logo-img
CISM training - Certified Information Security Manager

CISM training - Certified Information Security Manager

4 days + 365 days of online support via the MyTSTC learning platform Classroom Engels, Nederlands MyTSTC

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

In the CISM training, you learn to align information security with existing business objectives and legally established requirements. As a Security Manager, you think in terms of risks and the possibilities to reduce these risks to an acceptable level for the organization. You determine the strategy and policy regarding information security and security incidents, with a focus on minimizing their impact on the business. 

With a CISM certification, you confirm your ability to assess risks, apply effective governance, and proactively respond to incidents. With a focus on emerging technologies such as AI and blockchain, it ensures that your skills align with the evolving security threats and requirements in the market. By addressing current concerns such as data breaches and ransomware attacks, the CISM course ensures that you stay ahead in a continuously changing environment.

Especially within larger organizations, the exact technical implementation of information security often falls outside the work of the security manager. Such knowledge is therefore not necessary for participation in this training.

In preparation for the CISM training, you will receive the official ISACA CISM study material and access to our accompanying MyTSTC learning platform upon registration. By doing a short self-study before the training, you will be better prepared for the classroom training and can ask more targeted questions to the experienced instructor based on the material covered. The result is a more interactive course with more depth on the heavier topics and less difference in levels among participants.

Working method

We deviate from the regular CISM training by starting with a short, guided self-study period after registration. For this, you will receive the CISM Review Manual by mail and gain access to our exclusive MyTSTC learning platform prior to the classroom days. On the platform, you will take a short assessment test after which you will receive tailored material (including videos) based on your answers to prepare you for the intensive training. Furthermore, you will read a limited number of pages from the Review Manual. With this approach, we reduce differences in levels among participants and spread the necessary self-study over a part before and after the training.

We advise you to practice with the included test questions from the ISACA CISM Questions, Answers & Explanations database after the training before taking the exam to get accustomed to the typical ISACA question format. If you need further guidance, you will receive it via MyTSTC. Finally, it is possible to attend the training again free of charge within a year (not applicable to in-company training). For example, if you unexpectedly fail, but also if you wish for extra help towards the exam.

This training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it’s just like being present in the classroom training, but from your own location.

Certification

This training prepares you for the CISM exam from ISACA. This exam can be taken throughout the year at various exam locations in the Netherlands, including at TSTC or from home under the supervision of your webcam. There are no admission requirements for exam participation. However, you must have sufficient relevant practical experience to hold the CISM title upon a successful result. If you do not yet meet the specified requirement, it is possible to gain this experience after you have passed the exam. Participants who unfortunately fail the exam may rejoin the classroom training free of charge. Our support only ends when you succeed.

Training Requirements

  • Information Security Manager
  • IT Security Manager
  • Information Security Officer
  • IT Security Officer
  • CISSP gecertificeerden
  • CISO - Chief Information Security Officer
  • Risk & Compliance Manager
  • Security Consultant / Adviseur Informatiebeveiliging
  • Business Continuity / Disaster Recovery Manager

Training Content

Dit domein biedt je diepgaand inzicht in de cultuur, regelgeving en structuur die samenhangen met enterprise governance, en stelt je in staat om informatiebeveiligingsstrategieën te analyseren, plannen en ontwikkelen. Hiermee versterkt je de geloofwaardigheid van je organisatie op strategisch niveau richting stakeholders op het gebied van informatiebeveiligingsgovernance.

A. Organisatiesturing op ondernemingsniveau

Organisatiecultuur

Wettelijke, regelgevende en contractuele vereisten

Organisatiestructuren, rollen en verantwoordelijkheden

B. Informatiebeveiligingsstrategie

Ontwikkeling van de informatiebeveiligingsstrategie

Frameworks en standaarden voor informatiegovernance

Strategische planning (bijv. budgetten, middelen en businesscase

Dit domein stelt je in staat om potentiële informatiebeveiligingsrisico’s, dreigingen en kwetsbaarheden te analyseren en te identificeren. Daarnaast krijg je alle benodigde kennis om informatiebeveiligingsrisico’s te herkennen en te beheersen, zodat je op managementniveau kunt opereren.

