CISM Certified Information Security Manager


CISM staat voor Certified Information Security Manager. Het CISM-certificaat geeft u internationale erkenning als security professional. Daarmee verhoogt u uw marktwaarde. De training CISM leidt u op voor het officiële CISM-examen van ISACA.

Omschrijving

Binnen de CISM-certificering worden de volgende vier security-domeinen onderkend:

  • Information Security Governance;
  • Information Risk Management and Compliance;
  • Information Security Program Development and Management;
  • Information Security Incident Management.

Tijdens de training CISM Certified Information Security Manager worden alle belangrijke security-domeinen behandeld. Ook wordt geoefend met examenvragen. U leert hoe u informatiebeveiliging in lijn kunt brengen met uw business-doelstellingen en wettelijk gestelde eisen. Ook wordt ingegaan op informatiebeveiligingsrisico’s en de mogelijkheden om deze risico’s tot een voor uw organisatie aanvaardbaar niveau te beperken.

Ook leert u tijdens de training hoe u de strategie en het beleid met betrekking tot informatiebeveiliging kunt bepalen. Ten slotte richt de training zich op security-incidenten, waarin het beperken van de impact van security incidenten voor de business centraal staat.

Om officieel CISM gecertificeerd te worden dient u aan de onderstaande eisen te voldoen:

  • slagen voor het officiële CISM-examen;
  • beschikken over ten minste 5 jaar relevante werkervaring in ten minste twee CISM-domeinen (of 4 jaar ervaring aangevuld met een HBO+ opleiding).

Het CISM examen is gefocust op de vier domeinen die zijn gedefinieerd door ISACA. Het daadwerkelijke examen duurt vier uur en bestaat uit 150 Engelstalige multiplechoicevragen.

De cursusprijs is inclusief lesmateriaal, koffie, thee en lunches. De examenkosten zijn niet inbegrepen.

Inhoud

Domain 1: Information Security Governance

  • Develop an information security strategy, aligned with business goals and directives
  • Establish and maintain an information security governance framework
  • Integrate information security governance into corporate governance
  • Develop and maintain information security policies
  • Develop business cases to support investments in information security
  • Identify internal and external influences to the organization
  • Gain ongoing commitment from senior leadership and other stakeholders
  • Define, communicate and monitor information security responsibilities
  • Establish internal and external reporting and communication channels

Domain 2: Information Risk Management

  • Establish and/or maintain a process for information asset classification to ensure that measures taken to protect assets are proportional to their business value
  • Identify legal, regulatory, organizational and other applicable requirements to manage the risk of noncompliance to acceptable levels
  • Ensure that risk assessments, vulnerability assessments and threat analyses are conducted consistently, and at appropriate times, to identify and assess risk to the organization’s information
  • Identify, recommend or implement appropriate risk treatment/response options to manage risk to acceptable levels based on organizational risk appetite
  • Determine whether information security controls are appropriate and effectively manage risk to an acceptable level
  • Facilitate the integration of information risk management into business and IT processes to enable a consistent and comprehensive information risk management program across the organization
  • Monitor for internal and external factors (e.g., threat landscape, cybersecurity, geopolitical, regulatory change) that may require reassessment of risk to ensure that changes to existing or new risk scenarios are identified and managed appropriately
  • Report noncompliance and other changes in information risk to facilitate the risk management decision-making process.
  • Ensure that information security risk is reported to senior management to support an understanding of potential impact on the organizational goals and objectives

Domain 3: Information Security Program Development & Management

  • Develop a security program, aligned with information security strategy
  • Ensure alignment between the information security program and other business functions
  • Establish and maintain requirements for all resources to execute the IS program
  • Establish and maintain IS architectures to execute the IS program
  • Develop documentation that ensures compliance with policies
  • Develop a program for information security awareness and training
  • Integrate information security requirements into organizational processes
  • Integrate information security requirements into contracts and activities of third parties
  • Develop procedures (metrics) to evaluate the effectiveness and efficiency of the IS program
  • Compile reports to key stakeholders on overall effectiveness of the IS program and the underlying business processes in order to communicate security performance

Domain 4: Information Security Incident Management

  • Define (types of) information security incidents
  • Establish an incident response plan
  • Develop processes for timely identification of information security incidents
  • Develop processes to investigate and document information security incidents
  • Develop incident escalation and communication processes
  • Establish teams that effectively respond to information security incidents
  • Test and review the incident response plan
  • Establish communication plans and processes
  • Determine the root cause of IS incidents
  • Align incident response plan with DRP and BCP
Plaats en data (15)
Plaats Duur Data
NIEUWEGEIN - Iepenhoeve 5 4 dagen 3 t/m 6 augustus 2026

