Overview

CISM® is a globally recognized standard of achievement of information security management. The CISM certification was developed specifically for experienced information security managers and those with information security management responsibilities who include Information Security Managers, Aspiring Information Security Managers, IS/IT Consultants and Chief Information Officers.

Private in-house training

Apart from public, instructor-led classes, we also offer private in-house trainings of this program for organizations. Call us at +852 2116 3328 or email us at [email protected] for more details.

Why Choose KORNERSTONE

  • KORNERSTONE is the Only ISACA® Accredited Training Organization in HK
  • ALL Official ISACA Material included
  • Practical, scenario-based learning – focus on application, not just theory
  • Over 85% Passing rate in ISACA program
  • Pass Guaranteed (80% over attendance)
  • Exclusive Offer on purchasing Exam Voucher

Skills Covered

  • Shape information security strategies that directly support business objectives
  • Design, implement, and sustain enterprise-wide security initiatives
  • Evaluate and prioritize security vulnerabilities to guide resource allocation
  • Coordinate incident detection, response, and recovery efforts
  • Establish governance frameworks that embed security into organizational culture

Target Audience

This program is designed for experienced information security managers, aspiring security leaders, IS/IT consultants, and Chief Information Officers. It is ideal for professionals responsible for developing and managing enterprise-wide information security programs and aligning security strategies with business objectives.

Training Highlights

  • 21-hour intensive examination preparation workshop
  • Conducted by renowned, experienced industrial expert
  • Real case study will be adopted with experience sharing
  • Eligible for 21 units of PDU / CPE

Course Curriculum

Module 1: Information Security Governance

  • Enterprise Governance Overview
  • Organizational Culture, Structures, Roles and Responsibilities
  • Legal, Regulatory and Contractual Requirements
  • Information Security Strategy
  • Information Governance Frameworks and Standards
  • Strategic Planning

Module 2: Information Security Risk Management

  • Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment, Evaluation and Analysis
  • Information Risk Response
  • Risk Monitoring, Reporting and Communication

Module 3: Information Security Program Development and Management

  • IS Program Development and Resources
  • IS Standards and Frameworks
  • Defining an IS Program Road Map
  • IS Program Metrics
  • IS Program Management
  • IS Awareness and Training
  • Integrating the Security Program with IT Operations
  • Program Communications, Reporting and Performance Management

Module 4: Information Security Incident Management

  • Incident Management and Incident Response Overview
  • Incident Management and Response Plans
  • Incident Classification/Categorization
  • Incident Management Operations, Tools and Technologies
  • Incident Investigation, Evaluation, Containment and Communication
  • Incident Eradication, Recovery and Review
  • Business Impact and Continuity
  • Disaster Recovery Planning
  • Training, Testing and Evaluation
  • Learning Objectives:
  • Distinguish between incident management and incident response
  • Outline the requirements and procedures necessary to develop an incident response plan
  • Identify techniques used to classify or categorize incidents.
  • Outline the types of roles and responsibilities required for an effective incident management and response team
  • Distinguish between the types of incident management tools and technologies available to an enterprise.
  • Describe the processes and methods used to investigate, evaluate and contain an incident
  • Identify the types of communications and notifications used to inform key stakeholders of incidents and tests.
  • Outline the processes and procedures used to eradicate and recover from incidents.
  • Describe the requirements and benefits of documenting events.
  • Explain the relationship between business impact, continuity and incident response.
  • Describe the processes and outcomes related to disaster recovery.
  • Explain the impact of metrics and testing when evaluating the incident response plan.

Let's make it work for you

Can’t find a date that fits? Need to train your whole team? Looking for a discount?
Speak to one of our training consultant today.

Dates & Locations

November 7, 2026 - November 21, 2026

Location: Jordan
Format: Onsite
Availability: GTR

Exam & Certification

  • Pass the CISM® examination
  • Five (5) or more years of experience in information security management. Experience waivers are available for a maximum of two (2) years
  • After passing the exam, candidates require to pay the US$50 application processing fee
  • CISM Chartered holders need to pay annual maintenance fee of US$45 for ISACA members and US$85 for ISACA non-member
  • Recertification is required every three years. CISM® Charter holders are required to earn 120 Continuing Professional Education (CPE) credits every 3 years, with a minimum 20CPEs earned each year after certification
  • More details: https://www.isaca.org/credentialing/cism/get-cism-certified

Trainer for this course

  • Mr. D Ko

    CISA, CISM, CCSP, AWS-SAA, CFA, FRM, HKICPA CPA

    • Experiences in providing regulatory compliance, internal control, incident assessment and IT risk and security consultation services for numerous local and international financial institutions
    • Act as Technology Risk and Assurance leader in government authority and providing regulatory and supervisory services
    • Collaborating with the banking industry and other organizations (such as SFC and IA) in various technology risk management or fintech initiatives
  • Mr. A Yau

    CISSP, CISA, CISM, CGEIT, CRISC, CDPSE

    • Mr. Yau is currently holding a Senior Management Role as Principal Cybersecurity Consultant and Trainer with 20+ years of experience
    • Specializes in leading engagements and serving clients in Information Security, including Next Generation Security Operation Center, IT Risk Assessment, Penetration Testing and IT Audit
    • Led the implementation and execution of Next Generation Security Operation Center, Security Operation Center, Infrastructure
    • Security for Mobile Device Management, Security Exchange 2010 and Infrastructure Security for Enterprise Cloud Services
    • Holds ISACA Accredited Trainer and Certified Mile2 Instructor credentials

Contact Us

Get in touch with our team via the form or WhatsApp »

Your preferences: