Get in Touch

Course Outline

The syllabus includes training objectives, details of modules, and a recommended reading list:

The latest syllabus

1. Information Security Management Principles

  • Identify definitions, meanings, and usage of concepts and terms across information security management.
  • Explain the necessity for, and the benefits of, information security.

2. Information Risk

  • Outline the threats to and vulnerabilities of information systems.
  • Describe the processes for understanding and managing risk related to information systems at strategic, tactical, and operational levels.

3. Information Security Framework

  • Explain how risk management should be implemented within an organisation:
    • Management of information security within the organisation
    • Organisational policy, standards, and procedures
    • Information security governance
    • Information security implementation
    • Security incident management
  • Interpret general principles of law, legal jurisdiction, and associated topics as they affect information security management.
  • Identify common, established standards and procedures that directly influence information security management.

4. Security Lifecycle

  • Understand the importance and relevance of the information lifecycle.
  • Recognise the stages of the information lifecycle.
  • Comprehend the design process lifecycle, including essential and non-functional requirements (architecture frameworks, Agile development, service continuity, and reliability).
  • Appreciate the importance of appropriate technical audit and review processes, effective change control, and configuration management.
  • Identify the risks to security arising from systems development and support.

5. Procedural/People Security Controls

  • Assess risks to information security involving people (organisational culture of security).
  • Identify user access controls that may be used to manage these risks.

6. Technical Security Controls

  • Identify technical controls that help ensure protection from Malicious Software.
  • Understand information security principles associated with underlying networks and communications systems:
    • Entry points in networks and associated authentication techniques
    • The role of cryptography in network security
  • Address information security issues relating to value-added services that use underlying networks and communications systems.
  • Address information security issues relating to organisations that utilise cloud computing facilities.
  • Understand operating systems, database and file management systems, network systems, and applications systems, and how they apply to the IT infrastructure.

7. Physical and Environmental Security Controls

  • Examine physical aspects of security in multi-layered defences.
  • Assess environmental risks.

8. Disaster Recovery and Business Continuity Management

  • Understand the differences between, and the need for, business continuity and disaster recovery.

9. Other Technical Aspects

  • Demonstrate an understanding of principles and common practices, including any legal constraints and obligations, to contribute appropriately to investigations.
  • Explain the role of cryptography in protecting systems and assets, including awareness of relevant standards and practices.

NobleProg is a BCS Accredited Training Provider.

This course will be delivered by an expert NobleProg trainer approved by BCS.

The price includes the delivery of the full course syllabus by an approved BCS trainer and the BCS CISMP exam (which can be taken remotely at your convenience and is invigilated centrally by BCS). Subject to successfully passing the exam (multiple choice, requiring a score of at least 65% to pass), participants will hold the accredited BCS Foundation Certificate in Information Security Management Principles (CISMP).

Requirements

There are no formal entry requirements; however, candidates should possess basic IT working knowledge and an awareness of the issues involved in security control activities.

 21 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 3900 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (4)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories