Training course
This is a free, self-paced reading course for CISM: Certified Information Security Manager, ISACA’s credential for the people who run security as a business function. The exam does not ask whether you can configure a control. It asks whether you can decide which controls are worth their cost, who owns the risk that remains after they are in place, and how to put that in front of a board. The material here is written in that register throughout, because the single most common way to fail CISM is to answer correct technical questions with correct technical answers that a senior manager would not have chosen.
The course is organized as one module per official exam domain, in the order ISACA publishes them, and each module carries the domain’s published weight. On CISM the weighting is lopsided in a way worth planning around: Information Security Program and Incident Management together account for 63% of the exam, and governance, which most candidates find the most abstract, carries only 17%. The modules are sized to that reality, so the time you spend reading tracks the time the exam spends testing.
What the course covers
Information Security Governance
Module 1 · 17%How security is directed and held accountable at the enterprise level: aligning the security strategy with business objectives, establishing the governance framework, defining roles from the board and steering committee down to owners and custodians, working with organizational culture and legal obligations, and building the business cases and board-level metrics that keep a program funded and credible.
Information Security Risk Management
Module 2 · 20%Identifying, analyzing, and treating information risk in business terms: the emerging threat landscape, vulnerability and control-deficiency analysis, qualitative and quantitative assessment, risk appetite and tolerance, the four treatment options, risk and control ownership, and the monitoring and reporting (risk registers, KRIs, escalation of residual risk) that keeps exposure visibly inside what the business has agreed to accept.
Information Security Program
Module 3 · 33%The heaviest domain, covering how a security program is built and operated: asset identification and classification, standards and frameworks, the policy hierarchy, program metrics, control design, selection, implementation, and testing, security awareness and role-based training, management of external and cloud services, and communicating program performance to stakeholders, the day-to-day machinery a security manager is actually judged on.
Incident Management
Module 4 · 30%Readiness and operations for the day something goes wrong: incident response planning, business impact analysis, continuity and disaster recovery integration, classification and escalation criteria, exercising and testing, and the operational sequence (triage, containment, eradication, recovery, and post-incident review) along with evidence handling, notification obligations, and communicating through a crisis.
How to use it
Read a module, then work the matching portion of the CISM practice exam before moving on. CISM questions routinely offer four defensible answers, and the only reliable way to build the management instinct they reward (business objective first, then the accountable owner, then the governance process, then cost against impact) is to be wrong a few dozen times and read why. Review the explanations on the questions you got right as well; on this exam a correct answer reached by technical reasoning is a near miss. This page is open to everyone; the course lessons themselves open once you are signed in to a free Certifym account.
For exam logistics, the 150 questions, the 240-minute window, the scaled 200 to 800 range with 450 to pass, registration pricing, PSI and remote-proctor delivery, the five-year experience requirement and its waivers, and the 30-day retake wait, see the CISM certification guide.
CISM Training Course
Complete training course preparing candidates for the ISACA CISM (Certified Information Security Manager) exam. Covers all four CISM domains at manager-level depth: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Fifty-one lessons totaling approximately eight hours of reading time, with 250+ key terms and 100+ curated further-reading references.
Module 1: Information Security Governance 17% of exam
- 1.1 What CISM Is: The Security Manager Role 8 min Free preview
- 1.2 Governance Fundamentals: Structures, Roles, Responsibilities 6 min π
- 1.3 Aligning Security with Business Strategy 5 min π
- 1.4 Security Governance Frameworks 6 min π
- 1.5 Legal, Regulatory, and Compliance Requirements 6 min π
- 1.6 Organizational Culture and Security 4 min π
- 1.7 Security Roles: RACI and Segregation of Duties 5 min π
- 1.8 Policies, Standards, Procedures, Guidelines 5 min π
- 1.9 Enterprise Risk Appetite and Tolerance 5 min π
Module 2: Information Security Risk Management 20% of exam
- 2.1 Risk Management Concepts and Terminology 5 min π
- 2.2 Risk Identification: Assets, Threats, Vulnerabilities 5 min π
- 2.3 Risk Assessment Methodologies 5 min π
- 2.4 Qualitative vs. Quantitative Risk Analysis (SLE/ARO/ALE) 5 min π
- 2.5 Threat Modeling and Attack Vectors 5 min π
- 2.6 Risk Treatment: Accept, Mitigate, Transfer, Avoid 5 min π
- 2.7 Third-Party and Supply Chain Risk 5 min π
- 2.8 Risk Monitoring and Reporting 5 min π
- 2.9 Emerging Risk: AI, Cloud, IoT, Quantum 5 min π
- 2.10 Risk Communication to Leadership 5 min π
Module 3: Information Security Program 33% of exam
- 3.1 Program Development and Objectives 5 min π
- 3.2 Program Resources: Budget, People, Technology 5 min π
- 3.3 Program Frameworks (ISO 27001, NIST CSF) 5 min π
- 3.4 Security Metrics and Reporting 5 min π
- 3.5 Security Awareness and Training Programs 5 min π
- 3.6 Third-Party Security Management 5 min π
- 3.7 Security Architecture and Design Principles 5 min π
- 3.8 Identity and Access Management 5 min π
- 3.9 Cryptography Fundamentals for Managers 5 min π
- 3.10 Network and Endpoint Security 5 min π
- 3.11 Data Protection and Privacy 5 min π
- 3.12 Cloud, Mobile, and IoT Security 5 min π
- 3.13 Application Security Program 5 min π
- 3.14 Change and Configuration Management 4 min π
- 3.15 Vulnerability and Patch Management 4 min π
- 3.16 Physical and Environmental Security 4 min π
- 3.17 Security Operations Center (SOC) Management 5 min π
Module 4: Incident Management 30% of exam
- 4.1 Incident Response Planning and Readiness 5 min π
- 4.2 Incident Classification and Categorization 4 min π
- 4.3 Detection and Analysis 4 min π
- 4.4 Containment Strategies 4 min π
- 4.5 Eradication and Recovery 4 min π
- 4.6 Incident Communication 4 min π
- 4.7 Post-Incident Review and Lessons Learned 4 min π
- 4.8 Digital Forensics for Managers 4 min π
- 4.9 Threat Intelligence Integration 4 min π
- 4.10 Business Impact Analysis 4 min π
- 4.11 Business Continuity Planning 4 min π
- 4.12 Disaster Recovery Planning 4 min π
- 4.13 IR and BC Testing 4 min π
- 4.14 Incident Metrics and Continuous Improvement 4 min π
- 4.15 External Coordination: Regulators, Law Enforcement, Media 4 min π
Frequently asked questions about the CISM training course
Is the CISM training course free?
Yes. The course costs nothing to read. Opening the lessons requires a free Certifym account, and nothing beyond that, no payment, no trial. It is funded by the practice-exam catalogue it sits alongside.
How is the course structured?
One module per official CISM domain, in ISACA’s published order, with each module weighted to the domain’s published percentage. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace ISACA’s official review material?
No. ISACA publishes the exam content outline and sells the CISM Review Manual and its own question database; those are the authoritative sources. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.
Do I need the five years of experience before studying?
No, the experience requirement applies to certification rather than to study, and ISACA allows waivers for up to two of the five years. But CISM is written for someone who has had to defend a budget or own a residual risk decision. If you have not, read module 1 slowly; the governance vocabulary is what the other three modules argue in.
What should I do after finishing the course?
Move to the CISM practice exam and use the per-domain results to direct the rest of your study. The practice pass line is 65%, an honest raw-score equivalent of where the scaled 450 tends to land; clear it consistently across all four domains rather than on the strength of modules 3 and 4 alone.
Is the course current?
The course is built against the four-domain exam content outline in force since June 2022: Information Security Governance at 17%, Information Security Risk Management at 20%, Information Security Program at 33%, and Incident Management at 30%, as published on the CISM certification guide. ISACA has announced an updated CISM Exam Content Outline taking effect November 3, 2026, so exams sat on or after that date test the revised outline; check the current version at isaca.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CISM® and CISA® are registered trademarks of ISACA (Information Systems Audit and Control Association). Use of these marks is solely to identify the certification for which these study materials are intended. The CISM Exam Content Outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISACA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, and eligibility criteria are set by ISACA and may change (including the announced November 3, 2026 outline update) so always verify current details at isaca.org before scheduling your exam.
