and best practices of information security governance.
  • Identify and manage information security risks within an organization.
  • Develop and implement an effective information security program.
  • Establish and maintain processes for incident management and response.
  • Prepare successfully for the CISM certification exam.

Course Content

Information Security Governance
This domain will provide you with a thorough insight into the culture, regulations and structure involved in enterprise governance, as well as enabling you to analyze, plan and develop information security strategies. Together, this will affirm high-level credibility in information security governance to stakeholders.

  • Introduction
  • Enterprise Governance
  • Organizational Culture
  • Legal, Regulatory and Contractual Requirements
  • Organizational Structures, Roles and Responsibilities
  • Information Security Strategy Development
  • Information Governance Frameworks and Standards
  • Strategic Planning (e.g., Budgets, Resources, Business Case)

Information Security Risk Management
This domain empowers you to analyze and identify potential information security risks, threats and vulnerabilities as well as giving you all the information about identifying and countering information security risks you will require to perform at management level.

Information Security Program
This domain covers the resources, asset classifications and frameworks for information security as well as empowering you to manage information security programs, including security control, testing, comms and reporting and implementation.

Incident Management
This domain provides in-depth training in risk management and preparedness, including how to prepare a business to respond to incidents and guiding recovery. The second module covers the tools, evaluation and containment methods for incident management.

Exam Preparation