CISM training across South Africa

CISM Training in South Africa for Information Security Leaders

Prepare for the ISACA Certified Information Security Manager (CISM) exam through 36+ hours of trainer-led learning for professionals across South Africa. Choose live online, self-paced reinforcement, classroom or corporate delivery, supported by recordings, an AI-powered LMS, notes, mind maps, infographics, 3,000+ practice questions, mock exams and structured exam guidance.

EduDelphi is an independent CISM exam-preparation provider. ISACA separately administers CISM registration, PSI testing, certification, experience review and continuing professional education requirements.

36+ Hoursguided CISM preparation
3,000+practice resources and mocks
4 Domainscurrent ISACA CISM structure
150 Questionsofficial CISM examination

Get CISM Fees & Batch OptionsExplore the CISM Exam Route

Course at a glance

CISM Course in South Africa: What You Are Planning For

A clear view of the training route, official examination and certification journey before you choose a batch.

Course detail Current reference
Credential Certified Information Security Manager (CISM)
Credential body ISACA
EduDelphi role Independent CISM training and exam preparation
Delivery Live online nationwide, self-paced reinforcement, classroom and corporate delivery
Guided learning 36+ trainer-led hours, recordings and structured revision
Practice 3,000+ practice questions, drills, revision activities and mock resources
Official exam 150 multiple-choice questions in 4 hours
Testing ISACA PSI test centre or remote proctoring, subject to current availability
Registration window Continuous registration; eligibility is currently valid for 6 months after registration
Fees EduDelphi tuition quoted in ZAR; official ISACA costs paid separately in USD
2026 exam update

CISM Exam Changes 2026: New Outline from 3 November

ISACA states that its revised CISM Exam Content Outline takes effect on 3 November 2026. Updated preparation materials are expected from September 2026. Candidates should match their study materials and exam booking to the official outline applicable on their intended examination date.

Before 3 November

Prepare against the current four-domain outline and applicable material for your booked exam date.

From September

ISACA says updated preparation material for the new outline becomes available in September 2026.

From 3 November

The revised official content outline applies. Confirm the published domain details before preparing for an exam on or after this date.

View the current ISACA CISM update

Credential clarity

What Is CISM?

CISM stands for Certified Information Security Manager. It is ISACA’s management-focused information-security credential for professionals responsible for governance, risk, security programmes and incident-management leadership.

CISM is most relevant when your next responsibility is not simply technical implementation, but making security decisions understandable, funded, governed and resilient across the organisation.

Provider versus credential body: EduDelphi prepares learners. ISACA controls the official exam, certification application, experience review and CISM designation.

Live CISM training workshop for South African security professionals
Trainer-led CISM learning connects governance choices with realistic security-management decisions.
Choose by responsibility

Who Should Take a CISM Course in South Africa?

CISM is strongest for professionals moving toward information-security leadership and decision-making, rather than entry-level technical cybersecurity alone.

Security & GRC leaders

Security managers, governance specialists, risk leaders and professionals who must connect security strategy to business objectives.

Audit, privacy & compliance

IT audit, assurance, privacy and compliance professionals moving into security-governance and control-accountability roles.

Programme & incident owners

Professionals responsible for security programmes, third-party risk, incident readiness, recovery and executive reporting.

When another route may fit better: choose CISA when IT audit is your primary direction, CRISC for focused IT risk and controls, or a technical credential when your immediate work is hands-on security engineering or operations.

South Africa relevance

Security Leadership in a South African Governance Context

South African security leaders often need to translate cyber risk into decisions about privacy, resilience, suppliers, incident response, investment priorities and accountability.

POPIA expects responsible parties to use appropriate, reasonable technical and organisational safeguards, identify foreseeable risks, verify safeguards and keep them updated. CISM preparation supports the management thinking behind those decisions; it does not replace legal advice or a POPIA-specific compliance programme.

We use balanced scenarios across financial services, telecom, consulting, mining, public-sector and enterprise environments, without pretending every sector has the same regulatory or risk profile.

POPIA Section 19

Reasonable technical and organisational safeguards, foreseeable-risk identification, verification of safeguards and ongoing control effectiveness.

Joint Standard 2 of 2024

Cybersecurity and cyber-resilience expectations for applicable financial institutions. The standard became effective on 1 June 2025.

Cybercrimes Act 19 of 2020

South Africa’s cybercrime legal environment and the wider need for disciplined incident, evidence and governance processes.

Banking & financial services

Governance, cyber-resilience, third-party risk, incident management and executive security reporting across banking, insurance, payments, fintech and retirement funds.

Important distinction: CISM training supports security-management capability; it does not itself establish POPIA, FIC, Joint Standard or other regulatory compliance.

See a management case example

Useful local connections

POPIA safeguardsBoard reportingThird-party riskIncident responseSecurity programmesBusiness resiliencePrivacy governanceExecutive communication

What is included

Keep Teaching, Revision & Exam Practice in One CISM Study System

A structured course for working professionals who need both flexibility and visible progress across every CISM domain.

Live expert-led learning

36+ hours of trainer-led sessions focused on management judgement, exam logic and practical context.