A. Informatiebeveiligings-risicobeoordeling

Opkomend risico- en dreigingslandschap

Analyse van kwetsbaarheden en tekortkomingen in beheersmaatregelen

Risicobeoordeling en -analyse

B. Informatiebeveiligingsrisicorespons

Risicobehandeling / risicobeheersingsopties

Eigenaarschap van risico’s en beheersmaatregelen

Risicomonitoring en -rapportage

Dit domein behandelt de middelen, classificatie van bedrijfsmiddelen (assets) en frameworks voor informatiebeveiliging. Daarnaast leer je hoe je een informatiebeveiligingsprogramma beheert, inclusief beheersmaatregelen, testing, communicatie, rapportage en implementatie.

A. Ontwikkeling van het informatiebeveiligingsprogramma

Middelen voor het informatiebeveiligingsprogramma (bijv. mensen, tools en technologieën)

Identificatie en classificatie van informatie-assets

Branchestandaarden en frameworks voor informatiebeveiliging

Informatiebeveiligingsbeleid, -procedures en -richtlijnen

Meetindicatoren (metrics) voor het informatiebeveiligingsprogramma

B. Management van het informatiebeveiligingsprogramma

Ontwerp en selectie van informatiebeveiligingsmaatregelen

Implementatie en integratie van informatiebeveiligingsmaatregelen

Testing en evaluatie van informatiebeveiligingsmaatregelen

Bewustwording en training op het gebied van informatiebeveiliging

Beheer van externe diensten (bijv. dienstverleners, leveranciers, derde en vierde partijen)

Communicatie en rapportage binnen het informatiebeveiligingsprogramma

Dit domein biedt diepgaande training in risicomanagement en paraatheid, inclusief hoe je een organisatie voorbereidt op incidentrespons en herstel begeleidt. Het tweede onderdeel behandelt tools, evaluatie- en indammingsmethoden binnen incidentmanagement.

A. Incidentmanagementparaatheid

Incident Response Plan (IRP)

Business Impact Analysis (BIA)

Business Continuity Plan (BCP)

Disaster Recovery Plan (DRP)

Incidentclassificatie en -categorisatie

Training, testing en evaluatie van incidentmanagement

B. Incidentmanagementoperaties

Tools en technieken voor incidentmanagement

Incidentonderzoek en -evaluatie

Methoden voor incidentindamming

Communicatie bij incidentrespons (bijv. rapportage, melding en escalatie)

Incidentuitbanning en herstel

Post-incident review-praktijken

Description

In the CISM training, you learn to align information security with existing business objectives and legally established requirements. As a Security Manager, you think in terms of risks and the possibilities to reduce these risks to an acceptable level for the organization. You determine the strategy and policy regarding information security and security incidents, with a focus on minimizing their impact on the business. 

With a CISM certification, you confirm your ability to assess risks, apply effective governance, and proactively respond to incidents. With a focus on emerging technologies such as AI and blockchain, it ensures that your skills align with the evolving security threats and requirements in the market. By addressing current concerns such as data breaches and ransomware attacks, the CISM course ensures that you stay ahead in a continuously changing environment.

Especially within larger organizations, the exact technical implementation of information security often falls outside the work of the security manager. Such knowledge is therefore not necessary for participation in this training.

In preparation for the CISM training, you will receive the official ISACA CISM study material and access to our accompanying MyTSTC learning platform upon registration. By doing a short self-study before the training, you will be better prepared for the classroom training and can ask more targeted questions to the experienced instructor based on the material covered. The result is a more interactive course with more depth on the heavier topics and less difference in levels among participants.

Working method

We deviate from the regular CISM training by starting with a short, guided self-study period after registration. For this, you will receive the CISM Review Manual by mail and gain access to our exclusive MyTSTC learning platform prior to the classroom days. On the platform, you will take a short assessment test after which you will receive tailored material (including videos) based on your answers to prepare you for the intensive training. Furthermore, you will read a limited number of pages from the Review Manual. With this approach, we reduce differences in levels among participants and spread the necessary self-study over a part before and after the training.

