Certified Information Security Manager training by experienced security management practitioners. All 4 domains at exam depth. Directly applicable to vCISO and CMMC program management roles.
The Certified Information Security Manager (CISM) is ISACA's certification for information security professionals who manage, design, and oversee enterprise security programs. Unlike technical security certifications, CISM focuses on governance, risk management, program leadership, and incident management at the enterprise level.
CISM is frequently held by CISOs, vCISOs, security directors, and security program managers. It is also increasingly relevant to CMMC compliance program leads who must own the security governance and incident management functions that CMMC requires.
ISACA requires candidates to have five years of work experience in IS/IT security, with at least three years in information security management roles. Experience substitutions are available. All requirements are verified and maintained by ISACA.
Exam details subject to change. Verify current requirements at isaca.org.
Four domains covering the full scope of enterprise information security management.
Establishing and maintaining an information security governance framework aligned to organizational strategy. Security policies, standards, roles and responsibilities, and the metrics used to manage security performance. This domain aligns directly to the governance requirements in CMMC and NIST 800-171.
Identifying, assessing, and managing information security risk to acceptable levels. Risk assessment methodologies, risk treatment options, and ongoing risk monitoring. Connects directly to NIST 800-30 risk assessment requirements embedded in CMMC.
The largest CISM domain. Developing and managing an information security program including security architecture, control implementation, security awareness training, and technology management. This domain carries the most exam weight and most directly reflects the day-to-day work of a CISM-holding security manager.
Establishing and managing an incident response capability. Incident classification, escalation, investigation, containment, eradication, and recovery. Also covers business continuity and disaster recovery. Critical for any organization preparing for CMMC incident response requirements under DFARS 252.204-7012.
IS audit certification that pairs with CISM for a complete GRC credential set.
Risk and controls depth that strengthens the risk management dimension of CISM work.
The technical implementation work that CISM-credentialed program managers oversee.
Schedule a conversation to discuss your CISM preparation timeline, security management background, and how CISM fits your career and compliance goals.
Schedule CISM Training ConsultationVirtual Infrastructure Services LLC · South Brunswick, NJ · +1 (732) 200-7351