Skip to main content
CYB-0332ExpertCurrent Intake
XCISM

Xcademia Information Security Management Practitioner

5-Day Instructor-Led Programme

The XCISM Certification Programme is the practitioner alternative to CISM, covering all four information security management domains: information security governance, information security risk management, information security programme development, and incident management. Assessed on Day 5 through a supervised security governance and programme design scenario. No 150-question MCQ exam. No CPE renewal requirements.

Duration

5 Days

Price

$5,617

Xcademia Information Security Management Practitioner
Duration
5 Days
Complete in 5 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

CISM is the leading information security management certification globally with over 107,000 holders. It is a 150 multiple choice exam across four domains covering the governance and management of enterprise information security. The exam rewards knowledge of ISACA terminology and CISM-specific definitions, not demonstrated management capability. XCISM is built for security managers and programme leads who want to apply security governance, risk management, and programme design skills in real scenarios.

Across five instructor-led days, XCISM covers all four CISM job practice domains at current weighting: Information Security Governance (Domain 1, 17%), Information Security Risk Management (Domain 2, 20%), Information Security Programme (Domain 3, 33%, the highest-weighted domain), and Incident Management (Domain 4, 30%). Coverage reflects the current ISACA CISM outline. Note: ISACA has announced a CISM exam content update effective November 2026. XCISM content will be updated to reflect this when the updated outline is published.

On Day 5, participants navigate a security governance and programme development scenario for a simulated organisation facing new regulatory obligations. A senior practitioner with security management experience assesses governance decisions, risk methodology, and programme design. XCISM certificate and Practitioner Assessment Report issued. Aligned with ISACA CISM four domains, ISO 27001:2022 Clause 5 and 6, NIST CSF 2.0 Govern function, COBIT 2019, ISO 31000, NIS2 Article 20, and DORA Article 5.

Hands-On Learning

Applied exercises across all four CISM domains: security strategy development, risk register design, security programme roadmap construction, incident management scenario, and regulatory compliance gap assessment.

Mentor-Led Sessions

Mentor-led sessions from experienced information security managers examining real governance decisions, risk acceptance challenges, programme investment justification, and board communication of security management outcomes.

Career-Ready Skills

Govern enterprise information security programmes across all four CISM domains, evidenced by a professional governance scenario assessment that demonstrates management capability rather than MCQ recall.

Learning Outcomes

Design and govern enterprise information security programmes aligned to all four CISM job practice domains, ISO 27001:2022, and NIST CSF 2.0 Govern function

Develop security governance frameworks including policy architecture, board reporting structures, and regulatory compliance governance for NIS2 and DORA obligations

Apply qualitative and FAIR quantitative risk management methodology to enterprise risk registers and third-party risk governance programmes

Lead information security programme design from capability maturity baseline through roadmap construction, investment governance, and KPI measurement

Govern incident management programmes including regulatory notification decision-making, response governance, and business continuity integration

Communicate information security programme performance to board-level audiences using risk language, maturity metrics, and regulatory compliance evidence

Prerequisites

1

Minimum 5 years of information security management experience with at least 3 years in a security management or programme leadership role

2

Working knowledge of at least two major security frameworks: ISO 27001, NIST CSF, COBIT, or equivalent governance frameworks

3

Experience with security risk management or security programme management at organisational level

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • Security governance positioning: CISO reporting structure, governance committee design, and board accountability
  • ISO 27001:2022 Clause 5 leadership requirements: commitment, policy, roles, responsibilities, and management review
  • NIST CSF 2.0 Govern function: organisational context, risk management strategy, roles, and oversight applied
  • COBIT 2019 governance vs management distinction and how security managers span both effectively
  • Security governance metrics and balanced scorecard: connecting programme activity to business outcome reporting
Stage 5Final Capstone

Xcademia Information Security Management Practitioner — Capstone Project

On Day 5, participants navigate a security governance and programme development scenario for a simulated financial services organisation facing NIS2 obligations, a supplier compromise, and a board request for a security programme review. They must produce a governance framework update, a risk register with residual risk assessment, a programme roadmap with investment justification, and an incident management policy update. The senior practitioner assesses the quality of governance decisions, risk methodology, and programme design throughout.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • ISACA CISM (4 domains)

    Global

    All four CISM job practice domains at current weighting: D1 17%, D2 20%, D3 33%, D4 30%

  • ISO 27001:2022

    Global

    Clause 5 leadership, Clause 6 planning, Clause 9 performance evaluation: primary governance reference

  • NIST CSF 2.0 Govern

    Global

    Organisational context, risk management strategy, roles and responsibilities, policies and oversight throughout

  • COBIT 2019

    Global

    Governance and management objectives mapped to CISM domains for governance framework design

  • ISO 31000

    Global

    Risk management principles and framework: applied throughout the risk management domain

  • NIS2 Article 20

    Global

    Senior management accountability and mandatory security training obligations for essential entities

  • DORA Article 5 and 6

    Global

    Management body ICT risk governance obligations for EU financial entities throughout

  • ISO 27005

    Global

    Information security risk management: detailed risk assessment methodology aligned to ISO 27001

Skills You'll Gain

Master these in-demand skills through hands-on practice

CISM all 4 domainsISO 27001:2022 leadership clausesNIST CSF 2.0 Govern functionSecurity strategy and policy designFAIR quantitative risk methodologyThird-party risk governanceSecurity programme KPIs and OKRsIncident management governanceNIS2 Article 20 and DORA Article 5Board-level security communicationSecurity culture programme designContinuous improvement for security

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

Information Security ManagerCISO / Deputy CISOHead of Information SecurityIT Risk ManagerSecurity Programme LeadGRC Manager
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

5 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$5,617+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Xcademia Information Security Management Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of Xcademia Information Security Management Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

CISM is a 150 multiple choice exam across 4 domains. Beyond the $760 exam, CISM holders pay annual membership fees and 120 CPE credits every 3 years. XCISM is 5 instructor-led days covering all 4 CISM domains assessed through a real governance and programme design scenario on Day 5. One price. No annual fees. The Practitioner Assessment Report documents applied governance capability.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options