We advise you to practice with the included test questions from the ISACA CISM Questions, Answers & Explanations database after the training before taking the exam to get accustomed to the typical ISACA question format. If you need further guidance, you will receive it via MyTSTC. Finally, it is possible to attend the training again free of charge within a year (not applicable to in-company training). For example, if you unexpectedly fail, but also if you wish for extra help towards the exam.

This training is classroom-based but can also be attended Live Online if desired. You will then follow the training live remotely with our own instructor, view the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. Essentially, it’s just like being present in the classroom training, but from your own location.

Certification

This training prepares you for the CISM exam from ISACA. This exam can be taken throughout the year at various exam locations in the Netherlands, including at TSTC or from home under the supervision of your webcam. There are no admission requirements for exam participation. However, you must have sufficient relevant practical experience to hold the CISM title upon a successful result. If you do not yet meet the specified requirement, it is possible to gain this experience after you have passed the exam. Participants who unfortunately fail the exam may rejoin the classroom training free of charge. Our support only ends when you succeed.

Training Requirements

  • Information Security Manager
  • IT Security Manager
  • Information Security Officer
  • IT Security Officer
  • CISSP gecertificeerden
  • CISO - Chief Information Security Officer
  • Risk & Compliance Manager
  • Security Consultant / Adviseur Informatiebeveiliging
  • Business Continuity / Disaster Recovery Manager

Training Content

Dit domein biedt je diepgaand inzicht in de cultuur, regelgeving en structuur die samenhangen met enterprise governance, en stelt je in staat om informatiebeveiligingsstrategieën te analyseren, plannen en ontwikkelen. Hiermee versterkt je de geloofwaardigheid van je organisatie op strategisch niveau richting stakeholders op het gebied van informatiebeveiligingsgovernance.

A. Organisatiesturing op ondernemingsniveau

Organisatiecultuur

Wettelijke, regelgevende en contractuele vereisten

Organisatiestructuren, rollen en verantwoordelijkheden

B. Informatiebeveiligingsstrategie

Ontwikkeling van de informatiebeveiligingsstrategie

Frameworks en standaarden voor informatiegovernance

Strategische planning (bijv. budgetten, middelen en businesscase

Dit domein stelt je in staat om potentiële informatiebeveiligingsrisico’s, dreigingen en kwetsbaarheden te analyseren en te identificeren. Daarnaast krijg je alle benodigde kennis om informatiebeveiligingsrisico’s te herkennen en te beheersen, zodat je op managementniveau kunt opereren.

A. Informatiebeveiligings-risicobeoordeling

Opkomend risico- en dreigingslandschap

Analyse van kwetsbaarheden en tekortkomingen in beheersmaatregelen

Risicobeoordeling en -analyse

B. Informatiebeveiligingsrisicorespons

Risicobehandeling / risicobeheersingsopties

Eigenaarschap van risico’s en beheersmaatregelen

Risicomonitoring en -rapportage

Dit domein behandelt de middelen, classificatie van bedrijfsmiddelen (assets) en frameworks voor informatiebeveiliging. Daarnaast leer je hoe je een informatiebeveiligingsprogramma beheert, inclusief beheersmaatregelen, testing, communicatie, rapportage en implementatie.

A. Ontwikkeling van het informatiebeveiligingsprogramma

Middelen voor het informatiebeveiligingsprogramma (bijv. mensen, tools en technologieën)

Identificatie en classificatie van informatie-assets

Branchestandaarden en frameworks voor informatiebeveiliging

Informatiebeveiligingsbeleid, -procedures en -richtlijnen

Meetindicatoren (metrics) voor het informatiebeveiligingsprogramma

B. Management van het informatiebeveiligingsprogramma

Ontwerp en selectie van informatiebeveiligingsmaatregelen

Implementatie en integratie van informatiebeveiligingsmaatregelen

Testing en evaluatie van informatiebeveiligingsmaatregelen

Bewustwording en training op het gebied van informatiebeveiliging

Beheer van externe diensten (bijv. dienstverleners, leveranciers, derde en vierde partijen)

Communicatie en rapportage binnen het informatiebeveiligingsprogramma

Dit domein biedt diepgaande training in risicomanagement en paraatheid, inclusief hoe je een organisatie voorbereidt op incidentrespons en herstel begeleidt. Het tweede onderdeel behandelt tools, evaluatie- en indammingsmethoden binnen incidentmanagement.

