Skip to content
CBT Nuggets

ISACA CISM – Certified Information Security Manager

This CISM training prepares IT professionals to manage enterprise-level security governance, risk, and incident response. This online, self-paced course aligns with ISACA's latest Certified Information Security Manager exam and is ideal for roles like Information Security Manager, GRC Lead, or Risk Officer. You'll build leadership skills in threat modeling, risk treatment, and post-incident review, making it perfect for both CISM certification prep and recertification.

Updated June 2025

14Skills
99Videos
14h 3mTotal
99 videos14h 3m

Who This Course Is For

This course is for mid- to senior-level IT professionals in security, risk, and governance roles. If you lead security programs, manage audits or incident response, or are preparing for the CISM exam, this course updates your skills to meet today’s regulatory and threat environment head-on.

Skills Your Team Will Gain

  • Design and align security strategy with business objectives
  • Conduct vulnerability and control gap analysis
  • Develop and evaluate business continuity plans
  • Manage third-party and supply chain security risks
  • Monitor incidents with tools like SIEMs and response playbooks
  • Communicate risk posture and incident response to stakeholders

Course Curriculum

  • Premium skill.Creating An Information Security Program1h 1m
  • Premium skill.IS Program Resources1h 5m
  • Premium skill.Creating A Successful IS Program1h 7m
  • Premium skill.Organizational Roles and Using Metrics50m
  • Premium skill.Introduction To Risk Management1h 17m
  • Premium skill.Risk Management Frameworks and Processes57m
  • Premium skill.Managing Assets and Threats1h 11m
  • Premium skill.Information Security Risk Management1h 13m
  • Premium skill.Creating An Information Security Program58m
  • Premium skill.Information Security Operations60m
  • Premium skill.Managing An Information Security Program58m
  • Premium skill.Implementing and Managing Security Controls48m
  • Premium skill.The Incident Response Process48m
  • Premium skill.BC/DR Planning and Standards49m

Certification

CISM – Certified Information Security Manager

The Certified Information Security Manager (CISM) certification validates an individual's expertise in information security management, risk management, and incident response, and is ideal for IT professionals who want to demonstrate their expertise ...

Exam CISMLevel ProfessionalDifficulty Advanced
Information Security GovernanceRisk ManagementInformation Security Program Development and ManagementInformation Security Incident Management
Official certification page

For IT leaders

What IT leaders need to know before assigning this course

Security teams often have strong technical skills but inconsistent approaches to governance, risk, controls, incident response, and BC/DR planning. IT Directors can assign this CISM-aligned course to standardize how experienced security practitioners think about building and managing an information security program.

The course is best suited for security managers, Team Leads, risk-focused IT Practitioners, and senior staff preparing for the ISACA CISM certification. The ordered curriculum represents about 14 hours of instruction per learner, making it a realistic multi-week assignment alongside operational work. For change management, Training Managers can sequence modules around program governance first, then risk management, security operations, controls, incident response, and continuity planning.

CBT Nuggets Playlists can help structure the rollout by role, Practice Exams can support certification readiness, and Team Reporting gives IT leaders visibility into completion progress across the team.

Team Impact

How this training helps your team succeed

IT teams complete this training to connect security management practices with day-to-day operational decisions. The course topics map to real program work: creating an IS program, allocating resources, using metrics, managing assets and threats, implementing controls, responding to incidents, and planning for business continuity and disaster recovery.

  • Improve governance consistency by aligning security program creation, roles, resources, and metrics.
  • Reduce operational risk by giving teams a shared process for risk management frameworks, asset management, threat analysis, and security controls.
  • Strengthen incident readiness by reviewing the incident response process before a real outage or breach scenario occurs.
  • Support audit and resilience goals with structured coverage of information security operations, BC/DR planning, and standards.

After completion

Knowledge & ability your team will gain

Knowledge

  • How information security programs are created, resourced, and managed.
  • How organizational roles and security metrics support program oversight.
  • Core risk management concepts, frameworks, and processes.
  • How assets, threats, controls, and operations fit into security program management.
  • How incident response and BC/DR planning contribute to organizational resilience.

Ability

  • Evaluate whether an IS program has the roles, resources, and metrics needed for effective management.
  • Apply risk management thinking to assets, threats, controls, and security operations.
  • Support implementation and management of security controls within a broader program.
  • Participate more effectively in incident response planning and execution.
  • Contribute to continuity and disaster recovery planning discussions with a CISM-aligned management perspective.

Readiness check

Confirm prerequisite knowledge before training begins

A short placement assessment on the CBT Nuggets assessments platform measures whether a learner already has the foundation this course assumes. IT Directors use it to put the right people in the right training — and any learner can take it right now to make sure they'll get full value from day one.

  • Questions generated from this course's own lesson transcripts — what gets measured is exactly what gets taught
  • Instant, per-learner results that show whether the prerequisite foundation is in place
  • Results roll up into team readiness reporting, so training hours go where they change outcomes

Runs on assessments.cbtnuggets.com — sign in with an Adept account so results roll up into team readiness reporting. Need one? Create an Adept account.

If gaps show up, start here

ISACA Cybersecurity Fundamentals (ITCA)

This ITCA - Cybersecurity Fundamentals training covers how to perform the basic, professional tasks required of an entry-level IT professional in a cybersecurity capacity. Although earning the ITCA Cybersecurity Fundamentals certification is valuable...

~24h 10m

This course is included with every subscription

Get your team access to all 559 courses, virtual labs, and practice exams.

Most Popular

Team

$749per seat / year

5+ learner seats

Get Started

Enterprise

Customannual contracts

Any size

Contact Enterprise Sales

Just need this course?

Single-course enrollment — $399 for 1 year of access to CISM.

Enroll in This Course
Calculate the ROI of training your team

Trusted by 23,000+ organizations

Frequently Asked Questions

Ready to upskill your team?

Talk to our sales team to find the right plan for your organization.