CISM®: Certified Information Security Manager
Cybersecurity must be managed in line with organisational risks and priorities. Structure your programme, clarify responsibilities and prepare well-founded decisions for discussions with senior management. Strengthen your position as a security leader beyond technical choices alone.
- Duration
- 5 days 35 hours
- Code
- SEC19FR Code
- Certification
- CISM®: Certified Information Security Manager Certification
Accredited training for the CISM®: Certified Information Security Manager certification.
Presentation
Businesses facing increasing cyberthreats need managers who can lead information security strategically, beyond technical considerations alone. CISM is one of the most sought-after certifications in security governance, with a substantially revised syllabus taking effect on 3 November 2026.
This 5-day course covers the 4 official ISACA domains with their new weightings: information security governance (18%), risk management (20%), information security programme (33%) and incident management (29%). It incorporates two new topics: enterprise architecture and information security architecture. Every module combines methodological guidance with case studies drawn from real environments.
By the end of the programme, you will master information security governance and strategic management within an organisation and be ready to take the official CISM examination included in our offer. Passing can lead to the Certified Information Security Manager credential (see the Certification tab for details).
Objectives
By the end of this CISM course, you will be able to:
- define and lead an information security governance strategy aligned with business objectives;
- identify, assess and manage information security risks to support strategic decision-making;
- design, deploy and manage an information security programme, including its operational governance;
- prepare and coordinate security incident response to ensure business continuity;
- understand the fundamentals of enterprise architecture and information security architecture;
- prepare for and pass the CISM examination to earn the Certified Information Security Manager credential.
Program
Module 1: Structure information security governance
- Information security strategy and alignment with business objectives.
- Policies, standards and governance frameworks applicable to information security.
- Regulatory compliance and legal obligations relating to data protection.
Practical exercise
- Develop a governance strategy aligned with the strategic objectives of a representative organisation.
Module 2: Lead information security risk management
- Identify, assess and prioritise information security risks.
- Risk treatment methodologies and their integration into decision-making.
- Continuous risk monitoring and stakeholder communication.
Practical exercise
- Conduct a comprehensive risk assessment and propose a prioritised treatment plan.
Module 3: Design and manage an information security programme
- Design, deploy and manage resources for a security programme.
- Define performance metrics and report to senior management.
- Manage external providers and integrate security awareness.
Practical exercise
- Build a security programme plan covering resources, metrics and reporting.
Module 4: Understand enterprise and information security architecture
- Enterprise architecture fundamentals and their role in security governance.
- Information security architecture principles and integration into information systems.
- Align technology architecture with strategic security objectives.
Practical exercise
- Analyse an enterprise architecture and identify security integration points.
Module 5: Coordinate security incident management
- Prepare for, detect and respond to information security incidents.
- Forensic analysis principles and documentation of handled incidents.
- Business continuity and disaster recovery following a major incident.
Practical exercise
- Simulate a security incident response and document the associated continuity plan.
Module 6: Prepare for the CISM examination
- Review the question types and certification examination format.
- Take a full practice examination, with detailed answer review and results analysis.
- Examination success strategies: time management, reading questions and managing stress.
Audience
This course is designed for professionals responsible for strategic information security management, particularly:
- chief information security officers (CISOs) leading their organisation's security governance and strategy;
- information security consultants seeking certification of their governance and risk management expertise;
- security auditors assessing the maturity of clients' security programmes;
- chief information officers (CIOs) seeking greater authority on strategic cybersecurity issues;
- information security project managers involved in deploying organisational security programmes.
Prerequisites
This course requires:
- Professional experience: at least 5 years in information security management, including 3 years across at least 3 of the 4 CISM domains, as required by ISACA for certification.
- Theoretical foundations: general knowledge of governance, risk management and information security standards.
- Language skills: the ability to read and understand French or English, depending on the language selected for the materials and examination.
Note: a university qualification in information security, such as a master's degree in cybersecurity, or certain ISACA-recognised certifications, such as CISSP and CISA, may provide an experience waiver of up to 2 years against the 5-year requirement. Only one waiver may be applied at a time.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Mock exam
Course highlights
- Immediate management recognition: strengthen your strategic credibility with senior management through a globally recognised security governance certification.
- Aligned with the 2026 syllabus: up-to-date content incorporates the new ISACA weightings, with a full practice examination to assess your learning before the official test.
- ISACA-certified trainers: learn from ISACA member trainers specialising in security governance.
- French-language materials and examination: access the reference manual and QAE question database in French, with the examination also available in French.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
CISM® is a registered trademark of ISACA. Mention for educational purposes does not imply any commitment or partnership.
fr
en