Information Systems Security Management Professional (ISSMP) Preparation Training Course
The Information Systems Security Management Professional (ISSMP) is a specialized certification under the Certified Information Systems Security Professional (CISSP) programme, provided by (ISC)². It concentrates on the management dimension of information security.
This instructor-led, live training (available online or onsite) is designed for senior security managers seeking to acquire the knowledge and competencies required to succeed in the certification exam and excel in their careers as security management professionals.
Upon completion of this training, participants will be capable of:
- Grasping the five domains of the ISSMP framework.
- Cultivating skills to oversee an information security programme.
- Acquiring the ability to establish and sustain security governance.
- Gaining insights into risk management, incident response, and business continuity planning.
- Preparing efficiently for the ISSMP certification examination.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practice sessions.
- Practical implementation within a live-lab environment.
Customization Options for the Course
- To arrange a customized training session for this course, please reach out to us to make the necessary arrangements.
Course Outline
Introduction to ISSMP and Security Leadership and Management
- Overview of ISSMP certification
- Understanding the ISSMP domains
- Leadership and management principles
- Security management frameworks and standards
- Establishing and maintaining security programmes
Security Lifecycle Management
- Information security governance
- Security programme development and management
- Policy, procedure, standards, and guidelines development
- Security metrics and reporting
Risk Management and Incident Response
- Risk management frameworks and methodologies
- Conducting risk assessments
- Incident response planning and management
- Business continuity and disaster recovery planning
Contingency Management
- Business continuity planning (BCP)
- Disaster recovery planning (DRP)
- Crisis management
- Exercises and testing of plans
Law, Ethics, and Security Compliance Management
- Legal and regulatory issues in information security
- Privacy laws and regulations
- Ethical issues in information security
- Compliance management
Strategic Planning and Financial Management
- Strategic planning for information security
- Financial management in security programmes
- Budgeting and financial reporting
- Cost-benefit analysis for security investments
Exam Preparation and Practice
- Review of all ISSMP domains
- Exam preparation strategies
- Practice exams and question reviews
- Time management for exam day
Final Review and Exam Readiness
- Final review of key concepts
- Individual study plans
- Mock exams and feedback
- Final Q&A session
Summary and Next Steps
Requirements
- Certified Information Systems Security Professional (CISSP) certification
- Familiarity with information security concepts, practices, and methodologies
Target Audience
- Security managers
- Information security officers
- IT managers
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
Information Systems Security Management Professional (ISSMP) Preparation Training Course - Enquiry
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
The way to receive the information from the trainer
Mohamed Romdhani - Shams Power
Course - CISM - Certified Information Security Manager
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in Kenya (online or onsite) is designed for intermediate-level IT auditors seeking to effectively incorporate AI tools into their audit practices.
By the end of this training, participants will be able to:
- Grasp the core concepts of artificial intelligence and its application in IT auditing.
- Utilize AI technologies such as machine learning, NLP, and RPA to improve audit efficiency, accuracy, and scope.
- Perform risk assessments using AI tools, enabling continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, enhancing the overall effectiveness of IT audits.
Micro Focus ArcSight ESM Advanced
35 HoursThis instructor-led, live training in Kenya (online or onsite) is aimed at advanced-level security analysts who wish to elevate their skills in utilizing advanced Micro Focus ArcSight ESM content to improve an organization's ability to detect, respond, and mitigate cyber threats with greater precision and speed.
By the end of this training, participants will be able to:
- Optimize the use of Micro Focus ArcSight ESM to enhance monitoring and threat detection capabilities.
- Construct and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules for effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
BCS Practitioner Certificate in Information Risk Management (CIRM)
35 HoursWho is it for:
Any professional engaged in the fields of information security and information assurance.
What will I learn:
Candidates will be expected to demonstrate:
- The significant business advantages derived from effective information risk management.
- The ability to articulate and fully utilize the terminology associated with information risk management.
- The methods for conducting threat and vulnerability assessments, business impact analyses, and risk assessments.
- The core principles governing controls and risk treatment.
- Techniques for presenting findings in a format suitable for developing a risk treatment plan.
- The application of information classification schemes.
CISM - Certified Information Security Manager
28 HoursDescription:
Important Notice: Please note that this updated CISM exam content outline applies to examinations commencing from 1 June 2022.
CISM® stands as the most prestigious and rigorous qualification for Information Security Managers worldwide. This credential offers you a pathway to join an exclusive peer network, empowering you to continuously learn and adapt to the evolving opportunities and challenges within Information Security Management.
Our CISM training approach delivers comprehensive coverage across the four CISM domains, with a clear emphasis on building foundational concepts and practicing with CISM questions released by ISACA. This course serves as intensive training and rigorous exam preparation for the ISACA Certified Information Security Manager (CISM®) Examination.
Our instructors advise all participants to review the ISACA-released CISM QA&E (Questions, Answers, and Explanations) as part of their exam preparation. The QA&E is particularly effective in helping participants understand the style of ISACA questions, the approach to solving them, and facilitates rapid memorization of CISM concepts during live classroom sessions.
All our trainers possess extensive experience in delivering CISM training. We are committed to thoroughly preparing you for the CISM examination.
Goal:
The primary objective is to help you pass your CISM examination on the first attempt.
Objectives:
- Apply the knowledge gained in a practical manner that benefits your organization.
- Establish and maintain an information security governance framework to achieve your organization's goals and objectives.
- Manage information risk to an acceptable level to meet business and compliance requirements.
- Establish and maintain information security architectures encompassing people, processes, and technology.
- Integrate information security requirements into the contracts and activities of third parties and suppliers.
- Plan, establish, and manage the capability to detect, investigate, respond to, and recover from information security incidents to minimize business impact.
Target Audience:
- Security professionals with 3-5 years of front-line experience.
- Information security managers or individuals with management responsibilities.
- Information security staff and assurance providers who require a deep understanding of information security management, including: CISOs, CIOs, CSOs, privacy officers, risk managers, security auditors, compliance personnel, BCP/DR personnel, and executive and operational managers responsible for assurance functions.
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led live training in Kenya (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Cybersecurity Fundamentals
28 HoursOverview:
There is a soaring demand for cybersecurity expertise, as digital threats continue to challenge enterprises globally. A vast majority of professionals surveyed by ISACA acknowledge this trend and intend to pursue roles that require cybersecurity proficiency.
To bridge this skills gap, ISACA has introduced the Cybersecurity Fundamentals Certificate, offering both education and validation of skills in this critical field.
Goals:
With cybersecurity threats on the rise and a global shortage of qualified security professionals, ISACA's Cybersecurity Fundamentals Certificate programme offers an efficient pathway to equip entry-level staff with the essential skills and knowledge required to thrive in the cybersecurity domain.
Intended Participants:
This certificate programme is also among the most effective ways to acquire foundational cybersecurity knowledge and start building your competencies in this vital area.
Data Sovereignty Fundamentals for Enterprise Leaders
14 HoursThis live, instructor-led training (available online or on-site) is designed for enterprise leaders who aim to understand data sovereignty principles and develop strategies for compliant data management.
By the conclusion of this session, participants will be capable of defining data sovereignty, identifying pertinent legislation, evaluating compliance risks, and implementing governance frameworks for international data management.
DevOps Security: Creating a DevOps Security Strategy
7 HoursIn this instructor-led, live course in Kenya, participants will learn how to formulate an effective security strategy to address the challenges posed by DevOps security.
Encryption Key Management
21 HoursEncryption Key Management involves the secure creation, storage, distribution, rotation, and retirement of cryptographic keys to safeguard sensitive information and ensure adherence to regulatory standards.
This instructor-led, live training (available online or onsite) is designed for intermediate-level IT and security professionals seeking to implement robust encryption key management practices and systems within enterprise environments.
By the conclusion of this training, participants will be capable of:
- Gaining insight into the lifecycle of encryption keys and best practices for their protection.
- Setting up and managing key management systems (KMS) in both on-premises and cloud environments.
- Implementing access control and auditing measures for key usage.
- Ensuring compliance with regulations and standards concerning encryption key security.
Course Format
- Interactive lectures and discussions.
- Hands-on experience with key management tools in lab environments.
- Guided exercises focused on implementing secure key lifecycle processes.
Course Customization Options
- To request customized training tailored to your infrastructure or compliance needs, please contact us to arrange.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers an expert introduction to the newly enacted Accessibility Law, empowering developers with the practical skills needed to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's importance and implications, the course rapidly transitions into hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
PECB ISO/IEC 27001 Foundation
14 HoursWhy should you attend?
The PECB ISO/IEC 27001 Foundation training equips you with the fundamental knowledge required to implement and manage an Information Security Management System (ISMS) in accordance with ISO/IEC 27001. Throughout this course, you will gain a comprehensive understanding of ISMS components, such as policy formulation, procedural guidelines, performance metrics, executive commitment, internal auditing, management reviews, and strategies for continuous improvement.
