CISM Training Course

Training course

This is a free, self-paced reading course for CISM: Certified Information Security Manager, ISACA’s credential for the people who run security as a business function. The exam does not ask whether you can configure a control. It asks whether you can decide which controls are worth their cost, who owns the risk that remains after they are in place, and how to put that in front of a board. The material here is written in that register throughout, because the single most common way to fail CISM is to answer correct technical questions with correct technical answers that a senior manager would not have chosen.

The course is organized as one module per official exam domain, in the order ISACA publishes them, and each module carries the domain’s published weight. On CISM the weighting is lopsided in a way worth planning around: Information Security Program and Incident Management together account for 63% of the exam, and governance, which most candidates find the most abstract, carries only 17%. The modules are sized to that reality, so the time you spend reading tracks the time the exam spends testing.

CISM Professional level 4 modules Domain-weighted Self-paced Free account

What the course covers

Information Security Governance

Module 1 · 17%

How security is directed and held accountable at the enterprise level: aligning the security strategy with business objectives, establishing the governance framework, defining roles from the board and steering committee down to owners and custodians, working with organizational culture and legal obligations, and building the business cases and board-level metrics that keep a program funded and credible.

Information Security Risk Management

Module 2 · 20%

Identifying, analyzing, and treating information risk in business terms: the emerging threat landscape, vulnerability and control-deficiency analysis, qualitative and quantitative assessment, risk appetite and tolerance, the four treatment options, risk and control ownership, and the monitoring and reporting (risk registers, KRIs, escalation of residual risk) that keeps exposure visibly inside what the business has agreed to accept.

Information Security Program

Module 3 · 33%

The heaviest domain, covering how a security program is built and operated: asset identification and classification, standards and frameworks, the policy hierarchy, program metrics, control design, selection, implementation, and testing, security awareness and role-based training, management of external and cloud services, and communicating program performance to stakeholders, the day-to-day machinery a security manager is actually judged on.

Incident Management

Module 4 · 30%

Readiness and operations for the day something goes wrong: incident response planning, business impact analysis, continuity and disaster recovery integration, classification and escalation criteria, exercising and testing, and the operational sequence (triage, containment, eradication, recovery, and post-incident review) along with evidence handling, notification obligations, and communicating through a crisis.

How to use it

Read a module, then work the matching portion of the CISM practice exam before moving on. CISM questions routinely offer four defensible answers, and the only reliable way to build the management instinct they reward (business objective first, then the accountable owner, then the governance process, then cost against impact) is to be wrong a few dozen times and read why. Review the explanations on the questions you got right as well; on this exam a correct answer reached by technical reasoning is a near miss. This page is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.

For exam logistics, the 150 questions, the 240-minute window, the scaled 200 to 800 range with 450 to pass, registration pricing, PSI and remote-proctor delivery, the five-year experience requirement and its waivers, and the 30-day retake wait, see the CISM certification guide.

CISM Training Course

Complete training course preparing candidates for the ISACA CISM (Certified Information Security Manager) exam. Covers all four CISM domains at manager-level depth: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Fifty-one lessons totaling approximately eight hours of reading time, with 250+ key terms and 100+ curated further-reading references.

Module 1: Information Security Governance 17% of exam

  • 1.1 What CISM Is: The Security Manager Role 8 min Free preview
  • 1.2 Governance Fundamentals: Structures, Roles, Responsibilities 6 min πŸ”’
  • 1.3 Aligning Security with Business Strategy 5 min πŸ”’
  • 1.4 Security Governance Frameworks 6 min πŸ”’
  • 1.5 Legal, Regulatory, and Compliance Requirements 6 min πŸ”’
  • 1.6 Organizational Culture and Security 4 min πŸ”’
  • 1.7 Security Roles: RACI and Segregation of Duties 5 min πŸ”’
  • 1.8 Policies, Standards, Procedures, Guidelines 5 min πŸ”’
  • 1.9 Enterprise Risk Appetite and Tolerance 5 min πŸ”’

Module 2: Information Security Risk Management 20% of exam

  • 2.1 Risk Management Concepts and Terminology 5 min πŸ”’
  • 2.2 Risk Identification: Assets, Threats, Vulnerabilities 5 min πŸ”’
  • 2.3 Risk Assessment Methodologies 5 min πŸ”’
  • 2.4 Qualitative vs. Quantitative Risk Analysis (SLE/ARO/ALE) 5 min πŸ”’
  • 2.5 Threat Modeling and Attack Vectors 5 min πŸ”’
  • 2.6 Risk Treatment: Accept, Mitigate, Transfer, Avoid 5 min πŸ”’
  • 2.7 Third-Party and Supply Chain Risk 5 min πŸ”’
  • 2.8 Risk Monitoring and Reporting 5 min πŸ”’
  • 2.9 Emerging Risk: AI, Cloud, IoT, Quantum 5 min πŸ”’
  • 2.10 Risk Communication to Leadership 5 min πŸ”’

Module 3: Information Security Program 33% of exam

  • 3.1 Program Development and Objectives 5 min πŸ”’
  • 3.2 Program Resources: Budget, People, Technology 5 min πŸ”’
  • 3.3 Program Frameworks (ISO 27001, NIST CSF) 5 min πŸ”’
  • 3.4 Security Metrics and Reporting 5 min πŸ”’
  • 3.5 Security Awareness and Training Programs 5 min πŸ”’
  • 3.6 Third-Party Security Management 5 min πŸ”’
  • 3.7 Security Architecture and Design Principles 5 min πŸ”’
  • 3.8 Identity and Access Management 5 min πŸ”’
  • 3.9 Cryptography Fundamentals for Managers 5 min πŸ”’
  • 3.10 Network and Endpoint Security 5 min πŸ”’
  • 3.11 Data Protection and Privacy 5 min πŸ”’
  • 3.12 Cloud, Mobile, and IoT Security 5 min πŸ”’
  • 3.13 Application Security Program 5 min πŸ”’
  • 3.14 Change and Configuration Management 4 min πŸ”’
  • 3.15 Vulnerability and Patch Management 4 min πŸ”’
  • 3.16 Physical and Environmental Security 4 min πŸ”’
  • 3.17 Security Operations Center (SOC) Management 5 min πŸ”’

Module 4: Incident Management 30% of exam

  • 4.1 Incident Response Planning and Readiness 5 min πŸ”’
  • 4.2 Incident Classification and Categorization 4 min πŸ”’
  • 4.3 Detection and Analysis 4 min πŸ”’
  • 4.4 Containment Strategies 4 min πŸ”’
  • 4.5 Eradication and Recovery 4 min πŸ”’
  • 4.6 Incident Communication 4 min πŸ”’
  • 4.7 Post-Incident Review and Lessons Learned 4 min πŸ”’
  • 4.8 Digital Forensics for Managers 4 min πŸ”’
  • 4.9 Threat Intelligence Integration 4 min πŸ”’
  • 4.10 Business Impact Analysis 4 min πŸ”’
  • 4.11 Business Continuity Planning 4 min πŸ”’
  • 4.12 Disaster Recovery Planning 4 min πŸ”’
  • 4.13 IR and BC Testing 4 min πŸ”’
  • 4.14 Incident Metrics and Continuous Improvement 4 min πŸ”’
  • 4.15 External Coordination: Regulators, Law Enforcement, Media 4 min πŸ”’

Frequently asked questions about the CISM training course

Is the CISM training course free?

Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.

How is the course structured?

One module per official CISM domain, in ISACA’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace ISACA’s official review material?

No. ISACA publishes the exam content outline and sells the CISM Review Manual and its own question database; those are the authoritative sources. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.

Do I need the five years of experience before studying?

No, the experience requirement applies to certification rather than to study, and ISACA allows waivers for up to two of the five years. But CISM is written for someone who has had to defend a budget or own a residual risk decision. If you have not, read module 1 slowly; the governance vocabulary is what the other three modules argue in.

What should I do after finishing the course?

Move to the CISM practice exam and use the per-domain results to direct the rest of your study. The practice pass line is 65%, an honest raw-score equivalent of where the scaled 450 tends to land; clear it consistently across all four domains rather than on the strength of modules 3 and 4 alone.

Is the course current?

The course is built against the four-domain exam content outline in force since June 2022: Information Security Governance at 17%, Information Security Risk Management at 20%, Information Security Program at 33%, and Incident Management at 30%, as published on the CISM certification guide. ISACA has announced an updated CISM Exam Content Outline taking effect November 3, 2026, so exams sat on or after that date test the revised outline; check the current version at isaca.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CISM® and CISA® are registered trademarks of ISACA (Information Systems Audit and Control Association). Use of these marks is solely to identify the certification for which these study materials are intended. The CISM Exam Content Outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISACA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, and eligibility criteria are set by ISACA and may change (including the announced November 3, 2026 outline update) so always verify current details at isaca.org before scheduling your exam.