IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CICSM®

Certified International Cybersecurity Manager

Below is a stronger, executive-level rewrite for the CICSM® landing-page hero and primary call-to-action section, positioning it clearly above CICSP® as the advanced management credential.

A padlock and chain securing a mobile device
Cybersecurity
CICSM® Certified International Cybersecurity Manager badge

Govern Cyber Risk. Lead Security. Build Enterprise Resilience.

Advanced Manager Level For cybersecurity leaders, managers and decision-makers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate

What You Will Learn

Master the core areas of cybersecurity.

  • 8 Advanced Cybersecurity Management Modules

Module 1: Enterprise Cybersecurity Strategy, Maturity, and Governance

Develop cybersecurity strategy, assess maturity, establish operating models, define governance, and create executive reporting structures.

Module 2: Enterprise Cyber Risk, Compliance, Privacy, and Assurance

Manage risk appetite, risk treatment, regulatory obligations, control frameworks, privacy, audit, and security assurance.

Module 3: Security Architecture, Zero Trust, Identity, Data, and Cloud Governance

Govern enterprise security architecture, Zero Trust, IAM, PAM, data protection, applications, APIs, cloud, and infrastructure.

Module 4: Cyber Defense, SOC, Threat, Vulnerability, and Exposure Management

Lead SOC operations, detection, threat intelligence, vulnerability management, exposure management, and cyber defense.

Module 5: Incident Response, Crisis Management, and Cyber Resilience

Direct incidents, executive escalation, crisis response, forensic readiness, continuity, disaster recovery, and resilience.

Module 6: Cybersecurity Investment, Technology, Third-Party, and Performance Management

Manage business cases, budgets, vendors, supply-chain risk, technology portfolios, KPIs, KRIs, and cybersecurity value.

Module 7: AI Security, Emerging Technologies, and Digital Risk

Govern AI, GenAI, IoT, OT, DevSecOps, software supply chains, cloud-native risks, automation, and future threats.

Module 8: Cybersecurity Leadership, Workforce, Culture, and Transformation

Build cybersecurity organizations, develop talent, strengthen security culture, communicate to executives and boards, and lead transformation.

Career Opportunities

CICSM® can support professional development toward roles such as:

  • Cybersecurity Manager
  • Information Security Manager
  • Security Operations Manager
  • SOC Manager
  • Cyber Defense Manager
  • Cyber Risk Manager
  • GRC Manager
  • Cloud Security Manager
  • Incident Response Manager
  • Security Program Manager
  • Cybersecurity Strategy Consultant
  • Security Architecture Manager
  • Director of Cybersecurity
  • Director of Information Security
  • Head of Cybersecurity
  • Head of Security Operations
  • Enterprise Cybersecurity Leader

Actual role eligibility depends on education, professional experience, leadership experience, and employer requirements.

View Career Outlook
About the credential

Become a Cybersecurity professional the market trusts.

A padlock and chain securing a mobile device

Advanced Manager level — Three-year certification cycle with continuing professional education

Why this credential

Why Earn CICSM®?

Organizations increasingly need cybersecurity leaders who can translate complex technical risks into clear enterprise priorities, investment decisions, governance actions, and measurable business outcomes.

CICSM® develops the professional judgment required to address critical leadership questions such as:

Which Cyber Risks Matter Most?

Evaluate threats, vulnerabilities, business dependencies, critical assets, potential impact, and organizational risk appetite to determine priorities.

Where Should Cybersecurity Investment Be Prioritized?

Compare security initiatives according to risk reduction, strategic importance, regulatory requirements, operational need, cost, and expected enterprise value.

What Cyber Risk Can the Organization Accept?

Support informed risk-acceptance, mitigation, transfer, avoidance, and escalation decisions within established governance structures.

How Should Security Architecture and Zero Trust Be Governed?

Establish strategic direction for IAM, networks, endpoints, cloud, applications, data protection, segmentation, and Zero Trust transformation.

How Should SOC and Cyber-Defense Capabilities Be Managed?

Evaluate detection coverage, threat intelligence, monitoring, incident escalation, operational performance, workforce capability, and defensive effectiveness.

How Should Vulnerabilities Be Prioritized?

Move beyond technical severity scores by considering asset criticality, exploitability, threat intelligence, business impact, compensating controls, and organizational exposure.

When Should a Cyber Incident Become an Executive Crisis?

Evaluate severity, operational impact, data exposure, regulatory implications, stakeholder impact, business continuity, and escalation requirements.

How Should the Organization Prepare for Major Cyber Disruption?

Integrate incident response, crisis management, business continuity, disaster recovery, executive communication, exercises, and cyber resilience.

How Should Third-Party Cyber Risk Be Governed?

Evaluate suppliers, service providers, cloud platforms, technology partners, software dependencies, contractual controls, and digital supply-chain exposure.

How Should Cybersecurity Performance Be Measured?

Establish meaningful KPIs, KRIs, maturity measures, resilience indicators, operational metrics, and executive reporting that demonstrate cybersecurity effectiveness and risk reduction.

How Should AI and Emerging Technology Risk Be Governed?

Address AI and Generative AI security, sensitive-data exposure, AI-enabled threats, automation, cloud-native technologies, IoT, OT, software supply chains, and emerging digital risks.

How Should Cyber Risk Be Communicated to Executives and Boards?

Translate technical cybersecurity information into concise discussions of business impact, risk exposure, strategic priorities, investment requirements, resilience, and decision options.

CICSM®

Who Should Earn CICSM®?

CICSM® is designed for experienced professionals such as:

  • Cybersecurity Managers
  • Information Security Managers
  • SOC Managers
  • Security Operations Managers
  • Cyber Defense Managers
  • Cyber Risk Managers
  • GRC Managers
  • IT Security Managers
  • Network Security Managers
  • Cloud Security Managers
  • Incident Response Managers
  • Security Program Managers
  • Cybersecurity Consultants
  • Security Architects transitioning into leadership
  • Senior Cybersecurity Analysts
  • Information Systems Managers
  • IT Managers
  • Directors of Cybersecurity
  • Directors of Information Security
  • Heads of Cybersecurity
  • Heads of Security Operations
  • Technology leaders with enterprise cybersecurity responsibilities
CICSM®

Recommended Candidate Background

CICSM® is an advanced management-level certification.

Candidates should preferably possess relevant experience in:

CICSP® is the recommended professional-level progression into CICSM®, although candidates with equivalent professional experience may qualify according to applicable IBACTP® certification policies.

  • Cybersecurity
  • Information security
  • Cyber risk
  • Security operations
  • Cloud security
  • Network security
  • GRC
  • Incident response
  • Information systems
  • IT management
  • Enterprise architecture
  • Security consulting
  • Technology leadership
Learning outcomes

CICSM® Course Learning Outcomes

Upon successful completion of the Certified International Cybersecurity Manager (CICSM®) program, participants will be able to:

1. Develop Enterprise Cybersecurity Strategy and Operating Models

Assess cybersecurity maturity, establish strategic priorities, define operating models, develop roadmaps, and align cybersecurity initiatives with enterprise objectives, risk priorities, and business value.

2. Lead Cybersecurity Governance, Risk, Compliance, and Executive Oversight

Establish governance structures, policies, accountability, risk-management processes, compliance programs, control oversight, and executive and board-level cybersecurity reporting.

3. Govern Enterprise Security Architecture and Technology

Provide management oversight for Zero Trust, IAM, networks, endpoints, applications, cloud environments, data protection, infrastructure, security platforms, and enterprise security architecture.

4. Lead Cyber Defense, Threat, Vulnerability, and Exposure Management

Direct SOC capabilities, threat intelligence, security monitoring, detection, vulnerability management, exposure reduction, remediation priorities, and enterprise cyber-defense operations.

5. Direct Incident Response, Cyber Crisis Management, and Resilience

Establish and lead incident-response capabilities, escalation frameworks, cyber-crisis management, executive communication, recovery strategies, business continuity, disaster recovery, and cyber resilience.

6. Manage Cybersecurity Investment, Performance, Vendors, and Third Parties

Develop cybersecurity business cases, prioritize investments, allocate resources, manage vendors and third-party risks, establish KPIs and KRIs, and evaluate cybersecurity performance and value.

7. Govern AI Security, Privacy, and Emerging Technology Risk

Evaluate and govern cybersecurity risks involving AI, Generative AI, cloud technologies, IoT, OT, DevSecOps, automation, software supply chains, privacy, and emerging digital technologies.

8. Lead Cybersecurity Workforce, Culture, and Enterprise Transformation

Build and develop cybersecurity teams, strengthen organizational security culture, manage skills and capabilities, influence stakeholders, communicate with executives and boards, and lead enterprise cybersecurity transformation.

What is assessed

CICSM® Certification Testing Outcomes — Skills and Competencies Assessed

The CICSM® certification assessment evaluates advanced managerial competency, strategic judgment, governance capability, risk-based decision-making, and cybersecurity leadership across eight integrated domains.

Candidates are expected to demonstrate the ability to assess, prioritize, govern, decide, and lead within realistic enterprise cybersecurity scenarios.

CICSM®

CICSM® Certification Competency Standard

CICSM® assesses more than cybersecurity knowledge. Candidates must demonstrate the managerial judgment and leadership capability required to make risk-informed enterprise cybersecurity decisions.

  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Defend
  • Respond
  • Measure
  • Lead
  • Transform

The ultimate testing objective is to validate the candidate's ability to:

Translate Cyber Risk into Strategy → Strategy into Priorities → Priorities into Security Capabilities → Capabilities into Resilience → Resilience into Protected Enterprise Value.

CICSM®

CICSM® Assessment Cognitive Standard

Because CICSM® is an advanced management certification, the assessment places emphasis on higher-order professional judgment.

Candidates are evaluated across:

  • Security + Risk + Cost + Compliance + Operations + Resilience + People + Enterprise Value
  • Understand
  • Apply
  • Analyze
  • Evaluate
  • Prioritize
  • Decide
  • Lead

The examination may require candidates to balance:

CICSM®

CICSM® Enterprise Cybersecurity Management Capstone

Eligible instructor-led candidates may complete the:

CICSM®

CICSM® Enterprise Cybersecurity Management Capstone

Part 1 — Strategy, Maturity, Risk, and Investment Roadmap

Assess organizational cybersecurity maturity, define material risks, establish priorities, develop business cases, and create a multi-year roadmap.

Part 2 — Governance, Architecture, Defense, and Resilience

Develop governance, security architecture priorities, SOC strategy, IAM, cloud controls, vulnerability management, incident readiness, compliance, and resilience.

Part 3 — Implementation, Workforce, Performance, and Executive Leadership

Define implementation priorities, budgets, workforce needs, metrics, vendors, third-party governance, transformation actions, and executive recommendations.

Capstone Leadership Progression

Assess → Strategize → Govern → Prioritize → Protect → Defend → Respond → Measure → Transform

What it validates

What is CICSM®?

The Certified International Cybersecurity Manager (CICSM®) is an advanced, vendor-neutral cybersecurity management certification designed to validate the strategic, governance, risk, operational, and leadership competencies required to manage cybersecurity as an enterprise capability.

CICSM® moves beyond technical execution. It focuses on how cybersecurity leaders assess risk, establish strategy, govern security capabilities, prioritize investments, direct cyber defense, manage crises, strengthen resilience, develop teams, and communicate cybersecurity priorities to executives and boards.

An Advanced Certification for Cybersecurity Leadership

CICSM® develops and validates management competency across eight integrated leadership areas:

1. Enterprise Cybersecurity Strategy & Leadership

Cybersecurity strategy, maturity assessment, operating models, strategic roadmaps, organizational alignment, and executive priorities.

2. Governance, Risk, Compliance & Executive Oversight

Cyber-risk governance, policies, risk appetite and tolerance, compliance, privacy, accountability, control frameworks, and executive oversight.

3. Security Architecture & Technology Governance

Zero Trust, IAM, network and endpoint security, cloud, applications, data protection, architecture governance, and technology decisions.

4. Cyber Defense, Threat & Vulnerability Management

SOC leadership, threat intelligence, monitoring, detection, vulnerability management, remediation priorities, and defensive capabilities.

5. Incident, Crisis & Cyber-Resilience Management

Incident leadership, escalation, crisis management, executive communication, business continuity, disaster recovery, and enterprise resilience.

6. Cybersecurity Investment, Performance & Third-Party Management

Cybersecurity budgets, investment prioritization, business cases, KPIs, KRIs, vendor management, third-party risk, and benefits realization.

7. AI Security, Privacy & Emerging Technology Risk

AI and Generative AI security, cloud, IoT, OT, automation, software supply chains, privacy, emerging threats, and responsible technology governance.

8. Workforce Leadership & Cybersecurity Transformation

Cybersecurity organization design, talent development, skills management, security culture, stakeholder engagement, executive reporting, change, and enterprise transformation.

What it validates

What Does the CICSM® Designation Represent?

The CICSM® designation represents a cybersecurity leader capable of connecting:

Strategy + Governance + Cyber Risk + Architecture + Cyber Defense + Resilience + Investment + Technology + People + Performance + Enterprise Value

The ultimate management objective is:

Applied practice

Applied CICSM® Management Labs

Assessment

Flexible CICSM® Certification Assessment Options

Option 1

Option 1 — CICSM® Certification Examination

Recommended structure:

The examination evaluates:

Strategy • Governance • Risk Judgment • Architecture Decisions • Cyber Defense Leadership • Incident Decisions • Investment • Performance • Executive Leadership

  • 100 questions
  • Advanced multiple-choice and scenario-based questions
  • 90 minutes
  • Closed book
  • Secure online proctoring or approved testing center
  • Recommended passing score: 70%
Option 2

Option 2 — CICSM® Enterprise Cybersecurity Management Capstone

Eligible instructor-led candidates may demonstrate advanced competency through the three-part enterprise management Capstone.

CICSM®

Certification Validity · 3 Years · Professional Designation

Certification Validity

The recommended CICSM® certification cycle is:

3 Years

Recommended recertification requirement:

Professional Designation

Successful candidates earn:

Cybersecurity

Standards and International Framework Alignment

The CICSM® Body of Knowledge incorporates internationally recognized standards, frameworks, and professional practices relevant to enterprise cybersecurity strategy, governance, risk management, privacy, AI governance, cyber defense, resilience, and professional competency.