Upon successful completion of this course, you will be eligible to sit for the examination and apply for the “PECB Certified ISO/IEC 27001 Foundation” credential. This certificate validates your grasp of the core methodologies, requirements, framework, and management approaches associated with information security.
Who should attend?
- Professionals currently engaged in Information Security Management.
- Individuals aiming to acquire knowledge regarding the primary processes of Information Security Management Systems (ISMS).
- Those aspiring to build a career in Information Security Management.
Educational approach
- Lectures are enriched with practical questions and real-world examples.
- Practical exercises incorporate case studies and interactive discussions.
- Practice tests mirror the format and rigour of the official Certification Exam.
PECB ISO/IEC 27001 Lead Implementer
35 HoursInformation security threats and attacks increase and improve constantly. The best form of defense against them is the proper implementation and management of information security controls and best practices. Information security is also a key expectation and requirement of customers, legislators, and other interested parties.
This training course is designed to prepare participants in implementing an information security management system (ISMS) based on ISO/IEC 27001. It aims to provide a comprehensive understanding of the best practices of an ISMS and a framework for its continual management and improvement.
After attending the training course, you can take the exam. If you successfully pass it, you can apply for a “PECB Certified ISO/IEC 27001 Lead Implementer” credential, which demonstrates your ability and practical knowledge to implement an ISMS based on the requirements of ISO/IEC 27001.
Who Can Attend?
- Project managers and consultants involved in and concerned with the implementation of an ISMS
- Expert advisors seeking to master the implementation of an ISMS
- Individuals responsible for ensuring conformity to information security requirements within an organization
- Members of an ISMS implementation team
General information
- Certification fees are included in the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months free of charge
Educational approach
- This training course contains essay-type exercises, multiple-choice quizzes, examples, and best practices used in the implementation of an ISMS.
- The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
- The exercises are based on a case study.
- The structure of the quizzes is similar to that of the certification exam.
Learning objectives
This training course will help you:
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of an ISMS
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks
- Understand the operation of an information security management system and its processes based on ISO/IEC 27001
- Learn how to interpret and implement the requirements of ISO/IEC 27001 in the specific context of an organization
- Acquire the necessary knowledge to support an organization in effectively planning, implementing, managing, monitoring, and maintaining an ISMS
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This course is designed for all staff members who need a practical grasp of Compliance and effective Risk Management.
Course Structure
The training utilizes a blended learning methodology that incorporates:
- Guided discussions
- Slide presentations
- Case studies
- Real-world examples
Learning Objectives
Upon completion of the course, participants will be equipped to:
Gain a robust understanding of Compliance fundamentals, alongside national and global initiatives focused on managing related risks.
Articulate how organizations and their teams can implement an effective Compliance Risk Management Framework.
Outline the duties of the Compliance Officer and the Money Laundering Reporting Officer, and comprehend how these roles fit into the broader business structure.
Pinpoint critical risk areas within Financial Crime, specifically regarding international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management involves the oversight of the lifecycle of open-source components within an organization, ensuring their secure, compliant, and efficient utilization.
This instructor-led, live training (available online or onsite) is designed for intermediate-level IT professionals aiming to implement best practices for managing open-source software in enterprise and government settings.
\rUpon completion of this training, participants will be able to:
- Implement effective OSS policies and governance frameworks.
- Utilize SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigate risks related to licensing and security vulnerabilities.
- Streamline OSS adoption to maximize innovation and cost savings.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations using OSS management tools.
Customization Options
- This course can be tailored to specific organizational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Kenya (online or onsite) offers a professional qualification for industry practitioners aiming to showcase their expertise and deep understanding of the PCI Data Security Standard (PCI DSS).
Upon completing this training, participants will be able to:
- Grasp the payment process and the PCI standards established to safeguard it.
- Comprehend the roles and responsibilities of entities within the payment industry.
- Gain profound insight into and understanding of the 12 PCI DSS requirements.
- Demonstrate knowledge of PCI DSS and its application to organizations involved in the transaction process.