3 augustus 2026 09:00 - 17:00 uur
4 augustus 2026 09:00 - 17:00 uur
5 augustus 2026 09:00 - 17:00 uur
6 augustus 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 3 t/m 6 augustus 2026

3 augustus 2026 09:00 - 17:00 uur
4 augustus 2026 09:00 - 17:00 uur
5 augustus 2026 09:00 - 17:00 uur
6 augustus 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 31 augustus 2026 t/m 3 september 2026

31 augustus 2026 09:00 - 17:00 uur
1 september 2026 09:00 - 17:00 uur
2 september 2026 09:00 - 17:00 uur
3 september 2026 09:00 - 17:00 uur
Inschrijven >
NIEUWEGEIN - Iepenhoeve 5 4 dagen 28 september 2026 t/m 1 oktober 2026

28 september 2026 09:00 - 17:00 uur
29 september 2026 09:00 - 17:00 uur
30 september 2026 09:00 - 17:00 uur
1 oktober 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 28 september 2026 t/m 1 oktober 2026

28 september 2026 09:00 - 17:00 uur
29 september 2026 09:00 - 17:00 uur
30 september 2026 09:00 - 17:00 uur
1 oktober 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 19 t/m 22 oktober 2026

19 oktober 2026 10:30 - 18:30 uur
20 oktober 2026 10:30 - 18:30 uur
21 oktober 2026 10:30 - 18:30 uur
22 oktober 2026 10:30 - 18:30 uur
Inschrijven >
NIEUWEGEIN - Iepenhoeve 5 4 dagen 26 t/m 29 oktober 2026

26 oktober 2026 09:00 - 17:00 uur
27 oktober 2026 09:00 - 17:00 uur
28 oktober 2026 09:00 - 17:00 uur
29 oktober 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 26 t/m 29 oktober 2026

26 oktober 2026 09:00 - 17:00 uur
27 oktober 2026 09:00 - 17:00 uur
28 oktober 2026 09:00 - 17:00 uur
29 oktober 2026 09:00 - 17:00 uur
Inschrijven >
NIEUWEGEIN - Iepenhoeve 5 4 dagen 26 t/m 29 oktober 2026

26 oktober 2026 09:00 - 17:00 uur
27 oktober 2026 09:00 - 17:00 uur
28 oktober 2026 09:00 - 17:00 uur
29 oktober 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 26 t/m 29 oktober 2026

26 oktober 2026 09:00 - 17:00 uur
27 oktober 2026 09:00 - 17:00 uur
28 oktober 2026 09:00 - 17:00 uur
29 oktober 2026 09:00 - 17:00 uur
Inschrijven >
PATERSWOLDE - Groningerweg 19 4 dagen 23 t/m 26 november 2026

23 november 2026 09:00 - 17:00 uur
24 november 2026 09:00 - 17:00 uur
25 november 2026 09:00 - 17:00 uur
26 november 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 23 t/m 26 november 2026

23 november 2026 09:00 - 17:00 uur
24 november 2026 09:00 - 17:00 uur
25 november 2026 09:00 - 17:00 uur
26 november 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 7 t/m 10 december 2026

7 december 2026 09:00 - 17:00 uur
8 december 2026 09:00 - 17:00 uur
9 december 2026 09:00 - 17:00 uur
10 december 2026 09:00 - 17:00 uur
Inschrijven >
NIEUWEGEIN - Iepenhoeve 5 4 dagen 21 t/m 24 december 2026

21 december 2026 09:00 - 17:00 uur
22 december 2026 09:00 - 17:00 uur
23 december 2026 09:00 - 17:00 uur
24 december 2026 09:00 - 17:00 uur
Inschrijven >
Virtual Classroom 4 dagen 21 t/m 24 december 2026

21 december 2026 09:00 - 17:00 uur
22 december 2026 09:00 - 17:00 uur
23 december 2026 09:00 - 17:00 uur
24 december 2026 09:00 - 17:00 uur
Inschrijven >

Praktische informatie

Doelgroep

De training is bedoeld voor medewerkers, die bezig zijn met de organisatorische kant van informatiebeveiliging. Het betreft onder andere Information Security Managers, Informatiebeveiligingsspecialisten, IT Security Managers, Security Officers, Security Consultants, Risk Managers en IT Auditors.

Voorkennis

Om officieel CISM gecertificeerd te worden dient u aan de onderstaande eisen te voldoen: - slagen voor het officiële CISM-examen; - beschikken over ten minste 5 jaar relevante werkervaring in ten minste twee CISM-domeinen (of 4 jaar ervaring aangevuld met een HBO+-opleiding).

Duur

De cursusduur is vier dagen.

Groepsgrootte

De maximale groepsgrootte bedraagt twaalf personen.

Certificaat

Na afloop van de cursus kunt u deelnemen aan het CISM-examen. De kosten voor het examen zijn niet bij de prijs inbegrepen.