Certification

Certified Information Security Manager (CISM)

ISACA

Median earnings
Cost
$50
Duration
Completion

Certified Information Security Manager® (CISM®) affirms your ability to assess risks, implement effective governance, and proactively respond to incidents. With a highlight on emerging technologies such as AI and blockchain, it guarantees your skillset meets evolving security threats and industry requirements. By addressing top-of-mind concerns like data breaches and ransomware attacks, crucial for IT professionals, this certification ensures you are staying ahead of the pace of change.

hybridProgram details →

Skills taught

Identify internal and external influences to the organization that impact the information security strategyEstablish and/or maintain an information security strategy in alignment with organizational goals and objectivesEstablish and/or maintain an information security governance frameworkIntegrate information security governance into corporate governanceEstablish and maintain information security policies to guide the development of standards, procedures, and guidelinesDevelop business cases to support investments in information securityGain ongoing commitment from senior leadership and other stakeholders to support the successful implementation of the information security strategyDefine, communicate, and monitor information security responsibilities throughout the organization and lines of authorityCompile and present reports to key stakeholders on the activities, trends, and overall effectiveness of the information security programEvaluate and report information security metrics to key stakeholdersEstablish and/or maintain the information security program in alignment with the information security strategyAlign the information security program with the operational objectives of other business functionsEstablish and maintain information security processes and resources to execute the information security programEstablish, communicate, and maintain organizational information security policies, standards, guidelines, procedures, and other documentationEstablish, promote, and maintain a program for information security awareness and trainingIntegrate information security requirements into organizational processes to maintain the organization’s security strategyIntegrate information security requirements into contracts and activities of external partiesMonitor external parties' adherence to established security requirementsDefine and monitor management and operational metrics for the information security programEstablish and/or maintain a process for information asset identification and classificationIdentify legal, regulatory, organizational, and other applicable compliance requirementsParticipate in and/or oversee the risk identification, risk assessment, and risk treatment processParticipate in and/or oversee the vulnerability assessment and threat analysis processIdentify, recommend, or implement appropriate risk treatment and response options to manage risk to acceptable levels based on organizational risk appetiteDetermine whether information security controls are appropriate and effectively manage risk to an acceptable levelFacilitate the integration of information risk management into business and IT processesMonitor for internal and external factors that may require reassessment of riskReport on information security risk, including noncompliance and changes in information risk, to key stakeholders to facilitate the risk management decisionmaking processEstablish and maintain an incident response plan, in alignment with the business continuity plan and disaster recovery planEstablish and maintain an information security incident classification and categorization process
← Browse credential pathways