A. Incidentmanagementparaatheid

Incident Response Plan (IRP)

Business Impact Analysis (BIA)

Business Continuity Plan (BCP)

Disaster Recovery Plan (DRP)

Incidentclassificatie en -categorisatie

Training, testing en evaluatie van incidentmanagement

B. Incidentmanagementoperaties

Tools en technieken voor incidentmanagement

Incidentonderzoek en -evaluatie

Methoden voor incidentindamming

Communicatie bij incidentrespons (bijv. rapportage, melding en escalatie)

Incidentuitbanning en herstel

Post-incident review-praktijken

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The CISM training - Certified Information Security Manager?

  • Analyzing which internal and external factors influence the information security strategy.
  • Developing and maintaining information security policies, standards, procedures, and guidelines.
  • Establishing, communicating, and monitoring roles, responsibilities, and authorities in the field of information security.
  • Establishing and reporting relevant information security metrics to stakeholders.
  • Determining applicable laws and regulations and other compliance requirements.
  • Reporting on information security risks and non-compliance to decision-makers to support risk management.
  • Organizing and leading an incident response team, including communication with internal and external stakeholders.
  • Developing and maintaining an information security strategy that aligns with organizational objectives.
  • Developing business cases to justify investments in information security.
  • Developing, implementing, and maintaining an effective information security program in line with the strategy.
  • Integrating information security requirements into business processes and contracts with external parties, and monitoring compliance.
  • Supervising risk identification, risk assessment, and risk treatment processes within information security.
  • Developing and maintaining an incident response plan in conjunction with business continuity and disaster recovery.
  • Evaluating and improving incident management through testing, reviews, and post-incident analyses (lessons learned and root-cause analysis).
  • Setting up and securing an information security governance framework and integrating it into corporate governance.
  • Creating support and commitment from senior management and stakeholders for the information security strategy.
  • Aligning the information security program with the operational objectives of other business functions.
  • Identifying and classifying information assets within the organization.
  • Assessing whether information security measures effectively manage risks within the established risk appetite.
  • Setting up processes for the timely detection, classification, investigation, and resolution of information security incidents.

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Date: 29 juni - 2 juli 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: 14 - 17 september 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: 16 - 19 november 2026

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: In overleg

Location: TSTC Veenendaal - Klassikaal & Live Online

1

Applicant Information

2

Billing Information

Shape

Frequently Asked Questions

The CISSP and CISM are both management-oriented certifications in information security, but with a different perspective. CISSP provides a broader overview of the field of IT information security and also addresses technical topics, but always from a management point of view. As such, CISSP is also more popular among consultants or information security professionals who want to engage with various individuals and levels within the organization about information security. CISM focuses more specifically on information security management, governance, risk management, and incident management, with practical applicability for CISOs, IT Security Managers, and auditors who lead policies and programs. Technical aspects are less emphasized here, but the management domains of CISSP are explored in greater depth in CISM.

The CISM is usually not the highest responsible person for information security in an organization, but holds a role under the CISO. Since it is less important in this role to communicate at the C-level or deal with matters such as vendor management and the supply chain, these topics play virtually no role in the CISM training. If you are heavily involved in these areas, then the CCISO training may be a better alternative or continuation in a learning path.

By having a CISM on staff, organizations are better able to manage risks, implement policies effectively, and be prepared for incidents such as data breaches and ransomware. For Dutch companies, a CISM certified employee and the resulting strategic IT security policy also help to meet compliance requirements such as ISO 27001 and the GDPR.

The CISM certification is an internationally recognized standard for information security management. It confirms that you can assess risks, apply governance, and effectively respond to incidents. For IT professionals and managers in the Netherlands and worldwide, it demonstrates that you possess the knowledge to make strategic security decisions.

By taking a CISM training not online or with an international provider but at TSTC, you benefit from local context, Dutch regulations (such as GDPR, CBW/NIS2), and practical examples, combined with internationally recognized standards and knowledge.

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino