CLS
Cybersecurity

CISM Certified Information Security Manager

The CISM course is designed to teach professionals international security practices and expertise to manage designs, administer and assess IT security for organizations of every size and scale

Total Duration
40 Hours
Level
Intermediate
Category
Cybersecurity
Partner
ISACA
About this course

About this course

In CISM course you will learn to build core competencies in maintaining and completely owning the security aspect of your organization's IT. Students develop critical thinking skills and sound judgment to perform tasks required to achieve CISM certification. The course focusses on giving knowledge to professionals with Information Security Governance covering creation of security policies, strategies and business cases. Understand what standards and frameworks are needed as best practice in meeting compliance. This will align the strategies with the business goals. Furthermore, it makes an individual understand the importance of Risk Management process along with how to develop and maintain an Information security program. He learns different ways to identify and respond to risks with asset classification.

Target Audience

Information Security Managers who manage enterprise information security program development and implementation.
IT Managers engaged in the process of aligning the information security strategy with business objectives.
Security professionals wanting to improve their skills in governance, risk management, security programs, and incident management.
Governance, Risk and Compliance professionals who work with security framework, policies, controls, and regulations.
IT Risk Professionals responsible for information security risk identification, assessment, treatment, monitoring, and reporting.

Prerequisites

Five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas.

Course Outline

  • Organizational Culture
  • Legal, Regulatory and Contractual Requirements
  • Organizational Structures, Roles and Responsibilities
  • Information Security Strategy Development
  • Information Governance Frameworks and Standards
  • Strategic Planning (e.g., Budgets, Resources, Business Case)
  • Emerging Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment and Analysis
  • Risk Treatment / Risk Response Options
  • Risk and Control Ownership
  • Risk Monitoring and Reporting
  • Information Security Program Resources (e.g., People, Tools, Technologies)
  • Information Asset Identification and Classification
  • Industry Standards and Frameworks for Information Security
  • Information Security Policies, Procedures and Guidelines
  • Information Security Program Metrics
  • Information Security Control Design and Selection
  • Information Security Control Implementation and Integrations
  • Information Security Control Testing and Evaluation
  • Information Security Awareness and Training
  • Management of External Services (e.g., Providers, Suppliers, Third Parties, Fourth Parties)
  • Information Security Program Communications and Reporting
  • Incident Response Plan
  • Business Impact Analysis (BIA)
  • Business Continuity Plan (BCP)
  • Disaster Recovery Plan (DRP)
  • Incident Classification/Categorization
  • Incident Management Training, Testing and Evaluation
  • Incident Management Tools and Techniques
  • Incident Investigation and Evaluation
  • Incident Containment Methods
  • Incident Response Communications (e.g., Reporting, Notification, Escalation)
  • Incident Eradication and Recovery
  • Post-Incident Review Practices
Learning outcomes

What you'll learn

Develop an effective information security strategy aligned with organizational goals, culture and business requirements.
Governance of Information Security
Information Security Program Development and Management
Assess emerging threats, vulnerabilities, and control deficiencies to identify and prioritize information security risks.
Design, implement and evaluate an effective information security program including policies, controls, resources and awareness initiatives.
Manage information assets through appropriate identification, classification, protection, and governance practices.
Develop and manage incident response, business continuity, and disaster recovery capabilities to support organizational resilience.
Coordinate incident investigation, containment, eradication, recovery, communication, and post-incident review activities.

Skills you'll learn

11 skills
Risk Management
Risk Assessment
Risk Analysis
Risk Monitoring
Security Strategy
Strategic Planning
Incident Response
Incident Recovery
Business Continuity
Disaster Recovery

Certificate

  • Attendance Certificate from CLS Learning Solutions
  • This course enables you to pass CISM Certified Information Security Manager Exam  


CISM Certified Information Security Manager

Potential Career Paths

Information Security Managers
IT Auditors
Cybersecurity Professionals
IT Risk Professionals
Compliance Professionals
Security Consultants
IT Managers