IT skills that go beyond the classroom.
+92 21 35044999WhatsAppVerify a certificate
ISACA · Advanced

Certified Information Security Manager (CISM)

Information security governance, risk management, security programme development and incident management for managers — aligned to the ISACA CISM job practice.
ISACA
Exam
CISM
Duration
8 Weeks
Level
Advanced
Delivery
Live online / on-site (Karachi)

What is Certified Information Security Manager (CISM)?

Certified Information Security Manager (CISM) is an advanced-level, 8 weeks instructor-led course that prepares you for the CISM exam at INFOTICS Academy in Karachi. Delivery: Live online / on-site (Karachi). The course fee is PKR 90,000. Register your interest and we will tell you when the next batch opens.

CISM is the credential for people who manage, design and oversee an enterprise's information-security programme. It is less about configuring tools and more about governance, risk, strategy and leadership: aligning security with business goals, deciding what risk is acceptable, building a programme, and leading the response when incidents occur.

The course is organised around the four CISM domains — information security governance, information security risk management, information security programme, and incident management — with case-based discussion, scenario questions and timed practice. The exam is 150 multiple-choice questions over four hours; ISACA also requires relevant work experience for the certification.

Certified Information Security Manager (CISM) at a glance
CertificationISACA Certified Information Security Manager (CISM)
Exam codeCISM
Vendor / trackISACA
LevelAdvanced
Duration8 Weeks
DeliveryLive online / on-site (Karachi)
Course feePKR 90,000
Attendance for certificateAt least 75%
Last updated
Exam outline checked
Updated outline: ISACA introduces a new CISM job practice for exams taken from 3 November 2026. Batches sitting the exam after that date are taught to the new job practice.

What will you learn?

  • Establish and maintain an information security governance framework aligned to organisational strategy
  • Identify, assess and treat information risk and report it to leadership
  • Develop, run and measure an information security programme including architecture, awareness and controls
  • Build incident management and response capability including business-continuity links
  • Interpret frameworks and standards such as ISO/IEC 27001, NIST CSF and COBIT in a management context
  • Approach CISM scenario questions with the "manager's mindset" and a proven revision plan

Who is this course for?

Designed for

Security analysts and engineers moving into management, IT managers, risk and compliance professionals, auditors and CISOs-in-the-making.

Prerequisites

Professional experience in information security or IT risk is strongly recommended. ISACA requires five years of relevant work experience (with permitted substitutions) to be awarded the certification; you can take the exam before completing the experience requirement.

What is in the curriculum?

5 modules · 23 recorded lessons and labs. Live classes follow the same order; recordings and slides unlock in your learner account after you enroll.

Module 1 Information security governance5 lessons

Strategy, roles and frameworks.

  • Enterprise governance and security strategy
  • Roles, responsibilities and reporting
  • Policies, standards and procedures
  • Frameworks: ISO/IEC 27001, NIST CSF, COBIT
  • Metrics and management reporting
Module 2 Information security risk management5 lessons

Understand and treat risk.

  • Risk identification and asset classification
  • Risk assessment methods and analysis
  • Risk treatment: mitigate, transfer, accept, avoid
  • Third-party and supply-chain risk
  • Risk monitoring and reporting
Module 3 Information security programme5 lessons

Build and run the programme.

  • Programme development and resources
  • Security architecture and control selection
  • Awareness, training and culture
  • Vendor management, change and configuration
  • Programme measurement and improvement
Module 4 Incident management5 lessons

Prepare, respond, recover.

  • Incident management and response plans
  • Detection, triage, escalation and containment
  • Forensics, evidence and lessons learned
  • Business continuity and disaster recovery integration
  • Tabletop exercise: ransomware scenarioLab
Module 5 Exam preparation3 lessons

Think like a security manager.

  • CISM question style and the manager's mindset
  • Timed practice assessment on this platformLab
  • Weak-area review and exam-day planning

What is included in the fee?

Live instructor-led classes

Small batches with attendance recorded every session. A 75% attendance record is required for the completion certificate.

Recorded lessons and materials

Catch up on any class and revise from recordings, slides and PDFs in the LMS.

Practical exercises

Practical exercises in every module so you apply what you learn.

Proctored mock exam

A 91-minute timed assessment with domain-level scoring and controlled retakes.

Verified digital badge and certificate

Earn a shareable badge and a QR-verified certificate, each with a public verification page.

Career portal access

CV and portfolio profile, job board and employer visibility for your verified credentials.

Independent training provider: this course prepares you for the CISM exam. The exam itself is sat and paid for separately with the certifying body. INFOTICS badges and certificates are training credentials, not vendor certifications.

How do you prove what you learned?

When does the next batch start?

No batch is open for enrollment right now

New batches are scheduled regularly. Register your interest and we will contact you as soon as dates for Certified Information Security Manager (CISM) are confirmed.

Frequently asked questions about Certified Information Security Manager (CISM)

What are the CISM exam domains?
Information security governance, information security risk management, information security programme, and incident management. The domain weightings are published by ISACA and are covered in class.
Do I need five years of experience to attend?
No. You can take the course and the exam earlier, but ISACA requires the work experience before it awards the certification.

More questions? Read the general FAQ or ask a counsellor.

Keep exploring

Related courses

All courses
PKR 90,000 No open batch
Notify me