CISM Training in South Africa for Information Security Leaders
Prepare for the ISACA Certified Information Security Manager (CISM) exam through 36+ hours of trainer-led learning for professionals across South Africa. Choose live online, self-paced reinforcement, classroom or corporate delivery, supported by recordings, an AI-powered LMS, notes, mind maps, infographics, 3,000+ practice questions, mock exams and structured exam guidance.
EduDelphi is an independent CISM exam-preparation provider. ISACA separately administers CISM registration, PSI testing, certification, experience review and continuing professional education requirements.
CISM Course in South Africa: What You Are Planning For
A clear view of the training route, official examination and certification journey before you choose a batch.
| Course detail | Current reference |
|---|---|
| Credential | Certified Information Security Manager (CISM) |
| Credential body | ISACA |
| EduDelphi role | Independent CISM training and exam preparation |
| Delivery | Live online nationwide, self-paced reinforcement, classroom and corporate delivery |
| Guided learning | 36+ trainer-led hours, recordings and structured revision |
| Practice | 3,000+ practice questions, drills, revision activities and mock resources |
| Official exam | 150 multiple-choice questions in 4 hours |
| Testing | ISACA PSI test centre or remote proctoring, subject to current availability |
| Registration window | Continuous registration; eligibility is currently valid for 6 months after registration |
| Fees | EduDelphi tuition quoted in ZAR; official ISACA costs paid separately in USD |
CISM Exam Changes 2026: New Outline from 3 November
ISACA states that its revised CISM Exam Content Outline takes effect on 3 November 2026. Updated preparation materials are expected from September 2026. Candidates should match their study materials and exam booking to the official outline applicable on their intended examination date.
Before 3 November
Prepare against the current four-domain outline and applicable material for your booked exam date.
From September
ISACA says updated preparation material for the new outline becomes available in September 2026.
From 3 November
The revised official content outline applies. Confirm the published domain details before preparing for an exam on or after this date.
What Is CISM?
CISM stands for Certified Information Security Manager. It is ISACA’s management-focused information-security credential for professionals responsible for governance, risk, security programmes and incident-management leadership.
CISM is most relevant when your next responsibility is not simply technical implementation, but making security decisions understandable, funded, governed and resilient across the organisation.
Provider versus credential body: EduDelphi prepares learners. ISACA controls the official exam, certification application, experience review and CISM designation.

Who Should Take a CISM Course in South Africa?
CISM is strongest for professionals moving toward information-security leadership and decision-making, rather than entry-level technical cybersecurity alone.
Security & GRC leaders
Security managers, governance specialists, risk leaders and professionals who must connect security strategy to business objectives.
Audit, privacy & compliance
IT audit, assurance, privacy and compliance professionals moving into security-governance and control-accountability roles.
Programme & incident owners
Professionals responsible for security programmes, third-party risk, incident readiness, recovery and executive reporting.
When another route may fit better: choose CISA when IT audit is your primary direction, CRISC for focused IT risk and controls, or a technical credential when your immediate work is hands-on security engineering or operations.
Security Leadership in a South African Governance Context
South African security leaders often need to translate cyber risk into decisions about privacy, resilience, suppliers, incident response, investment priorities and accountability.
POPIA expects responsible parties to use appropriate, reasonable technical and organisational safeguards, identify foreseeable risks, verify safeguards and keep them updated. CISM preparation supports the management thinking behind those decisions; it does not replace legal advice or a POPIA-specific compliance programme.
We use balanced scenarios across financial services, telecom, consulting, mining, public-sector and enterprise environments, without pretending every sector has the same regulatory or risk profile.
POPIA Section 19
Reasonable technical and organisational safeguards, foreseeable-risk identification, verification of safeguards and ongoing control effectiveness.
Joint Standard 2 of 2024
Cybersecurity and cyber-resilience expectations for applicable financial institutions. The standard became effective on 1 June 2025.
Cybercrimes Act 19 of 2020
South Africa’s cybercrime legal environment and the wider need for disciplined incident, evidence and governance processes.
Banking & financial services
Governance, cyber-resilience, third-party risk, incident management and executive security reporting across banking, insurance, payments, fintech and retirement funds.
Important distinction: CISM training supports security-management capability; it does not itself establish POPIA, FIC, Joint Standard or other regulatory compliance.
Useful local connections
POPIA safeguardsBoard reportingThird-party riskIncident responseSecurity programmesBusiness resiliencePrivacy governanceExecutive communication
Keep Teaching, Revision & Exam Practice in One CISM Study System
A structured course for working professionals who need both flexibility and visible progress across every CISM domain.
Live expert-led learning
36+ hours of trainer-led sessions focused on management judgement, exam logic and practical context.
Recordings & self-paced reinforcement
Revisit difficult sessions and keep momentum when work responsibilities affect attendance.
AI-powered LMS
Notes, mind maps, infographics, structured revision resources and a clear study path in one place.
3,000+ practice resources
Questions, drills, revision activities and mock resources used to find and close weaker areas.
Mock review & exam strategy
Practise interpreting management-level question scenarios, timing answers and reviewing decision logic.
Route & scheduling support
Guidance on the separate ISACA registration process, PSI scheduling, exam timing and official cost categories.
CISM Exam Domains: Governance, Risk, Programme & Incidents
The current ISACA CISM exam has four job-practice domains. EduDelphi uses the applicable official outline for your intended exam administration.
1. Information Security Governance – 17%
- Enterprise governance, culture, structures and regulatory context.
- Security strategy, governance frameworks, policy direction and business cases.
- Stakeholder commitment, roles, accountability, metrics and executive reporting.
2. Information Security Risk Management – 20%
- Threat, vulnerability, control-deficiency and risk assessment analysis.
- Risk response, risk ownership, treatment options, monitoring and reporting.
- Applying risk reasoning to business and technology decisions.
3. Information Security Program – 33%
- Resources, assets, standards, policies, programme metrics and communications.
- Control design, implementation, testing, security awareness and third-party services.
- Running a security programme that supports the wider organisation.
4. Incident Management – 30%
- Incident readiness, classification, business impact, continuity and recovery planning.
- Investigation, containment, response communications and escalation.
- Post-incident review and improvement of response capability.
For November 2026 onward: ISACA’s revised outline takes effect on 3 November 2026. We will direct your preparation toward the current applicable official content rather than relying on an old static syllabus.
CISM Exam Format, Eligibility & Certification Route
You can take the CISM examination before completing the full experience requirement. Passing the exam is one step in the eventual ISACA certification route.
Register with ISACA
Registration is continuous. ISACA payment establishes exam eligibility for its current six-month period.
Prepare and schedule
Book through PSI after registration, at an authorised centre or through remote proctoring where currently available. Appointments may currently be scheduled as early as 48 hours after payment, subject to PSI availability.
Pass the CISM exam
Complete the computer-based 150-question exam within the four-hour appointment.
Apply for certification
ISACA requires qualifying experience across at least three CISM domains, application review, ethics commitment and CPE maintenance.
ISACA currently requires five years of professional information-security management experience across at least three domains for certification. Candidates have five years after passing to apply.
Plan Your CISM Budget in ZAR & Official ISACA Costs
Your total plan has two separate parts: EduDelphi CISM training in ZAR and official ISACA registration/certification costs in USD.
EduDelphi training fees
Request the current ZAR fee for your live online, self-paced, classroom, individual or corporate route. We will explain tuition, AI LMS access, recordings, practice resources, mock support and available instalment options.
Official ISACA costs
US$575 current member exam fee
US$760 current non-member exam fee
US$50 CISM certification application fee
Official ISACA fees are separate from EduDelphi tuition and can change. Confirm current pricing directly with ISACA before payment.
CISM Classes Across South Africa: Live, Self-Paced & Corporate
Plan around work commitments without losing the accountability of a structured CISM route.
Live online
South Africa-time sessions for professionals nationwide, with recordings to support continuity.
Self-paced support
LMS-led reinforcement, revision materials, recordings and scheduled guidance for flexible study.
Classroom / onsite
Instructor-led physical delivery can be arranged for suitable groups and locations.
Corporate cohorts
Private CISM preparation for security, audit, risk, compliance and technology teams.
Learners can join from Johannesburg, Sandton, Pretoria, Centurion, Midrand, Cape Town, Durban, Gqeberha and elsewhere in South Africa.

Practise the Management Decision, Not Just the Definition
EduDelphi uses scenario discussion to help CISM learners practise the judgement required when security choices affect operations, leadership and external stakeholders.
South Africa security scenario
A third-party service provider reports unauthorised access to personal information. The technical team wants to contain the incident quickly, while executives need a reliable assessment of business impact, legal/privacy considerations, customer communication and recovery priorities.
What learners work through
Identify the decision owner, establish evidence and risk facts, test whether the incident plan is fit for purpose, decide escalation priorities and connect the next steps to governance, supplier management and post-incident improvement.
Why this matters: the purpose is not to give legal advice or a single memorised answer. It is to build a disciplined CISM-style approach to management judgement, communication and risk-based decision making.

Build a Stronger Information-Security Leadership Narrative
CISM knowledge can strengthen how you contribute to security governance, risk reporting, programme management, third-party oversight and incident readiness.
It can be relevant to security managers, GRC professionals, IT risk and audit specialists, privacy/compliance professionals, programme managers and leaders developing toward CISO-track responsibilities.
CISM does not guarantee employment, promotion or salary. Outcomes also depend on experience, employer needs, sector, local market conditions and the responsibilities you can demonstrate at work.
Learn with a CISM and Security-Governance Practitioner
Kashif Akhtar
CISA · CISM · CRISC · CDPSE · PMP · CSCP
Kashif supports CISM learners through security-governance concepts, risk interpretation, programme decisions, question debriefs, mock review and structured revision planning.
Faculty perspective: CISM questions often look technical at first, but the better answer usually starts with the management objective: clarify the risk, governance responsibility, evidence and business impact before choosing a control or action.
Corporate CISM Training for South African Teams
Private CISM preparation can be planned for security, audit, risk, privacy, compliance and technology teams across South Africa. Cohorts can be paced around programme priorities, reporting cycles and intended examination timing.
EduDelphi has delivered professional learning for teams associated with recognised organisations across sectors. The logos below represent organisation-level training relationships, not CISM endorsement or certification-body affiliation.








CISM, CISA, CRISC or CISSP?
Choose by the work you want to own, rather than by whichever certification title is most familiar.
| Route | Primary focus | Usually best when |
|---|---|---|
| CISM | Information-security governance, risk, programmes and incidents | You are moving into management-level security responsibility. |
| CISA | IT audit, assurance and control evaluation | Technology assurance and audit work are central to your role. |
| CRISC | IT risk and information-systems controls | You need deeper risk, control design and risk-treatment capability. |
| CISSP | Broad information-security technical and managerial knowledge | You need wide security-domain coverage alongside technical depth. |
CISM Course & Certification Questions
Is this the official CISM certification from ISACA?
EduDelphi provides independent CISM training and exam preparation. ISACA administers the official CISM exam, reviews certification applications and awards the CISM designation when its requirements are met.
Can I take the CISM exam before meeting the experience requirement?
Yes. ISACA states that the CISM exam is open to interested candidates. Full certification requires qualifying experience, but candidates have five years from passing the exam to apply for certification.
What experience is required for CISM certification?
ISACA currently requires five years of professional information-security management experience across at least three of the four CISM job-practice domains. Any applicable experience substitutions or detailed application provisions should be checked in the current ISACA application documentation.
How many questions are on the CISM exam?
The current CISM examination has 150 multiple-choice questions and a four-hour appointment. ISACA uses a scaled score, with 450 as the current passing score.
How long do I have to take the CISM exam after registration?
ISACA currently states that CISM exam eligibility is valid for six months after registration and payment. PSI appointment availability should be checked when planning your date.
How quickly can I schedule my CISM exam after registering?
Appointments may currently be scheduled as early as 48 hours after payment, subject to PSI availability. Successful payment, eligibility status and live appointment availability all affect the date you can select.
What changes in the CISM exam from November 2026?
ISACA says its updated CISM Exam Content Outline takes effect on 3 November 2026. EduDelphi will plan your study materials and revision around the official outline applicable to your intended exam date.
Is CISM training available in Johannesburg, Cape Town and Durban?
Yes. Live online learning is available nationwide, including Johannesburg, Cape Town, Pretoria, Durban and other locations. Classroom, onsite and corporate arrangements can also be discussed.
Is self-paced CISM preparation available?
Yes. Self-paced reinforcement includes access to recordings, the AI-powered LMS, notes, practice resources, mock support and scheduled guidance for candidates who need greater flexibility.
What is included in the CISM course?
The route includes 36+ trainer-led hours, recordings, an AI-powered LMS, notes, mind maps, infographics, 3,000+ practice questions and revision resources, mock support and guidance on the separate ISACA process.
What are CISM course fees in South Africa?
EduDelphi tuition is quoted in ZAR based on your learning mode and route. ISACA’s official examination and certification costs are separate and are currently published in USD.
What happens after I become CISM certified?
CISM holders currently need at least 20 CPE hours each year and 120 CPE hours over a three-year reporting cycle. ISACA currently lists an annual maintenance fee of US$45 for members and US$85 for non-members. Confirm the applicable current requirements and fees with ISACA when maintaining the certification.
Are instalment options available?
Eligible individual learners can discuss instalment or staged-payment options when requesting the current CISM fee breakdown.
Can companies arrange corporate CISM training?
Yes. Corporate CISM cohorts can be delivered live online, onsite or in classroom formats, with pacing and case discussion aligned to your team’s governance, risk and incident-management priorities.
Get CISM Fees, Syllabus & South Africa Batch Options
Share your role, city, preferred learning format and intended exam date. We will send the current ZAR training fee, delivery options, CISM syllabus, 2026 transition guidance and separate official ISACA cost information.





















