Become a Strategic Enterprise Security Leader with the ISACA CISM credential.
- Why get CISM certified: As the growing number of high-profile breaches demonstrates, information security failures can significantly damage an enterprise’s bottom line and reputation. Demand for skilled information security management professionals continues to rise.
- Why CISM matters: Per the 2027 Cloud Adoption and Risk Report sponsored by CSA, one of the most important IT skills needed in the next five years are incident response management, cited by 80.4% of respondents.
- Who should get CISM certified: Mid to high-level professionals with 3–5 years of experience in the managing, designing, overseeing and assessing of enterprise information security
Certified Information Security Manager demonstrates your ability to assess risks, implement effective governance and proactively respond to incidents. Stay on top of evolving security threats such as data breaches and ransomware attacks.
HRDC Claimable and Malaysian Bumiputeras are eligible for Yayasan Peneraju Financing Scheme. T&C applies.
Discover Top ISACA Certifications for Malaysia’s Digital Trust Future: Advance your AI, cybersecurity, audit, governance, risk, and privacy capabilities with ISACA certifications built for the high impact roles organizations need in 2026.

Overview
Designed for IT professionals with technical expertise and experience in IS/IT security and control looking to transition from team player to manager.
Data breaches, ransomware attacks and other constantly evolving security threats are top-of-mind for today’s IT professionals. With a Certified Information Security Manager® (CISM®) certification, you’ll learn how to assess risks, implement effective governance and proactively respond to incidents.
The ISACA CISM certification can add credibility and confidence to interactions with internal and external stakeholders, peers, and regulators.
This cybersecurity certification indicates expertise in information security governance, program development and management, incident management and risk management.
Content in this course is:
- Aligned with the CISM job practice
- Adapted from the CISM Review Manual 16th Edition
- Reviewed by subject matter experts that hold the CISM certification
The course features an enhanced facilitator guide, additional participant resources, knowledge check questions from the CISM Questions, Answers and Explanations (QAE) database along with scenario-based activities and enrichment materials (articles, podcasts and whitepapers) selected from the ISACA website to provide learners with an opportunity to go deeper into specific areas related to the course content.
Here are five insightful blog posts about ISACA and its cybersecurity certifications. Each one focuses on a different aspect of how ISACA’s training can enhance your cybersecurity career, take a read:Â
- ISACA Certifications in 2026: The Definitive Guide to Digital Trust and Compliance in Malaysia
- Survival of the Fittest: Using CISA and CISM to Navigate Malaysia’s Cyber Security Act 2024
- Malaysia Salary Guide 2026: The Real Value of ISACA Certifications
- Beyond the Hype: Why 2026 Demands the ISACA AAIA and AAISM Certifications
- Theory vs. Reality: How the CCOA Certification Bridges the Skills Gap in Malaysian SOCs
Explore more about cybersecurity certifications with our cybersecurity training and certifications guide.
Skills Covered
After completing this course, participants should be able to:
- Explain the relationship between executive leadership, enterprise governance and information security governance.
- Outline the components used to build an information security strategy.
- Explain how the risk assessment process influences the information security strategy.
- Articulate the process and requirements used to develop an effective information risk response strategy.
- Describe the components of an effective information security program.
- Explain the process to build and maintain an enterprise information security program.
- Outline techniques used to assess the enterprise’s ability and readiness to manage an information security incident.
- Outline methods to measure and improve response and recovery capabilities.
Prerequisites
To earn the CISM credential you need five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas.
Target Audience
The ISACA CISM certification is perfect for experienced information security managers and everyone who works in IT Governance. You will learn about four domains in information security. These domains are about compliance, risk management and security governance

Domain 1: Information Security Governance
- Enterprise Governance Overview
- Organizational Culture, Structures, Roles and Responsibilities
- Legal, Regulatory and Contractual Requirements
- Information Security Strategy
- Information Governance Frameworks and Standards
- Strategic Planning
Domain 2: Managing Information Risk
- Risk and Threat Landscape
- Vulnerability and Control Deficiency Analysis
- Risk Assessment, Evaluation and Analysis
- Information Risk Response
- Risk Monitoring, Reporting and Communication
Domain 3: Developing and Managing an Information Security Program
- IS Program Development and Resources
- IS Standards and Frameworks
- Defining an IS Program Road Map
- IS Program Metrics
- IS Program Management
- IS Awareness and Training
- Integrating the Security Program with IT Operations
- Program Communications, Reporting and Performance Management
Domain 4: Information Security Incident Management
- Incident Management and Incident Response Overview
- Incident Management and Response Plans
- Incident Classification/Categorization
- Incident Management Operations, Tools and Technologies
- Incident Investigation, Evaluation, Containment and Communication
- Incident Eradication, Recovery and Review
- Business Impact and Continuity
- Disaster Recovery Planning
- Training, Testing and Evaluation
Dates & Locations
September 8, 2026 - September 11, 2026
September 8, 2026 - September 11, 2026
October 13, 2026 - October 16, 2026
October 13, 2026 - October 16, 2026
November 10, 2026 - November 13, 2026
November 10, 2026 - November 13, 2026
December 1, 2026 - December 4, 2026
December 1, 2026 - December 4, 2026

Exam & Certification
ISACA’s Certified Information Security Manager (CISM) certification brings credibility to your team and ensures alignment between the organization’s information security program and its broader goals and objectives. CISM can validate your team’s commitment to compliance, security and integrity and increase customer retention!
New to cybersecurity or thinking of taking up a career in cybersecurity? Explore our fundamental cybersecurity courses:
Training & Certification Guide
Frequently Asked Questions
Speak to a Training Consultant
All courses are HRD Claimable.
Get in touch with our team via the form or WhatsApp us on +6011-5119 6631
























