CISM: manage security, risk, and incidents
Prepare for CISM through governance, risk management, security programs, and banking and APS incident scenarios.
Objectives and progression
Eight lessons, 50 questions, and eight original cases with an internal 32-decision assessment in 50 minutes. Fictional banking examples connect investment, obsolescence, exceptions, suppliers, APS transition, containment, and recovery. This course follows the current outline before November 3, 2026, weighted 17/20/33/30%. ISACA announced an update for that date with weights 18/20/33/29% and new architecture areas. This first pass does not yet claim full coverage of the new outline.
Audience: Security managers, IT project managers, APS owners, and technology-risk professionals.
Prerequisites: IT and security fundamentals. ISACA certification requires the exam, validated experience, and other requirements; normally five years covering at least three domains, subject to eligible waiver rules. The exam may be taken before meeting experience requirements. Confirm individual requirements with ISACA; completing DR does not award certification.
290 estimated study minutes
- Connect security decisions to business objectives and responsibilities.
- Build proposals and reporting that enable informed decisions.
- Interpret exposure, controls, and estimates without overstating precision.
- Keep risk decisions valid when deadlines, threats, and dependencies change.
- Connect assets, resources, design, and metrics to executable controls.
- Assess evidence, shared responsibility, and secure service exit.
- Define criteria, authority, communication, and recovery before an incident.
- Coordinate evidence, communication, and return-to-service criteria.
Modules
- Governance, strategy, and authority
- Policies, investment, and reporting
- Assess risk and uncertainty
- Treat, monitor, and escalate risk
- Develop the security program
- Manage controls, suppliers, and lifecycle
- Prepare response and continuity
- Contain, recover, and learn
Continue learning
- CISSP — Certified Information Systems Security Professional
- CISA — Certified Information Systems Auditor
- Technical Project Manager
- Production Support L3
References and version
CISM current outline before November 3, 2026
- CISM Exam Content Outline · 2026-09-29
- ISACA Exam Candidate Guide · 2026-09-29
- Earn a CISM Certification · 2026-09-29
- ISACA updates CISM exam content outline · 2026-09-29
- Cybersecurity Framework 2.0 · 2026-09-29
- Guide for Conducting Risk Assessments · 2026-09-29
- Contingency Planning Guide · 2026-09-29
- Technical Guide to Security Testing and Assessment · 2026-09-29
- Incident Response Recommendations and Considerations · 2026-09-29
- Secure Software Development Framework 1.1 · 2026-09-29
- Authentication and Authenticator Management · 2026-09-29
- Shared Responsibility Model · 2026-09-29
- Guidelines for Media Sanitization · 2026-09-29
- Engineering Trustworthy Secure Systems · 2026-09-29
What you will explore
0 / 8Governance, strategy, and authority
Connect security decisions to business objectives and responsibilities.
Policies, investment, and reporting
Build proposals and reporting that enable informed decisions.
Assess risk and uncertainty
Interpret exposure, controls, and estimates without overstating precision.
Treat, monitor, and escalate risk
Keep risk decisions valid when deadlines, threats, and dependencies change.
Develop the security program
Connect assets, resources, design, and metrics to executable controls.
Manage controls, suppliers, and lifecycle
Assess evidence, shared responsibility, and secure service exit.
Prepare response and continuity
Define criteria, authority, communication, and recovery before an incident.
Contain, recover, and learn
Coordinate evidence, communication, and return-to-service criteria.