Course overview
thinQtank® Learning is offering a unique instructor-led training camp that gives students the knowledge and skills needed to build and run an information security program that a business will actually fund and follow — establishing governance and the authority behind it, managing security risk in the language the board uses, designing and operating the program itself, and managing incidents when the program is tested.
This course also helps students prepare to take the ISACA CISM exam. CISM is the MANAGEMENT credential: it is not about configuring the control, it is about deciding which controls exist, what they cost, who owns them and how you know they work.
What's included
14 itemsthinQtank® Learning Accelerated Custom Exam Study Guide for the CISM exam
Exam delivery in classroom with 98% success
Custom and focused exam preparation software and materials
Course specific thinQtank® Learning publications to promote a fun and exciting learning
Membership to the thinQtank® Learning University Online
WE DO NOT "TEACH THE TEST" - Students will receive valuable examples and discussion
Receive all reading material and study guides when you register
All courses taught by certified instructors
Additional hours of remote lab access
Custom video recordings with even more in-depth learning of course topics
Customized practice exam software
Digital courseware
Retake any or all portions of the course as many times as you like in person or live on-line for 24 months
Six months mentoring access to our engineers after completing the course
What you'll be able to do
12 objectives- Establish information security governance, and the organizational authority that makes it real
- Align a security strategy with what the business is actually trying to do
- Build the policy, standard and procedure structure that a program rests on
- Identify, assess and treat information security risk, and report it in business terms
- Run a risk register that informs decisions rather than decorating a shelf
- Design an information security program: scope, resources, roles and the roadmap
- Select and justify controls on cost, risk reduction and feasibility — not on fashion
- Manage third-party and supply-chain security risk
- Measure the program: metrics, assurance and reporting that survive a board meeting
- Build and run incident management: preparation, classification, escalation and response
- Plan and test business continuity and recovery alongside incident response
- Communicate with executives, regulators and the business during and after an incident
The exam
- ISACA CISM — Certified Information Security Manager
- 150 multiple-choice questions
- Four hours to complete
- Scaled score of 450 or better, on a scale of 200 to 800
- Four domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management
- THE EXAM OUTLINE CHANGES ON 3 NOVEMBER 2026. Every class in this schedule runs after that date, so every student will sit the NEW outline. The four domains above are the ones ISACA lists today; the weightings are deliberately not published here, because the current ones will no longer apply
- Five years of information security MANAGEMENT experience, across at least three of the four domains and within the ten years before you apply, is required to certify. You may sit the exam first — you then have five years from passing to apply
- CISM Voucher — an exam registration is available through thinQtank for $760 USD. Ask when you register and we will add it to your enrollment
Who it's for, and what you need first
Target Audience
- Information security managers, and those about to become one
- Security architects and senior engineers moving into program ownership
- Risk, compliance and governance staff who own part of the security program
- IT managers and directors who carry security responsibility
- Consultants who build or assess security programs for clients
- Service members, veterans and military spouses using AF COOL, Army Credentialing Assistance, MyCAA or VET TEC 2.0
Prerequisites
- Practical experience of information security work, and of the organization it protects
- A working understanding of risk, controls and how a business makes spending decisions
- No certification is required to sit the exam. The experience requirement applies when you APPLY to certify, not when you test
How it's delivered
Instructor-Led Training
Immersive Live-Online Training
On-Site and Custom Delivery
Training Camp Format
This course is delivered as an instructor-led training camp, with the exam sat in the classroom as part of the camp. Camps are scheduled by cohort, and the balance of lecture and hands-on lab work is set to suit the group and the delivery method. Contact us for the schedule covering your dates.
Dates and locations
25 scheduledGuaranteed to run means the class goes ahead whatever the enrollment.
Prices shown are MSRP. Qualified military personnel funding through Air Force COOL, Army Credentialing Assistance, MyCAA or VET TEC 2.0 pay a flat $1,500 per class, whatever the listed price. Everyone else — call 855-868-4467 about group pricing, discounts and current promotions.