Choose your language
CISM Certification Training
From 4 to 360h of flexible workload

CISM Certification Training

The CISM Certification Training prepares experienced security professionals to lead enterprise information security programmes with authority. You will master governance, risk management, compliance, and incident response — the four domains that define the CISM exam and the modern security manager role. This training builds the strategic and operational skills employers expect from certified security leaders.

What you will learn:

This course covers every domain tested on the CISM exam, starting with information security governance and risk management principles, then moving through regulatory compliance, security programme development, and incident response. You will learn how to align security strategy with business objectives, build and manage a compliance programme, and lead an organisation through a security incident from detection to post-incident review. The curriculum also addresses business continuity planning, emerging technology risks, and executive communication skills. Practical scenario-based workshops reinforce your ability to apply integrated thinking to complex, real-world security challenges.

How you study in practice CISM Certification Training

How you practise CISM Certification Training

For companies looking to train their teams

With Elevify for businesses, the course includes exercises and examples tailored to your company and its specific needs.

Click here

Course content

8 Chapters40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Information Security Governance Foundations

  • Lesson 1 • Security Strategy Alignment

    Links security objectives to business goals using strategic planning tools. Demonstrates how misalignment creates risk and reduces programme effectiveness.

  • Lesson 2 • Policies, Standards, and Procedures

    Covers the policy hierarchy from high-level directives to operational procedures. Provides the document architecture needed to enforce governance decisions.

  • Lesson 3 • Governance Concepts and Frameworks

    Defines governance versus management and maps key frameworks to organisational needs. Anchors the chapter by establishing vocabulary used throughout the course.

  • Lesson 4 • Governance Metrics and Reporting

    Introduces key performance and risk indicators used to measure governance effectiveness. Prepares candidates to present security posture to executive audiences.

  • Lesson 5 • Organisational Structures for Security

    Examines reporting lines, committee structures, and CISO positioning. Connects governance theory to practical organisational design.

Chapter 2See details

Information Risk Management Principles

  • Lesson 1 • Risk Identification Techniques

    Covers asset inventories, threat modelling, and vulnerability discovery methods. Feeds directly into the analysis and evaluation sections that follow.

  • Lesson 2 • Continuous Risk Monitoring

    Establishes processes for ongoing risk tracking and reassessment. Ensures the risk register remains current as the threat landscape evolves.

  • Lesson 3 • Risk Treatment and Response

    Examines the four treatment options and criteria for selecting controls. Connects risk analysis outputs to actionable security investment decisions.

  • Lesson 4 • Risk Analysis and Evaluation

    Applies qualitative and quantitative techniques to prioritise identified risks. Enables informed decision-making by translating risk data into business impact.

  • Lesson 5 • Risk Management Concepts

    Defines risk terminology and establishes the risk management lifecycle. Provides the conceptual foundation for all subsequent risk analysis activities.

Chapter 3See details

Regulatory Compliance and Legal Obligations

  • Lesson 1 • Building a Compliance Programme

    Guides construction of a structured compliance programme with clear ownership. Translates regulatory requirements into operational controls and audit evidence.

  • Lesson 2 • Audit and Assessment Management

    Covers internal and external audit processes, evidence preparation, and findings remediation. Prepares the security manager to lead audit engagements confidently.

  • Lesson 3 • Contractual and Third-Party Obligations

    Addresses security clauses in contracts and vendor compliance requirements. Extends the compliance programme beyond organisational boundaries.

  • Lesson 4 • Legal Liability and Incident Reporting

    Examines legal exposure from security incidents and mandatory reporting timelines. Connects compliance obligations to the incident management chapters ahead.

  • Lesson 5 • Compliance Framework Overview

    Surveys major regulatory categories and their security implications. Establishes why compliance is a governance driver, not a substitute for risk management.

Chapter 4See details

Security Programme Development and Management

  • Lesson 1 • Technology and Control Management

    Addresses control selection, implementation oversight, and technology lifecycle management. Bridges governance decisions to technical security operations.

  • Lesson 2 • Security Awareness and Training Programmes

    Designs role-based awareness programmes that reduce human-factor risk. Demonstrates how training metrics feed back into programme effectiveness measurement.

  • Lesson 3 • Security Programme Architecture

    Defines the components of a comprehensive security programme and their interdependencies. Provides the structural blueprint used throughout programme development.

  • Lesson 4 • Resource and Budget Management

    Covers security budget justification, allocation, and tracking techniques. Equips managers to defend spending decisions using risk and business value arguments.

  • Lesson 5 • Programme Maturity and Improvement

    Applies maturity models to assess current state and plan capability improvements. Closes the chapter by linking programme performance back to governance reporting.

Chapter 5See details

Information Security Risk Assessment in Practice

  • Lesson 1 • Scenario-Based Risk Workshops

    Uses structured scenarios to practise end-to-end risk assessment execution. Reinforces analytical skills through applied problem-solving before the exam.

  • Lesson 2 • Supply Chain and Third-Party Risk

    Examines risk introduced through vendors, partners, and software supply chains. Builds on earlier compliance content by adding risk-based vendor evaluation.

  • Lesson 3 • Emerging Technology Risk

    Assesses risk from AI, IoT, and operational technology environments. Prepares managers to evaluate novel threats before formal standards exist.

  • Lesson 4 • Cloud and Virtualisation Risk

    Identifies unique risk factors in cloud service models and shared responsibility boundaries. Extends foundational risk skills to modern infrastructure environments.

  • Lesson 5 • Risk Communication to Stakeholders

    Translates technical risk findings into executive-ready narratives and recommendations. Connects risk assessment outputs to governance reporting established earlier.

Chapter 6See details

Incident Management and Response

  • Lesson 1 • Crisis Communication and Notification

    Manages internal escalation, external notifications, and media relations during incidents. Connects legal notification obligations to operational communication plans.

  • Lesson 2 • Incident Management Lifecycle

    Defines the phases of incident management and the roles involved at each stage. Provides the operational framework applied in all subsequent sections.

  • Lesson 3 • Incident Response Planning

    Covers the design and maintenance of incident response plans and playbooks. Ensures the organisation can respond consistently before an incident occurs.

  • Lesson 4 • Digital Forensics Fundamentals

    Introduces evidence collection, chain of custody, and forensic analysis basics. Supports legal and regulatory obligations covered in the compliance chapter.

  • Lesson 5 • Post-Incident Analysis and Improvement

    Extracts lessons learned and drives control improvements from incident data. Feeds findings back into the risk register and programme maturity processes.

Chapter 7See details

Business Continuity and Disaster Recovery

  • Lesson 1 • Business Continuity Planning

    Translates BIA findings into actionable continuity strategies and documented plans. Ensures critical functions can continue during and after disruptive events.

  • Lesson 2 • Testing and Exercising Plans

    Covers the spectrum of continuity tests from walkthroughs to full interruption exercises. Validates plan effectiveness and identifies gaps before a real event.

  • Lesson 3 • Business Impact Analysis

    Identifies critical processes, dependencies, and recovery time objectives through structured analysis. Provides the data foundation for all continuity planning decisions.

  • Lesson 4 • Disaster Recovery Planning

    Focuses on IT system recovery procedures, backup strategies, and failover architectures. Complements BCP by addressing the technical recovery layer.

  • Lesson 5 • Integrating BC and DR with Security

    Aligns continuity and recovery programmes with the broader security governance structure. Ensures resilience objectives are reflected in risk assessments and policies.

Chapter 8See details

CISM Exam Strategy and Application

  • Lesson 1 • CISM Exam Structure and Domains

    Reviews the four CISM domains, question format, and scoring methodology. Orients candidates to the exam blueprint before focused review begins.

  • Lesson 2 • Weak Area Identification and Remediation

    Uses diagnostic practice results to target remaining knowledge gaps. Ensures efficient use of final study time before the exam date.

  • Lesson 3 • Scenario-Based Question Practice

    Applies a structured approach to dissecting and answering scenario-based questions. Develops the managerial perspective required to select best-answer options.

  • Lesson 4 • Exam Day Readiness

    Prepares candidates for logistics, time management, and mental performance on exam day. Closes the course with confidence-building strategies and final review.

  • Lesson 5 • Integrated Domain Review

    Synthesises concepts across all four domains through cross-domain scenario analysis. Builds the integrative thinking required for complex exam questions.

Certification
Certification

Your valid completion certificate

This course is for you:

  • Senior security analyst: ready to move into a management or leadership position.

  • IT risk manager: seeking formal credentials to validate existing governance expertise.

  • Compliance officer: expanding scope to include a full security programme management role.

  • Security consultant: pursuing CISM to strengthen client credibility and engagement value.

  • Infrastructure manager: transitioning into a dedicated information security leadership track.

  • Military or government security professional: translating clearance experience into civilian certification.

What our students say

Feedback from those who have already studied with us:

Your lessons are perfect. I purchased the one-year package and finally have the opportunity to follow various topics of interest without needing to change platforms... I'm grateful for everything you do, I've already recommended you to other people...
Giulio Carlo
Giulio CarloDigital Marketing Student
I like how the lessons are straight to the point and how I can change chapters and skip content I don't need.
Mariana Ferres
Mariana FerresPhotography Student
I like the content and the way videos are presented and transcribed, which speeds up the process!
Luciana Alvarenga
Luciana AlvarengaNail Design Student
The platform is fast, simple to use. The diversity of content and complementary videos really help with learning.
André Felipe
André FelipePrompt Engineering Student

Top qualifications

FAQ

Who is Elevify? How does it work?

Do the courses have certificates?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course