◆ ISACA Certification Preparation ◆

Lead with the CISM in Five Days

A management-focused boot camp for security leaders pursuing ISACA’s premier credential for information security managers. Nine lessons, four domains, one business-first mindset — every answer evaluated as a manager, not a technician.

Begin the Boot Camp ▼

Course Content

Nine Lessons. Four Domains.

Each lesson develops one slice of the CISM body of knowledge — learning objectives, key terminology, a management-focused content outline, exam tips, and a scored knowledge check. Begin at Lesson 0 for the exam orientation and the manager’s mindset.

L 0
Day 1 — Morning
Orientation: Exam Strategy & the Management Mindset

CISM is a management exam, not a technical one. Before your first study hour, master the exam’s architecture, scoring, and the four domains — and the single habit that separates passers from the rest: answering every question as a business-aligned security manager, never a technician.

L 1
17% Exam Weight
Day 1 — Afternoon
Domain 1 — Information Security Governance

Governance answers WHAT we protect and WHY before any technical HOW. Domain 1 covers security strategy, the five governance outcomes, frameworks (COBIT, ISO 27001, NIST CSF), board and steering-committee oversight, and aligning the security program with business objectives.

L 2
20% Exam Weight
Day 2 — Morning
Domain 2 — Information Security Risk Management (Part A)

Risk is a business decision, not an IT decision. Part A covers the risk management strategy, risk appetite and tolerance, and information asset classification and valuation — the foundation on which every risk-based decision rests.

L 3
20% Exam Weight
Day 2 — Afternoon
Domain 2 — Information Security Risk Management (Part B)

Part B works the risk lifecycle in practice: risk identification, assessment, and analysis; risk treatment (accept, mitigate, transfer, avoid); and ongoing risk monitoring and reporting — communicating risk to leadership in business terms.

L 4
33% Exam Weight
Day 3 — Morning
Domain 3 — Information Security Program (Part A)

The program is where strategy becomes capability. The highest-weight domain begins with the security program charter and architecture, then the controls framework — selecting, implementing, and integrating the controls that deliver the strategy.

L 5
33% Exam Weight
Day 3 — Afternoon
Domain 3 — Information Security Program (Part B)

Part B runs the program day to day: security awareness and training, third-party and supply-chain integration, security operations, the metrics that prove value to leadership, and the continuous-improvement loop that keeps the program effective.

L 6
30% Exam Weight
Day 4 — Morning
Domain 4 — Incident Management (Part A)

When prevention fails, management response defines the outcome. Part A covers the incident management program, incident classification, and the response lifecycle — from preparation and detection through containment, eradication, and recovery, with the manager’s oversight role front and center.

L 7
30% Exam Weight
Day 4 — Afternoon
Domain 4 — Business Continuity & Recovery (Part B)

Resilience is the manager’s job. Part B covers business continuity planning, disaster recovery, plan testing, and the post-incident review — ensuring the organization can absorb disruption, recover within defined objectives, and learn from every event.

L 8
Day 5 — Capstone
Capstone — Final Review, Practice & Exam Prep

The closer: synthesize the four domains and the trap-answer patterns, work integrated cross-domain scenarios, then build a 30/60/90-day study plan and an exam-day playbook — before proving it on the full, timed CISM Practice Exam.

Boot Camp Schedule

Five Days to Certification-Ready

One domain per day, with Day 5 devoted to integrated practice and exam simulation. Two sessions per day, morning and afternoon, each running approximately 3 hours with knowledge checks, exam tips, and Q&A.

Day 1
Governance & Strategy
  • Adopt the business-aligned manager mindset for the exam
  • Evaluate security governance, strategy, and framework alignment
Day 2
Risk Thinking
  • Identify, classify, and value information assets and risk
  • Analyze risk (qualitative/quantitative) and recommend treatment
Day 3
Building the Program
  • Design a risk-based security program, controls, and architecture
  • Evaluate awareness, third-party risk, and program operations
Day 4
Incident & Resilience
  • Direct incident response across its full lifecycle
  • Evaluate continuity and disaster-recovery objectives and testing
Day 5
Capstone & Exam Sim
  • Synthesize the four domains into one management-judgment framework
  • Rehearse under timed, blueprint-weighted exam conditions

Exam Blueprint

Domain Weights at a Glance

The CISM exam draws its 150 questions from four domains. Domains 3 and 4 — building the program and managing incidents — together make up 63% of the exam. Weight your study accordingly, and resist over-studying the lighter governance domain.