Recordings & self-paced reinforcement

Revisit difficult sessions and keep momentum when work responsibilities affect attendance.

AI-powered LMS

Notes, mind maps, infographics, structured revision resources and a clear study path in one place.

3,000+ practice resources

Questions, drills, revision activities and mock resources used to find and close weaker areas.

Mock review & exam strategy

Practise interpreting management-level question scenarios, timing answers and reviewing decision logic.

Route & scheduling support

Guidance on the separate ISACA registration process, PSI scheduling, exam timing and official cost categories.

Current CISM syllabus

CISM Exam Domains: Governance, Risk, Programme & Incidents

The current ISACA CISM exam has four job-practice domains. EduDelphi uses the applicable official outline for your intended exam administration.

1. Information Security Governance – 17%
  • Enterprise governance, culture, structures and regulatory context.
  • Security strategy, governance frameworks, policy direction and business cases.
  • Stakeholder commitment, roles, accountability, metrics and executive reporting.
2. Information Security Risk Management – 20%
  • Threat, vulnerability, control-deficiency and risk assessment analysis.
  • Risk response, risk ownership, treatment options, monitoring and reporting.
  • Applying risk reasoning to business and technology decisions.
3. Information Security Program – 33%
  • Resources, assets, standards, policies, programme metrics and communications.
  • Control design, implementation, testing, security awareness and third-party services.
  • Running a security programme that supports the wider organisation.
4. Incident Management – 30%
  • Incident readiness, classification, business impact, continuity and recovery planning.
  • Investigation, containment, response communications and escalation.
  • Post-incident review and improvement of response capability.

For November 2026 onward: ISACA’s revised outline takes effect on 3 November 2026. We will direct your preparation toward the current applicable official content rather than relying on an old static syllabus.

Official route & exam format

CISM Exam Format, Eligibility & Certification Route

You can take the CISM examination before completing the full experience requirement. Passing the exam is one step in the eventual ISACA certification route.

150multiple-choice questions
4 Hoursofficial exam duration
450passing scaled score
6 Monthsexam eligibility after registration
1

Register with ISACA

Registration is continuous. ISACA payment establishes exam eligibility for its current six-month period.

2

Prepare and schedule

Book through PSI after registration, at an authorised centre or through remote proctoring where currently available. Appointments may currently be scheduled as early as 48 hours after payment, subject to PSI availability.

3

Pass the CISM exam

Complete the computer-based 150-question exam within the four-hour appointment.

4

Apply for certification

ISACA requires qualifying experience across at least three CISM domains, application review, ethics commitment and CPE maintenance.

ISACA currently requires five years of professional information-security management experience across at least three domains for certification. Candidates have five years after passing to apply.

Check My CISM EligibilityView Official CISM Requirements

CISM course fees in South Africa

Plan Your CISM Budget in ZAR & Official ISACA Costs

Your total plan has two separate parts: EduDelphi CISM training in ZAR and official ISACA registration/certification costs in USD.

EduDelphi training fees

Request the current ZAR fee for your live online, self-paced, classroom, individual or corporate route. We will explain tuition, AI LMS access, recordings, practice resources, mock support and available instalment options.

Get CISM Fee Breakdown in ZAR

Official ISACA costs

US$575 current member exam fee
US$760 current non-member exam fee
US$50 CISM certification application fee

Official ISACA fees are separate from EduDelphi tuition and can change. Confirm current pricing directly with ISACA before payment.

View Official ISACA Fees

Flexible delivery

CISM Classes Across South Africa: Live, Self-Paced & Corporate

Plan around work commitments without losing the accountability of a structured CISM route.

Live online

South Africa-time sessions for professionals nationwide, with recordings to support continuity.

Self-paced support

LMS-led reinforcement, revision materials, recordings and scheduled guidance for flexible study.

Classroom / onsite

Instructor-led physical delivery can be arranged for suitable groups and locations.

Corporate cohorts

Private CISM preparation for security, audit, risk, compliance and technology teams.

Learners can join from Johannesburg, Sandton, Pretoria, Centurion, Midrand, Cape Town, Durban, Gqeberha and elsewhere in South Africa.

South African CISM learner studying from Cape Town
Study live, revisit recordings and use the LMS around an active professional schedule.
Case-based learning

Practise the Management Decision, Not Just the Definition

EduDelphi uses scenario discussion to help CISM learners practise the judgement required when security choices affect operations, leadership and external stakeholders.

South Africa security scenario

A third-party service provider reports unauthorised access to personal information. The technical team wants to contain the incident quickly, while executives need a reliable assessment of business impact, legal/privacy considerations, customer communication and recovery priorities.

What learners work through

Identify the decision owner, establish evidence and risk facts, test whether the incident plan is fit for purpose, decide escalation priorities and connect the next steps to governance, supplier management and post-incident improvement.

Why this matters: the purpose is not to give legal advice or a single memorised answer. It is to build a disciplined CISM-style approach to management judgement, communication and risk-based decision making.

Information security leadership meeting in Johannesburg
CISM knowledge supports clearer risk, programme and incident-management conversations at work.
Career relevance, not a promise

Build a Stronger Information-Security Leadership Narrative

CISM knowledge can strengthen how you contribute to security governance, risk reporting, programme management, third-party oversight and incident readiness.

It can be relevant to security managers, GRC professionals, IT risk and audit specialists, privacy/compliance professionals, programme managers and leaders developing toward CISO-track responsibilities.

CISM does not guarantee employment, promotion or salary. Outcomes also depend on experience, employer needs, sector, local market conditions and the responsibilities you can demonstrate at work.

Compare CISM with other security routes

Faculty

Learn with a CISM and Security-Governance Practitioner

Kashif Akhtar, CISM trainer

Kashif Akhtar

CISA · CISM · CRISC · CDPSE · PMP · CSCP

Kashif supports CISM learners through security-governance concepts, risk interpretation, programme decisions, question debriefs, mock review and structured revision planning.

Faculty perspective: CISM questions often look technical at first, but the better answer usually starts with the management objective: clarify the risk, governance responsibility, evidence and business impact before choosing a control or action.

Team learning

Corporate CISM Training for South African Teams

Private CISM preparation can be planned for security, audit, risk, privacy, compliance and technology teams across South Africa. Cohorts can be paced around programme priorities, reporting cycles and intended examination timing.

EduDelphi has delivered professional learning for teams associated with recognised organisations across sectors. The logos below represent organisation-level training relationships, not CISM endorsement or certification-body affiliation.

Request Corporate CISM Training

Choose the right route

CISM, CISA, CRISC or CISSP?

Choose by the work you want to own, rather than by whichever certification title is most familiar.

Route Primary focus Usually best when
CISM Information-security governance, risk, programmes and incidents You are moving into management-level security responsibility.
CISA IT audit, assurance and control evaluation Technology assurance and audit work are central to your role.
CRISC IT risk and information-systems controls You need deeper risk, control design and risk-treatment capability.
CISSP Broad information-security technical and managerial knowledge You need wide security-domain coverage alongside technical depth.
Frequently asked questions

CISM Course & Certification Questions

Is this the official CISM certification from ISACA?

EduDelphi provides independent CISM training and exam preparation. ISACA administers the official CISM exam, reviews certification applications and awards the CISM designation when its requirements are met.

Can I take the CISM exam before meeting the experience requirement?

Yes. ISACA states that the CISM exam is open to interested candidates. Full certification requires qualifying experience, but candidates have five years from passing the exam to apply for certification.

What experience is required for CISM certification?

ISACA currently requires five years of professional information-security management experience across at least three of the four CISM job-practice domains. Any applicable experience substitutions or detailed application provisions should be checked in the current ISACA application documentation.

How many questions are on the CISM exam?

The current CISM examination has 150 multiple-choice questions and a four-hour appointment. ISACA uses a scaled score, with 450 as the current passing score.

How long do I have to take the CISM exam after registration?

ISACA currently states that CISM exam eligibility is valid for six months after registration and payment. PSI appointment availability should be checked when planning your date.

How quickly can I schedule my CISM exam after registering?

Appointments may currently be scheduled as early as 48 hours after payment, subject to PSI availability. Successful payment, eligibility status and live appointment availability all affect the date you can select.

What changes in the CISM exam from November 2026?

ISACA says its updated CISM Exam Content Outline takes effect on 3 November 2026. EduDelphi will plan your study materials and revision around the official outline applicable to your intended exam date.

Is CISM training available in Johannesburg, Cape Town and Durban?

Yes. Live online learning is available nationwide, including Johannesburg, Cape Town, Pretoria, Durban and other locations. Classroom, onsite and corporate arrangements can also be discussed.

Is self-paced CISM preparation available?

Yes. Self-paced reinforcement includes access to recordings, the AI-powered LMS, notes, practice resources, mock support and scheduled guidance for candidates who need greater flexibility.

What is included in the CISM course?

The route includes 36+ trainer-led hours, recordings, an AI-powered LMS, notes, mind maps, infographics, 3,000+ practice questions and revision resources, mock support and guidance on the separate ISACA process.

What are CISM course fees in South Africa?

EduDelphi tuition is quoted in ZAR based on your learning mode and route. ISACA’s official examination and certification costs are separate and are currently published in USD.

What happens after I become CISM certified?

CISM holders currently need at least 20 CPE hours each year and 120 CPE hours over a three-year reporting cycle. ISACA currently lists an annual maintenance fee of US$45 for members and US$85 for non-members. Confirm the applicable current requirements and fees with ISACA when maintaining the certification.

Are instalment options available?

Eligible individual learners can discuss instalment or staged-payment options when requesting the current CISM fee breakdown.

Can companies arrange corporate CISM training?

Yes. Corporate CISM cohorts can be delivered live online, onsite or in classroom formats, with pacing and case discussion aligned to your team’s governance, risk and incident-management priorities.

Plan your CISM route

Get CISM Fees, Syllabus & South Africa Batch Options

Share your role, city, preferred learning format and intended exam date. We will send the current ZAR training fee, delivery options, CISM syllabus, 2026 transition guidance and separate official ISACA cost information.

We respect your privacy. No spam – only relevant course information.