Get in Touch

award icon svg Certificate

Course Outline

Domain 1—Information Security Governance (24%)

Develop and sustain an information security governance framework along with supporting processes to ensure that the security strategy aligns with organizational objectives, that information risk is appropriately controlled, and that program resources are managed responsibly.

  • 1.1 Formulate and maintain an information security strategy aligned with organizational goals to guide the creation and ongoing management of the security program.
  • 1.2 Implement and maintain an information security governance framework to support activities that further the security strategy.
  • 1.3 Embed information security governance within corporate governance to ensure that organizational objectives are supported by the security program.
  • 1.4 Create and maintain information security policies to convey management directives and direct the development of standards, procedures, and guidelines.
  • 1.5 Prepare business cases to justify investments in information security.
  • 1.6 Identify internal and external influences on the organization, such as technology, the business environment, risk tolerance, geographic location, and legal or regulatory requirements, to ensure these factors are addressed in the security strategy.
  • 1.7 Secure commitment from senior management and support from other stakeholders to enhance the likelihood of successful strategy implementation.
  • 1.8 Define and communicate the roles and responsibilities related to information security across the organization to establish clear accountability and lines of authority.
  • 1.9 Establish, monitor, evaluate, and report on metrics, such as key goal indicators [KGIs], key performance indicators [KPIs], and key risk indicators [KRIs], to provide management with accurate data on the effectiveness of the security strategy.

Domain 2—Information Risk Management and Compliance (33%)

Control information risk to an acceptable level to satisfy the organization's business and compliance needs.

  • 2.1 Develop and maintain a process for identifying and classifying information assets to ensure that protection measures are proportionate to their business value.
  • 2.2 Identify legal, regulatory, organizational, and other applicable requirements to manage the risk of noncompliance to acceptable levels.
  • 2.3 Ensure that risk assessments, vulnerability assessments, and threat analyses are performed regularly and consistently to identify risks to the organization's information.
  • 2.4 Determine and implement suitable risk treatment options to maintain risk at acceptable levels.
  • 2.5 Evaluate information security controls to verify their appropriateness and effectiveness in mitigating risk to an acceptable level.
  • 2.6 Integrate information risk management into business and IT processes, such as development, procurement, project management, and mergers and acquisitions, to foster a consistent and comprehensive risk management approach across the organization.
  • 2.7 Monitor existing risks to ensure that changes are identified and managed appropriately.
  • 2.8 Report noncompliance and other changes in information risk to the relevant management levels to support the risk management decision-making process.

Domain 3—Information Security Program Development and Management (25%)

Establish and manage the information security program in alignment with the overall information security strategy.

  • 3.1 Build and maintain the information security program in accordance with the information security strategy.
  • 3.2 Ensure alignment between the information security program and other business functions, such as human resources [HR], accounting, procurement, and IT, to support integration with business processes.
  • 3.3 Identify, acquire, manage, and define requirements for internal and external resources needed to execute the information security program.
  • 3.4 Create and maintain information security architectures covering people, processes, and technology to support the execution of the security program.
  • 3.5 Establish, communicate, and maintain organizational information security standards, procedures, guidelines, and other documentation to support and guide compliance with security policies.
  • 3.6 Develop and maintain a program for information security awareness and training to foster a secure environment and an effective security culture.
  • 3.7 Integrate information security requirements into organizational processes, such as change control, mergers and acquisitions, development, business continuity, and disaster recovery, to preserve the organization's security baseline.
  • 3.8 Incorporate information security requirements into contracts and the activities of third parties, such as joint ventures, outsourced providers, business partners, and customers, to maintain the organization's security baseline.
  • 3.9 Establish, monitor, and periodically report on program management and operational metrics to assess the effectiveness and efficiency of the information security program.

Domain 4—Information Security Incident Management (18%)

Plan, establish, and manage the capability to detect, investigate, respond to, and recover from information security incidents to minimize business impact.

  • 4.1 Create and maintain an information security incident classification and categorization process to enable accurate identification and response to incidents.
  • 4.2 Develop, maintain, and align the incident response plan with the business continuity and disaster recovery plans to ensure effective and timely responses to security incidents.
  • 4.3 Develop and implement processes to ensure the timely identification of information security incidents.
  • 4.4 Establish and maintain processes to investigate and document information security incidents, allowing for appropriate response and cause determination while adhering to legal, regulatory, and organizational requirements.
  • 4.5 Create and maintain incident handling processes to ensure that the appropriate stakeholders are involved in incident response management.
  • 4.6 Organize, train, and equip teams to respond effectively and promptly to information security incidents.
  • 4.7 Periodically test and review incident management plans to ensure effective responses to security incidents and to enhance response capabilities.
  • 4.8 Establish and maintain communication plans and processes to manage interactions with internal and external entities.
  • 4.9 Conduct post-incident reviews to determine the root cause of security incidents, develop corrective actions, reassess risk, evaluate response effectiveness, and take appropriate remedial measures.
  • 4.10 Establish and maintain integration among the incident response plan, disaster recovery plan, and business continuity plan.

Requirements

This course does not have specific pre-requisites. However, ISACA requires a minimum of five years of professional experience in information security to achieve full certification status. While you may sit for the CISM exam before meeting this experience threshold, the official CISM qualification is granted only once the experience requirements are fulfilled. There are no barriers to beginning your certification journey early in your career, allowing you to start implementing globally recognized information security management practices immediately.

 28 Hours

Number of participants


Price per participant

Testimonials (7)

Upcoming Courses

Related Categories