Information Systems Security Management Professional (ISSMP) Preparation Training Course
The Information Systems Security Management Professional (ISSMP) is a specialised certification within the Certified Information Systems Security Professional (CISSP) programme offered by (ISC)², concentrating on the managerial dimensions of information security.
This instructor-led, live training session (available online or on-site) is designed for senior security managers who aspire to acquire the knowledge and competencies required to succeed in the examination and excel in their professional roles as security management experts.
Upon completion of this training, participants will be capable of:
- Gaining a comprehensive understanding of the five ISSMP domains.
- Acquiring the skills necessary to manage an information security programme.
- Learning how to establish and sustain security governance.
- Gaining insights into risk management, incident response, and continuity planning.
- Preparing effectively for the ISSMP certification examination.
Course Format
- Interactive lectures and discussions.
- Extensive exercises and practical application.
- Hands-on implementation within a live-lab environment.
Customisation Options
- To request a tailored training session for this course, please contact us to make arrangements.
Course Outline
Introduction to ISSMP and Security Leadership and Management
- Overview of ISSMP certification
- Understanding the ISSMP domains
- Leadership and management principles
- Security management frameworks and standards
- Establishing and maintaining security programs
Security Lifecycle Management
- Information security governance
- Security program development and management
- Policy, procedure, standards, and guidelines development
- Security metrics and reporting
Risk Management and Incident Response
- Risk management frameworks and methodologies
- Conducting risk assessments
- Incident response planning and management
- Business continuity and disaster recovery planning
Contingency Management
- Business continuity planning (BCP)
- Disaster recovery planning (DRP)
- Crisis management
- Exercises and testing of plans
Law, Ethics, and Security Compliance Management
- Legal and regulatory issues in information security
- Privacy laws and regulations
- Ethical issues in information security
- Compliance management
Strategic Planning and Financial Management
- Strategic planning for information security
- Financial management in security programs
- Budgeting and financial reporting
- Cost-benefit analysis for security investments
Exam Preparation and Practice
- Review of all ISSMP domains
- Exam preparation strategies
- Practice exams and question reviews
- Time management for exam day
Final Review and Exam Readiness
- Final review of key concepts
- Individual study plans
- Mock exams and feedback
- Final Q&A session
Summary and Next Steps
Requirements
- Certified Information Systems Security Professional (CISSP) certification
- Familiarity with information security concepts, practices, and methodologies
Target Audience
- Security managers
- Information security officers
- IT managers
Need help picking the right course?
southafrica@nobleprog.co.za or +27 (0)10 005 5793
Information Systems Security Management Professional (ISSMP) Preparation Training Course - Enquiry
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
The way to receive the information from the trainer
Mohamed Romdhani - Shams Power
Course - CISM - Certified Information Security Manager
Related Courses
AI and IT Audit
14 HoursThis instructor-led, live training in Botswana (online or onsite) is designed for intermediate-level IT auditors who wish to effectively incorporate AI tools into their audit practices.
By the end of this training, participants will be able to:
- Understand the core concepts of artificial intelligence and its application within IT auditing.
- Leverage AI technologies such as machine learning, NLP, and RPA to enhance audit efficiency, accuracy, and scope.
- Conduct risk assessments using AI tools, facilitating continuous monitoring and proactive risk management.
- Integrate AI into audit planning, execution, and reporting, thereby improving the overall effectiveness of IT audits.
Micro Focus ArcSight ESM Advanced
35 HoursThis instructor-led, live training in Botswana (online or onsite) is aimed at advanced-level security analysts who wish to elevate their skills in utilising advanced Micro Focus ArcSight ESM content to improve an organisation's ability to detect, respond to, and mitigate cyber threats with greater precision and speed.
By the end of this training, participants will be able to:
- Optimise the use of Micro Focus ArcSight ESM to enhance monitoring and threat detection capabilities.
- Construct and manage advanced ArcSight variables to refine event streams for more precise analysis.
- Develop and implement ArcSight lists and rules for effective event correlation and alerting.
- Apply advanced correlation techniques to identify complex threat patterns and reduce false positives.
BCS Practitioner Certificate in Information Risk Management (CIRM)
35 HoursWho is it for:
Intended for professionals engaged in the fields of information security and information assurance.
What will I learn:
Participants will demonstrate the ability to:
- Explain how effective information risk management delivers substantial business advantages.
- Articulate and utilise information risk management terminology accurately.
- Perform threat and vulnerability assessments, business impact analyses, and risk assessments.
- Understand the principles governing controls and risk treatment.
- Present findings in a format that serves as the foundation for a risk treatment plan.
- Apply information classification schemes effectively.
CISM - Certified Information Security Manager
28 HoursDescription:
Disclaimer: Please note that this updated CISM exam content outline applies to exams commencing on 1 June 2022.
CISM® is the most prestigious and rigorous qualification for Information Security Managers globally. This credential provides you with the opportunity to join an elite peer network capable of continuously learning and relearning about the expanding opportunities and challenges in Information Security Management.
Our CISM training methodology covers the content across the four CISM domains in depth, with a clear focus on building concepts and solving ISACA-released CISM exam questions. The course is an intensive training and rigorous exam preparation for ISACA’s Certified Information Security Manager (CISM®) Examination.
Our instructors encourage all attending delegates to review the ISACA-released CISM QA&E (Questions, Answers and Explanations) as part of their exam preparation. The QA&E is exceptional in helping delegates understand the ISACA style of questions, the approach to solving them, and facilitates rapid memory assimilation of CISM concepts during live classroom sessions.
All our trainers have extensive experience in delivering CISM training. We will thoroughly prepare you for the CISM examination.
Goal:
The ultimate goal is to pass your CISM examination on the first attempt.
Objectives:
- Apply the knowledge gained in a practical manner that benefits your organisation
- Establish and maintain an Information Security Governance framework to achieve your organisation's goals and objectives
- Manage Information risk to an acceptable level to meet business and compliance requirements
- Establish and maintain information security architectures (people, process, technology)
- Integrate information security requirements into the contracts and activities of third parties/suppliers
- Plan, establish and manage the capability to detect, investigate, respond to and recover from information security incidents to minimise business impact
Target Audience:
- Security professionals with 3-5 years of frontline experience
- Information security managers or those with management responsibilities
- Information security staff, information security assurance providers who require an in-depth understanding of information security management, including: CISOs, CIOs, CSOs, privacy officers, risk managers, security auditors, and compliance personnel, BCP/DR personnel, executive and operational managers responsible for assurance functions
Cybersecurity Governance, Risk & Compliance (GRC)
14 HoursThis instructor-led, live training in Botswana (online or onsite) is aimed at intermediate-level cybersecurity professionals who wish to enhance their understanding of GRC frameworks and apply them to secure and compliant business operations.
By the end of this training, participants will be able to:
- Understand the key components of cybersecurity governance, risk, and compliance.
- Conduct risk assessments and develop risk mitigation strategies.
- Implement compliance measures and manage regulatory requirements.
- Develop and enforce security policies and procedures.
Cybersecurity Fundamentals
28 HoursDescription:
There is a surging demand for cybersecurity expertise, as evolving threats continue to challenge enterprises globally. An overwhelming majority of professionals surveyed by ISACA acknowledge this reality and intend to pursue roles requiring cybersecurity proficiency.
To bridge this skills gap, ISACA has introduced the Cybersecurity Fundamentals Certificate, designed to educate and verify competence in this critical field.
Objectives:
Amidst rising cybersecurity threats and a growing global shortage of skilled security professionals, ISACA's Cybersecurity Fundamentals Certificate programme offers an effective means to rapidly equip entry-level staff with the essential skills and knowledge required to operate successfully within the cybersecurity landscape.
Target Audience:
This certificate programme serves as an ideal avenue for acquiring foundational cybersecurity knowledge and beginning to develop expertise in this vital domain.
Data Sovereignty Fundamentals for Enterprise Leaders
14 HoursThis instructor-led, live training (available online or onsite) is designed for enterprise leaders who wish to understand data sovereignty principles and develop compliant data management strategies.
By the end of this training, participants will be able to define data sovereignty, identify relevant laws, assess compliance risks, and implement governance frameworks for cross-border data management.
DevOps Security: Creating a DevOps Security Strategy
7 HoursIn this instructor-led, live course in Botswana, participants will learn how to formulate an appropriate security strategy to address the DevOps security challenge.
Encryption Key Management
21 HoursManaging Encryption Keys is the discipline of securely creating, storing, distributing, rotating, and retiring cryptographic keys to protect sensitive data and ensure regulatory compliance.
This instructor-led, live training (online or onsite) is aimed at intermediate-level IT and security professionals who wish to implement robust encryption key management practices and systems across enterprise environments.
By the end of this training, participants will be able to:
- Understand the lifecycle of encryption keys and best practices for their protection.
- Set up and manage key management systems (KMS) both on-prem and in the cloud.
- Implement access control and auditing for key usage.
- Comply with regulations and standards related to encryption key security.
Format of the Course
- Interactive lecture and discussion.
- Hands-on use of key management tools in lab environments.
- Guided exercises focused on secure key lifecycle implementation.
Course Customization Options
- To request a customized training for this course based on your infrastructure or compliance requirements, please contact us to arrange.
Accessibility by Design (Compliance with EU ACT)
21 HoursThis course offers an expert introduction to the newly enacted Accessibility Law, equipping developers with the practical skills necessary to design, develop, and maintain fully accessible applications. Beginning with a contextual discussion on the law's importance and implications, the course quickly transitions to hands-on coding practices, tools, and testing techniques to ensure compliance and inclusivity for users with disabilities.
PECB ISO/IEC 27001 Foundation
14 HoursWhy should you attend?
The ISO/IEC 27001 Foundation training equips you with the essential knowledge to implement and manage an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001 standard. Throughout this course, you will gain a comprehensive understanding of the various ISMS components, such as ISMS policies, procedures, performance metrics, management commitment, internal audits, management reviews, and continual improvement processes.
Upon completing this course, you will be eligible to sit for the examination and apply for the “PECB Certified ISO/IEC 27001 Foundation” certification. Earning a PECB Foundation Certificate demonstrates that you have grasped the fundamental methodologies, requirements, framework, and management approaches associated with the standard.
Who should attend?
- Professionals involved in Information Security Management
- Individuals wishing to acquire knowledge about the core processes of Information Security Management Systems (ISMS)
- Those interested in pursuing a career in Information Security Management
Educational approach
- Lecture sessions are reinforced with practical questions and examples
- Practical exercises incorporate examples and group discussions
- Practice tests mirror the format of the actual Certification Exam
PECB ISO/IEC 27001 Lead Implementer
35 HoursInformation security threats and attacks increase and improve constantly. The best form of defense against them is the proper implementation and management of information security controls and best practices. Information security is also a key expectation and requirement of customers, legislators, and other interested parties.
This training course is designed to prepare participants in implementing an information security management system (ISMS) based on ISO/IEC 27001. It aims to provide a comprehensive understanding of the best practices of an ISMS and a framework for its continual management and improvement.
After attending the training course, you can take the exam. If you successfully pass it, you can apply for a “PECB Certified ISO/IEC 27001 Lead Implementer” credential, which demonstrates your ability and practical knowledge to implement an ISMS based on the requirements of ISO/IEC 27001.
Who Can Attend?
- Project managers and consultants involved in and concerned with the implementation of an ISMS
- Expert advisors seeking to master the implementation of an ISMS
- Individuals responsible for ensuring conformity to information security requirements within an organization
- Members of an ISMS implementation team
General information
- Certification fees are included in the exam price
- Training material containing over 450 pages of information and practical examples will be distributed
- A participation certificate of 31 CPD (Continuing Professional Development) credits will be issued
- In case of exam failure, you can retake the exam within 12 months free of charge
Educational approach
- This training course contains essay-type exercises, multiple-choice quizzes, examples, and best practices used in the implementation of an ISMS.
- The participants are encouraged to communicate with each other and engage in discussions when completing quizzes and exercises.
- The exercises are based on a case study.
- The structure of the quizzes is similar to that of the certification exam.
Learning objectives
This training course will help you:
- Gain a comprehensive understanding of the concepts, approaches, methods, and techniques used for the implementation and effective management of an ISMS
- Acknowledge the correlation between ISO/IEC 27001, ISO/IEC 27002, and other standards and regulatory frameworks
- Understand the operation of an information security management system and its processes based on ISO/IEC 27001
- Learn how to interpret and implement the requirements of ISO/IEC 27001 in the specific context of an organization
- Acquire the necessary knowledge to support an organization in effectively planning, implementing, managing, monitoring, and maintaining an ISMS
Compliance and the Management of Compliance Risk
21 HoursTarget Audience
This programme is designed for all staff members who need a practical grasp of Compliance and effective Risk Management.
Training Format
The training employs a blended learning strategy that comprises:
- Guided group discussions
- Presentations supported by slides
- Analysis of case studies
- Practical real-world examples
Course Objectives
Upon completion of this course, participants will be capable of:
Gaining a comprehensive understanding of the core elements of Compliance, as well as national and global initiatives focused on managing related risks.
Articulating how organisations and their teams can build an effective Compliance Risk Management Framework.
Outlining the duties of the Compliance Officer and the Money Laundering Reporting Officer, and understanding how these roles fit into the broader business structure.
Pinpointing key risk areas within Financial Crime, especially concerning international operations, offshore centres, and high-net-worth clients.
Open Source Software (OSS) Management
14 HoursOpen Source Software (OSS) Management entails the oversight of the lifecycle for open-source components within an organization, ensuring their secure, compliant, and efficient utilisation.
This instructor-led, live training (available online or onsite) is designed for intermediate-level IT professionals seeking to implement best practices for managing open-source software in enterprise and government settings.
Upon completion of this training, participants will be capable of:
- Establishing effective OSS policies and governance frameworks.
- Utilising SBOM and SCA tools to identify, track, and manage open-source dependencies.
- Mitigating risks associated with licensing and security vulnerabilities.
- Streamlining OSS adoption while maximising innovation and cost savings.
Course Format
- Interactive lectures and discussions.
- Case studies and scenario-based exercises.
- Hands-on demonstrations using OSS management tools.
Customisation Options
- This course can be tailored to align with specific organisational OSS policies and toolchains. Please contact us to arrange.
PCI-DSS Practitioner
14 HoursThis instructor-led, live Payment Card Industry Professional training in Botswana (online or onsite) offers a personal qualification for industry practitioners aiming to showcase their professional expertise and grasp of the PCI Data Security Standard (PCI DSS).
Upon completion of this training, participants will be capable of:
- Grasping the payment process and the PCI standards established to safeguard it.
- Understanding the roles and responsibilities of entities within the payment industry.
- Gaining profound insight into and understanding the 12 PCI DSS requirements.
- Showing knowledge of PCI DSS and its application to organisations involved in the transaction process.