D1 — Information Security Governance17%
D2 — Information Security Risk Management20%
D3 — Information Security Program33%
D4 — Incident Management30%

Boot Camp Resources

Exam Resources, Labs & Development Tools

Supplemental tools to reinforce every CISM domain — from scored practice assessments and study audio to hands-on management scenario labs and AI-assisted content creation utilities, all calibrated to the business-first manager’s perspective.

🎯

Exam Resources

Reference
🎧
Generate Audio Files for Study

This tool creates 10-minute audio podcasts you can use to study for the CISM exam. The podcasts are generated for specific domains and topics within a domain.

Covers: Podcast · 10 Minute Max · Study · Perfect for Driving Trips · Audio Files

Assessment
📝
CISM Practice Exam

Timed, scenario-based practice questions spanning all four CISM domains. Calibrated to the management-judgment mindset the exam demands — think like a business-aligned security manager, not a technician. Includes instant feedback, domain-by-domain score breakdown, and full review mode with rationale.

Covers: All 4 Domains · Timed · Scored · Rationale · Review Mode

Reference
🖨️
Exam-Day One-Pager

A one-page, printable cram sheet of the two highest-yield artifacts: the manager mindset filters and the trap-answer patterns. Save it as a PDF and review it the morning of the exam.

Covers: Printable · Mindset Filters · Trap Patterns · Exam-Day Review

🔬

Labs & Activities

Hands-On Lab
💻
CISM Management Scenario Labs

Apply CISM domain concepts in structured, scenario-based exercises designed for the practicing security manager. Each lab presents a realistic enterprise challenge drawn from the four domains — analyze the situation, complete guided tasks, and demonstrate the business-aligned, risk-based decision-making the credential requires.

Covers: Scenario Analysis · Guided Tasks · Domain Application · Management Decisions

Activity Builder
🧩
Generate Workshop Activities

Pick a CISM domain, an interaction mechanic, and the flow you want — and watch the prompt build in real time. Paste it into your AI platform to generate a self-contained, interactive HTML5 management activity.

Covers: Self-contained · Interactive · Activities · Simulations · HTML Files

🔧

Content Development Tools

Dev Tool
🖼️
Graphics Generation

Generate custom instructional graphics, process diagrams, and visual assets aligned to CISM domain content. Create governance maps, risk-treatment flows, program architecture diagrams, and incident-response visuals to support boot-camp instruction.

Covers: Diagrams · Governance Maps · Process Flows · Domain Visuals · Assets

Dev Tool
✍️
Content Generation

Generate lesson text, scenario-based practice questions, domain summaries, and study materials aligned to the ISACA CISM Job Practice. Accelerate boot-camp development with AI-assisted content calibrated to the business-aligned, management-first perspective the CISM demands.

Covers: Lesson Text · Exam Questions · Scenarios · Domain Summaries · Study Aids

Dev Tool
📖
Case Study Generation

Generate custom instructional case studies aligned to CISM domain content. Create management case studies spanning governance structures, risk decisions, security program operations, third-party integration, and incident-response scenarios.

Covers: Management Scenarios · Governance · Risk Decisions · Program Ops · Incident Response

About This Boot Camp

Built for Security Leaders

Who this is for

This boot camp is designed for information security managers, aspiring CISOs, security program leads, risk managers, and IT managers moving into security leadership who are ready to pursue the CISM — the Certified Information Security Manager credential issued by ISACA.

Unlike technically focused certifications, CISM rewards management thinking. Over five structured days you will work through every domain of the ISACA CISM Job Practice with the depth and business-aligned judgment the exam demands — learning to answer as the manager who balances security against business objectives.

How to use this resource

Work through each lesson in order. Every domain lesson includes a glossary of key terms, a management-focused content outline, scenario-based exam questions, and exam-tip callouts. Complete Lessons 8 and 9 last — the capstone scenarios and mock exams are most effective once all four domains are covered.

Exam Quick Facts

150Exam Questions
4 hrsTime Limit
450Passing Score /800
5 yrsExperience Req.
200–800Scaled Score
120 CPEPer 3-yr Cycle

Budgeting? Beyond the exam registration fee, plan for a one-time certification application fee and a recurring annual maintenance fee (AMF) to keep the credential active. See the full cost breakdown in Lesson 0 →