Get in Touch

award icon svg Certificate

Course Outline

Domain 1—Information Security Governance (24%)

The focus here is on establishing and sustaining a robust information security governance framework and supporting processes. This ensures that the security strategy aligns with organizational goals, information risks are managed appropriately, and program resources are utilized responsibly.

  • 1.1 Formulate and sustain an information security strategy aligned with organizational objectives to guide the creation and ongoing management of the security program.
  • 1.2 Develop and maintain a governance framework that directs activities supporting the broader security strategy.
  • 1.3 Embed information security governance within corporate governance to ensure that organizational goals are supported by the security program.
  • 1.4 Create and uphold information security policies that communicate management directives and guide the formulation of standards, procedures, and guidelines.
  • 1.5 Formulate business cases to justify and support investments in information security.
  • 1.6 Identify internal and external influences on the organization, such as technology, business environment, risk tolerance, location, and legal requirements, ensuring these factors are addressed in the security strategy.
  • 1.7 Secure commitment from senior management and support from other stakeholders to maximize the likelihood of successfully implementing the security strategy.
  • 1.8 Define and clearly communicate the roles and responsibilities of information security across the organization to establish clear accountability and authority lines.
  • 1.9 Establish, monitor, evaluate, and report on metrics, including key goal indicators [KGIs], key performance indicators [KPIs], and key risk indicators [KRIs], to provide management with accurate insights into the effectiveness of the security strategy.

Domain 2—Information Risk Management and Compliance (33%)

This domain centers on managing information risk to acceptable levels in order to satisfy both business needs and compliance requirements.

  • 2.1 Implement and maintain a process for identifying and classifying information assets to ensure that protective measures are proportionate to their business value.
  • 2.2 Identify applicable legal, regulatory, organizational, and other requirements to manage noncompliance risk to acceptable levels.
  • 2.3 Ensure that risk assessments, vulnerability assessments, and threat analyses are performed regularly and consistently to identify risks to the organization’s information.
  • 2.4 Determine and implement suitable risk treatment options to keep risk at acceptable levels.
  • 2.5 Evaluate information security controls to verify that they are appropriate and effectively mitigate risk to acceptable levels.
  • 2.6 Integrate information risk management into business and IT processes, such as development, procurement, project management, and M&A, to foster a consistent and comprehensive risk management approach across the organization.
  • 2.7 Monitor existing risks to ensure that changes are identified and managed appropriately.
  • 2.8 Report noncompliance issues and other changes in information risk to the relevant management to support the risk management decision-making process.

Domain 3—Information Security Program Development and Management (25%)

The objective is to establish and manage the information security program in close alignment with the information security strategy.

  • 3.1 Build and sustain the information security program in line with the overall security strategy.
  • 3.2 Ensure alignment between the security program and other business functions, such as human resources [HR], accounting, procurement, and IT, to facilitate integration with business processes.
  • 3.3 Identify, acquire, manage, and define requirements for internal and external resources necessary to execute the security program.
  • 3.4 Establish and maintain information security architectures encompassing people, processes, and technology to drive program execution.
  • 3.5 Create, communicate, and maintain organizational standards, procedures, guidelines, and other documentation to support compliance with security policies.
  • 3.6 Develop and sustain a program for information security awareness and training to foster a secure environment and a strong security culture.
  • 3.7 Integrate security requirements into organizational processes, including change control, M&A, development, business continuity, and disaster recovery, to maintain the organization’s security baseline.
  • 3.8 Embed security requirements into contracts and activities involving third parties, such as joint ventures, outsourced providers, business partners, and customers, to uphold the organization’s security baseline.
  • 3.9 Establish, monitor, and periodically report on program management and operational metrics to assess the effectiveness and efficiency of the security program.

Domain 4—Information Security Incident Management (18%)

This domain involves planning, establishing, and managing the capability to detect, investigate, respond to, and recover from security incidents to minimize business impact.

  • 4.1 Establish and maintain a process for classifying and categorizing security incidents to enable accurate identification and appropriate response.
  • 4.2 Develop, maintain, and align the incident response plan with the business continuity and disaster recovery plans to ensure effective and timely responses.
  • 4.3 Create and implement processes to guarantee the timely identification of security incidents.
  • 4.4 Establish and maintain processes to investigate and document incidents, enabling appropriate response and root cause determination while adhering to legal, regulatory, and organizational requirements.
  • 4.5 Set up and maintain incident handling processes to ensure that the right stakeholders are involved in response management.
  • 4.6 Organize, train, and equip teams to respond effectively and promptly to security incidents.
  • 4.7 Periodically test and review incident management plans to ensure effective response and to enhance response capabilities.
  • 4.8 Establish and maintain communication plans and processes for managing interactions with internal and external entities.
  • 4.9 Conduct post-incident reviews to determine root causes, develop corrective actions, reassess risk, evaluate response effectiveness, and take necessary remedial actions.
  • 4.10 Establish and maintain integration among the incident response, disaster recovery, and business continuity plans.

Requirements

Specific prerequisites are not mandatory for enrollment in this course. However, please note that ISACA requires a minimum of five years of professional experience in information security to award full certification. While you may sit for the CISM exam before fulfilling these experience criteria, the official qualification is granted only once the requirements are met. Nevertheless, there is no barrier to obtaining certification early in your career, allowing you to begin applying globally recognized information security management practices.

 28 Hours

Number of participants


Price per participant

Testimonials (7)

Upcoming Courses

Related Categories