Skip to content
CBT Nuggets
DemoBook a Demo

ISACA CISM – Certified Information Security Manager

This CISM training prepares IT professionals to manage enterprise-level security governance, risk, and incident response. This online, self-paced course aligns with ISACA's latest Certified Information Security Manager exam and is ideal for roles like Information Security Manager, GRC Lead, or Risk Officer. You'll build leadership skills in threat modeling, risk treatment, and post-incident review, making it perfect for both CISM certification prep and recertification.

Updated June 2025

14Skills
99Videos
14hTotal

Who This Course Is For

This course is for mid- to senior-level IT professionals in security, risk, and governance roles. If you lead security programs, manage audits or incident response, or are preparing for the CISM exam, this course updates your skills to meet today’s regulatory and threat environment head-on.

Skills Your Team Will Gain

  • Design and align security strategy with business objectives
  • Conduct vulnerability and control gap analysis
  • Develop and evaluate business continuity plans
  • Manage third-party and supply chain security risks
  • Monitor incidents with tools like SIEMs and response playbooks
  • Communicate risk posture and incident response to stakeholders

Course Curriculum

One skill is free to watch — no signup needed. The other 13 premium skills unlock for your whole team with a CBT Nuggets plan.

Free skill preview

Creating An Information Security Program

Bob SalmansDuration: 1h 1m16 videos

Watch this complete skill free — the same trainer, videos, and labs your team gets with a plan.

Watch free skill
  • Creating An Information Security ProgramFree1h 1m · 16 videos
  • Premium skill.IS Program Resources1h 5m · 16 videos
  • Premium skill.Creating A Successful IS Program1h 7m · 15 videos
  • Premium skill.Organizational Roles and Using Metrics50m · 16 videos
  • Premium skill.Introduction To Risk Management1h 17m · 16 videos
  • Premium skill.Risk Management Frameworks and Processes57m · 14 videos
  • Premium skill.Managing Assets and Threats1h 11m · 16 videos
  • Premium skill.Information Security Risk Management1h 13m · 16 videos
  • Premium skill.Creating An Information Security Program58m · 15 videos
  • Premium skill.Information Security Operations60m · 15 videos
  • Premium skill.Managing An Information Security Program58m · 13 videos
  • Premium skill.Implementing and Managing Security Controls48m · 16 videos
  • Premium skill.The Incident Response Process48m · 16 videos
  • Premium skill.BC/DR Planning and Standards49m · 16 videos
Want to browse the locked skills?
with no purchase required. Already have an account?

An account gets you the full catalog to browse, pre-assessments, quiz questions on free skills, and IT Trainerbot, with every answer citing its source video.

Certification

CISM – Certified Information Security Manager

The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise ...

Exam CISMLevel ProfessionalDifficulty AdvancedCost $575 for members $760 for non-members
Information Security GovernanceRisk ManagementInformation Security Program Development and ManagementInformation Security Incident Management
Official certification page

Put this course to work for your team

Every plan includes this course plus the full library, virtual labs, and practice exams — or talk it through with sales.

For IT leaders

What IT leaders need to know before assigning this course

Security teams often have strong technical skills but inconsistent approaches to governance, risk, controls, incident response, and BC/DR planning. IT Directors can assign this CISM-aligned course to standardize how experienced security practitioners think about building and managing an information security program.

The course is best suited for security managers, Team Leads, risk-focused IT Practitioners, and senior staff preparing for the ISACA CISM certification. The ordered curriculum represents about 14 hours of instruction per learner, making it a realistic multi-week assignment alongside operational work. For change management, Training Managers can sequence modules around program governance first, then risk management, security operations, controls, incident response, and continuity planning.

CBT Nuggets Playlists can help structure the rollout by role, Practice Exams can support certification readiness, and Team Reporting gives IT leaders visibility into completion progress across the team.

Team Impact

How this training helps your team succeed

IT teams complete this training to connect security management practices with day-to-day operational decisions. The course topics map to real program work: creating an IS program, allocating resources, using metrics, managing assets and threats, implementing controls, responding to incidents, and planning for business continuity and disaster recovery.

  • Improve governance consistency by aligning security program creation, roles, resources, and metrics.
  • Reduce operational risk by giving teams a shared process for risk management frameworks, asset management, threat analysis, and security controls.
  • Strengthen incident readiness by reviewing the incident response process before a real outage or breach scenario occurs.
  • Support audit and resilience goals with structured coverage of information security operations, BC/DR planning, and standards.

After completion

Capabilities your team walks away with

Knowledge

  • How information security programs are created, resourced, and managed.
  • How organizational roles and security metrics support program oversight.
  • Core risk management concepts, frameworks, and processes.
  • How assets, threats, controls, and operations fit into security program management.
  • How incident response and BC/DR planning contribute to organizational resilience.

Ability

  • Evaluate whether an IS program has the roles, resources, and metrics needed for effective management.
  • Apply risk management thinking to assets, threats, controls, and security operations.
  • Support implementation and management of security controls within a broader program.
  • Participate more effectively in incident response planning and execution.
  • Contribute to continuity and disaster recovery planning discussions with a CISM-aligned management perspective.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own video transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes
Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one?
.

If gaps show up, start here

ISACA Cybersecurity Fundamentals (ITCA)

This ITCA - Cybersecurity Fundamentals training covers how to perform the basic, professional tasks required of an entry-level IT professional in a cybersecurity capacity. Although earning the ITCA Cybersecurity Fundamentals certification is valuable...

~24h

This course is included with every subscription

Unlock this one course, or get one learner — or your whole team — access to all 287 courses, virtual labs, and practice exams.

Course Unlock

Just need this course?

$225one time

No subscription

One year of access to CISM

  • Every skill in this course
  • Its virtual labs and practice exam
  • Ask IT Trainerbot about it — free

CBT Nuggets Individual

IT Trainerbot Pro

$49per month

Billed annually

Every course, for one learner

See Individual pricing
For IT teams

CBT Nuggets Teams

IT Trainerbot for Teams

$59per seat / mo

Billed annually

From 1 learner seat · unlimited admin seats

Checking your access

Need tenant hosting, reseller terms, or payment plans on a larger agreement? Book a Demo to discuss an Enterprise contract.

See plans and pricing for your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Who should take this CISM training?

This course is for experienced IT professionals who manage or oversee security programs, risk, or incident response. If you're already in a mid- to senior-level cybersecurity or governance role – or moving into one – this training updates your skills for emerging threats like AI-driven attacks and positions you for the CISM exam.

How much does the CISM cost?

The CISM exam costs $575 USD for ISACA members and $760 for non-members. An ISACA membership costs around $145 a year, so it might be worth becoming a member if you’re paying for the exam anyway. It’s a pricey process, but it's well worth it if you’re pursuing leadership roles in security, compliance, or risk governance.

Does earning the CISM pay well?

Yes – CISM consistently ranks among the highest-paying certs in IT. According to industry surveys, professionals with CISM earn well into six figures, especially in roles like security manager, IT risk lead, or GRC director. It’s a major salary booster for those managing security at the organizational level.

Is it hard to learn the technical and managerial skills of the CISM?

It’s challenging but doable with experience. The hardest part is the shift from technical tasks to management thinking – budgeting, governance frameworks, and risk ownership. If you’re used to hands-on tools, this course helps you think like a leader in control, compliance, and crisis readiness.

What jobs do I qualify for with the CISM?

With CISM, you're qualified for roles like Information Security Manager, Cybersecurity Program Lead, GRC Manager, or IT Risk Director. Employers recognize CISM as the benchmark for leadership in security policy, incident response planning, and program oversight.

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.