Each lesson develops one slice of the CISM body of knowledge — learning objectives, key terminology, a management-focused content outline, exam tips, and a scored knowledge check. Begin at Lesson 0 for the exam orientation and the manager’s mindset.
Day 1 — Morning
Orientation: Exam Strategy & the Management Mindset
CISM is a management exam, not a technical one. Before your first study hour, master the exam’s architecture, scoring, and the four domains — and the single habit that separates passers from the rest: answering every question as a business-aligned security manager, never a technician.
Day 1 — Afternoon
Domain 1 — Information Security Governance
Governance answers WHAT we protect and WHY before any technical HOW. Domain 1 covers security strategy, the five governance outcomes, frameworks (COBIT, ISO 27001, NIST CSF), board and steering-committee oversight, and aligning the security program with business objectives.
Day 2 — Morning
Domain 2 — Information Security Risk Management (Part A)
Risk is a business decision, not an IT decision. Part A covers the risk management strategy, risk appetite and tolerance, and information asset classification and valuation — the foundation on which every risk-based decision rests.
Day 2 — Afternoon
Domain 2 — Information Security Risk Management (Part B)
Part B works the risk lifecycle in practice: risk identification, assessment, and analysis; risk treatment (accept, mitigate, transfer, avoid); and ongoing risk monitoring and reporting — communicating risk to leadership in business terms.
Day 3 — Morning
Domain 3 — Information Security Program (Part A)
The program is where strategy becomes capability. The highest-weight domain begins with the security program charter and architecture, then the controls framework — selecting, implementing, and integrating the controls that deliver the strategy.
Day 3 — Afternoon
Domain 3 — Information Security Program (Part B)
Part B runs the program day to day: security awareness and training, third-party and supply-chain integration, security operations, the metrics that prove value to leadership, and the continuous-improvement loop that keeps the program effective.
Day 4 — Morning
Domain 4 — Incident Management (Part A)
When prevention fails, management response defines the outcome. Part A covers the incident management program, incident classification, and the response lifecycle — from preparation and detection through containment, eradication, and recovery, with the manager’s oversight role front and center.
Day 4 — Afternoon
Domain 4 — Business Continuity & Recovery (Part B)
Resilience is the manager’s job. Part B covers business continuity planning, disaster recovery, plan testing, and the post-incident review — ensuring the organization can absorb disruption, recover within defined objectives, and learn from every event.
Day 5 — Capstone
Capstone — Final Review, Practice & Exam Prep
The closer: synthesize the four domains and the trap-answer patterns, work integrated cross-domain scenarios, then build a 30/60/90-day study plan and an exam-day playbook — before proving it on the full, timed CISM Practice Exam.