
CompTIA
Cisco
ISACA & governance
Offense & defense
Current outline · through 2 Nov 2026·Cybersecurity Management
ISACA CISM
Prepare for the ISACA CISM exam across information security governance, risk management, program management, and incident management.
Choose a preferred plan, then confirm availability with our team.

RSAY completion certificate
Recognize your training achievement
Online or in-person
Explore delivery options below
Management / professional
Review prerequisites before choosing
4 learning modules
Topics, practice, and learning checks
BUILD SKILLS THAT MATTER
From understanding to application.
A focused learning experience that connects the concepts to decisions you make in real technical work.
Is this the right course for me? ↗What you will be able to do
- Establish security governance aligned with enterprise objectives and stakeholder needs.
- Assess, treat, monitor, and communicate information security risk.
- Develop, resource, implement, measure, and improve an information security program.
- Prepare for, detect, contain, communicate, recover from, and learn from incidents.
Who this course is for
Security managers · Security program leaders · Risk and governance professionals · Professionals pursuing CISM
INSIDE THE COURSE
Explore the syllabus.
Open a module to see its focus, a suggested practical activity, and how you will check your understanding. Exam percentages are not allocations of training hours.
Official certification reference ↗Activities are RSAY learning examples, not a promise of vendor-owned lab access. Final materials are confirmed in the cohort guide.
01Information Security Governance · 17%
Topics in focus
Enterprise governance, legal requirements, organizational structures, strategy, frameworks, and planning.
Put it into practice
Translate a business objective into a security governance responsibility and measurable outcome.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
02Information Security Risk Management · 20%
Topics in focus
Threat landscape, vulnerabilities, assessments, treatment, ownership, monitoring, and reporting.
Put it into practice
Prepare a risk treatment recommendation with business impact, ownership, and acceptance criteria.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
03Information Security Program · 33%
Topics in focus
Resources, assets, standards, policies, metrics, controls, testing, awareness, third parties, and reporting.
Put it into practice
Prioritize a security-program roadmap and choose metrics that inform management decisions.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
04Incident Management · 30%
Topics in focus
Readiness, BIA, continuity, recovery, classification, investigation, containment, communications, and review.
Put it into practice
Run a tabletop incident scenario and draft stakeholder communications and lessons learned.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
RECOGNIZE YOUR PROGRESS
Your learning. Your achievement.
Receive an RSAY ITC completion certificate when you meet the attendance, activities, and assessment requirements published in your cohort guide.
Completion is not vendor certification
The RSAY certificate records training completion. Vendor certification requires its own exam and applicable eligibility criteria. An exam voucher is not included unless explicitly confirmed in your package.
CERTIFICATION EXAM
Know your next milestone.
- Certification / version
- Current outline · through 2 Nov 2026
- Exam duration
- 240 minutes
- Assessment
- 150 questions
ISACA states that a new CISM exam content outline takes effect on 3 November 2026. RSAY will update future cohorts accordingly.
Exam policies can change. Verify current requirements with the certification provider before booking. Training does not guarantee a pass.
Review official requirements ↗MAKE ROOM FOR YOUR NEXT SKILL
Course schedule & pricing
An intensive week, evening sessions, or weekends. Explore a learning rhythm that fits your life.
Example schedules · not open cohorts
Compare three 40-hour plans. Dates, delivery, breaks, venue, and final price must be confirmed by RSAY. Choosing a plan does not book or charge you.
All times: Riyadh · UTC+3
Five-day intensive
Sunday–Thursday · 09:00–17:00
Online or in-person · venue to be confirmed5 × 8 hours = 40 hours
View every session
- 4 Oct 2026 09:00–17:00
- 5 Oct 2026 09:00–17:00
- 6 Oct 2026 09:00–17:00
- 7 Oct 2026 09:00–17:00
- 8 Oct 2026 09:00–17:00
Weekday evenings
Sunday–Wednesday · 18:00–20:00
Online or in-person · venue to be confirmed20 × 2 hours = 40 hours
View every session
- 4 Oct 2026 18:00–20:00
- 5 Oct 2026 18:00–20:00
- 6 Oct 2026 18:00–20:00
- 7 Oct 2026 18:00–20:00
- 11 Oct 2026 18:00–20:00
- 12 Oct 2026 18:00–20:00
- 13 Oct 2026 18:00–20:00
- 14 Oct 2026 18:00–20:00
- 18 Oct 2026 18:00–20:00
- 19 Oct 2026 18:00–20:00
- 20 Oct 2026 18:00–20:00
- 21 Oct 2026 18:00–20:00
- 25 Oct 2026 18:00–20:00
- 26 Oct 2026 18:00–20:00
- 27 Oct 2026 18:00–20:00
- 28 Oct 2026 18:00–20:00
- 1 Nov 2026 18:00–20:00
- 2 Nov 2026 18:00–20:00
- 3 Nov 2026 18:00–20:00
- 4 Nov 2026 18:00–20:00
Five weekends
Friday–Saturday · 09:00–13:00
Online or in-person · venue to be confirmed10 × 4 hours = 40 hours
View every session
- 9 Oct 2026 09:00–13:00
- 10 Oct 2026 09:00–13:00
- 16 Oct 2026 09:00–13:00
- 17 Oct 2026 09:00–13:00
- 23 Oct 2026 09:00–13:00
- 24 Oct 2026 09:00–13:00
- 30 Oct 2026 09:00–13:00
- 31 Oct 2026 09:00–13:00
- 6 Nov 2026 09:00–13:00
- 7 Nov 2026 09:00–13:00
Prerequisites
Review the management / professional level and intended audience. Relevant networking and operating-system knowledge helps with technical security courses; our team can assess your starting point.
Technical requirements
A computer, current browser, reliable internet, and clear audio. Software, virtual-machine requirements, and lab access are specified before registration is confirmed.
Learning schedule
The cohort guide confirms dates, breaks, live hours, self-study, activities, and assessments. Example plans on this page are illustrative until confirmed.
Measuring progress
Knowledge checks, practical activities, feedback, and a final review connect to learning outcomes. Completion criteria and assessment weights are published in the cohort guide.
Support & accessibility
Tell us about learning support or accessibility needs before enrollment. Our team can clarify attendance, complaints, privacy, and refund policies.