Certification track

CISM Certification Training

The management-track credential for people who run security, not just do it. Our CISM cohorts prepare security managers and aspiring CISOs across all four ISACA domains — governance, risk, programme, and incident management — with teaching grounded in how enterprises actually operate.

Enquire about training

Corporate cohorts — arranged on demand for your team

Awarding body
ISACA
Exam
CISM
Duration
4-day intensive bootcamp
Delivery
Onsite or live virtual, cohort-based
Prerequisites
5 years' information security experience, incl. 3 years in security management (waivers available)

Overview

CISM is the credential for people accountable for security, not just engaged in it. ISACA’s four domains — governance, risk management, programme development, and incident management — map directly onto the job of running a security function inside a real enterprise.

That is exactly how we teach it. Our CISM cohorts are led by practitioners who have owned security programmes, so every domain is grounded in the situations managers actually face: winning board support, defending a risk position, resourcing a programme, and leading through an incident.

The exam itself rewards judgement — most questions present several defensible answers and ask for the best one. Our practice phase trains that specific skill with timed, scenario-driven mocks and per-domain diagnostics, and we support each candidate through ISACA’s application and experience-verification process after the pass. Cohorts are arranged on demand, onsite or live virtual, around your team’s calendar.

Who it's for

  • Security managers and team leads formalising their move into leadership
  • Aspiring CISOs and heads of security building the management credential to match
  • Risk, audit, and GRC professionals whose remit now includes security programmes
  • Organisations standardising a management-level security qualification across leaders

What's covered

  • Domain 1 — Information Security Governance: strategy, frameworks, and board alignment
  • Domain 2 — Information Security Risk Management: assessing, treating, and reporting risk
  • Domain 3 — Information Security Programme: building and running the security function
  • Domain 4 — Incident Management: preparing for, responding to, and learning from incidents
  • Translating technical risk into business language executives act on
  • Exam technique for ISACA's scenario-driven, best-answer question style
CISM

Your journey, end to end

  1. Map & enrol

    We confirm each candidate's experience against ISACA's requirements, identify waiver eligibility, and baseline their strengths across the four domains before teaching begins.

  2. Train

    A four-day, practitioner-led intensive across governance, risk, programme, and incident management — taught by people who have run security functions, with enterprise scenarios throughout.

  3. Practise

    ISACA-style scenario questions demand judgement, not recall. Timed mocks train candidates to pick the best answer among plausible ones, with diagnostics per domain.

  4. Certify

    We guide candidates through exam booking, ISACA's application and experience-verification process, and test-day strategy.

  5. Beyond

    Post-course revision resources, retake support, and CPE guidance for maintaining the credential — plus a pathway conversation for what comes after CISM.

Format & delivery

  • 4-day instructor-led bootcamp, onsite or live virtual
  • Cohorts arranged on demand around your team's calendar
  • ISACA-aligned courseware and official-style question practice
  • Timed mock exams with per-domain diagnostics and revision plans
  • Application and experience-verification guidance after the pass

Outcomes

  • Candidates prepared for CISM's scenario-driven exam style, not just its syllabus
  • Managers who can frame security decisions in governance and business-risk terms
  • A leadership team carrying the credential boards and regulators recognise
  • A common management vocabulary across your security leadership

Industry relevance

FinanceTechnologyGovernment

Frequently asked questions

CISM or CISSP — which should our leaders take?

CISSP proves broad technical-to-governance capability; CISM is squarely a management credential focused on running the security function. People managing teams, budgets, and programmes usually get more from CISM; hands-on architects and senior engineers from CISSP. Many leaders ultimately hold both — we help you sequence them.

What experience does ISACA require?

Five years in information security, including three in security management across at least three of the four domains. Up to two years can be waived for certain credentials and degrees. Candidates can pass the exam first and certify once the experience is verified — we advise on each person's route.

How is the exam structured?

150 multiple-choice questions over four hours, heavily scenario-based — most questions ask for the best answer among several defensible ones. Our practice phase is built specifically around that judgement style.

When does the cohort run?

On demand. We build the cohort around your team's window rather than a fixed public schedule — including split delivery across two blocks where a four-day release is difficult.

Can we mix CISM and CISSP candidates in one engagement?

Yes. We regularly run blended engagements where managers pursue CISM while senior practitioners prepare for CISSP, with shared foundations and split domain tracks.

Download the datasheet

Get the full programme outline, delivery options, and example agenda as a PDF.

Ready to train your team?

Tell us about your team and we'll recommend the right courses and curriculum.

Talk to us

Related programmes