CICSM® emphasizes the practical managerial application of these frameworks rather than memorization of individual standards or control requirements.

Key Standards and Frameworks

  • ISO/IEC 17024 — Personnel certification and competency principles
  • ISO/IEC 27001 — Information Security Management Systems (ISMS)
  • ISO/IEC 27002 — Information security controls and implementation guidance
  • ISO/IEC 27005 — Information security risk management
  • ISO/IEC 27701 — Privacy Information Management Systems (PIMS)
  • ISO 31000 — Enterprise risk-management principles
  • ISO/IEC 42001 — Artificial Intelligence Management Systems (AIMS)
  • ISO/IEC 23894 — Artificial Intelligence risk management
  • NIST Cybersecurity Framework (CSF) — Enterprise cybersecurity risk management and resilience
  • NIST NICE Workforce Framework — Cybersecurity workforce roles, knowledge, skills, and competencies
  • NIST AI Risk Management Framework (AI RMF) — AI risk identification, assessment, governance, and management
  • Relevant NIST Security Guidance — Security controls, Zero Trust, incident response, risk management, privacy, and cyber resilience
  • CISA Cybersecurity Guidance — Cyber defense, infrastructure protection, vulnerability reduction, and resilience
  • Recognized Professional Practices — Secure development, cloud security, identity security, incident and crisis management, software supply-chain security, business continuity, and cyber resilience

Management and Leadership Application

CICSM® prepares cybersecurity managers to use recognized frameworks as decision-support and governance tools for addressing enterprise cybersecurity challenges.

Candidates develop the ability to:

  • Interpret standards within organizational and regulatory contexts
  • Assess cybersecurity maturity and control effectiveness
  • Align security frameworks with enterprise risk
  • Prioritize cybersecurity initiatives and investments
  • Establish governance and accountability
  • Evaluate compliance and assurance requirements
  • Develop meaningful cybersecurity KPIs and KRIs
  • Integrate cybersecurity with privacy, AI, cloud, and enterprise risk
  • Measure security performance and resilience
  • Drive continuous cybersecurity improvement
CICSM®

Global and Vendor-Neutral Design

CICSM® is designed around transferable cybersecurity-management competencies.

The credential can be relevant across:

Recognition remains subject to individual employer, regulatory, institutional, and jurisdictional requirements.

  • Technology
  • Banking and finance
  • Healthcare
  • Government
  • Telecommunications
  • Manufacturing
  • Energy
  • Critical infrastructure
  • Education
  • Insurance
  • Transportation
  • Retail
  • Supply chain
  • Consulting
  • Professional services
Cybersecurity

Accreditation and Credentialing Quality Alignment

The CICSM® certification framework is structured around recognized principles of professional credentialing, competency assessment, examination integrity, and continuing professional competence.

Its design incorporates relevant credentialing and personnel-certification principles associated with:

  • ISO/IEC 17024 — Certification of persons
  • ANSI National Accreditation Board (ANAB) — Personnel-certification accreditation practices
  • National Commission for Certifying Agencies (NCCA) — Professional certification quality standards
  • Institute for Credentialing Excellence (I.C.E.) — Credentialing and certification best practices
  • International conformity-assessment and personnel-certification practices
  • Competency • Validity • Reliability • Fairness • Impartiality • Security • Professional Relevance • Continuing Competence

CICSM® Credentialing Quality Framework

The CICSM® certification framework encompasses the following quality elements:

Job Task Analysis • Defined Management Competencies • Eligibility Standards • Validated Body of Knowledge • Examination Blueprint • Subject Matter Expert (SME) Review • Psychometric Principles • Examination Security • Candidate Identity Verification • Impartial Certification Decisions • Appeals and Complaints • Professional Ethics • Continuing Professional Education • Recertification • Credential Verification • Periodic Program Review • Continuous Improvement

These elements support a structured approach to determining what cybersecurity managers are expected to know, analyze, evaluate, govern, prioritize, and lead at the advanced professional level.

CICSM® Certification Quality Lifecycle

The CICSM® credentialing process follows an integrated quality progression:

Analyze → Define → Validate → Assess → Certify → Maintain → Verify → Review → Improve

This lifecycle supports the continuing:

  • Relevance of the CICSM® Body of Knowledge
  • Validity and reliability of certification assessments
  • Fairness and consistency of certification decisions
  • Security and integrity of examinations
  • Professional relevance of management competencies
  • Continuing competence of credential holders
  • Transparency of credential status
  • Responsiveness to changes in cybersecurity practice
  • Continuous improvement of the certification program

Professional Competency and Continuing Certification

CICSM® is designed to represent more than successful completion of training. Certification requirements distinguish among:

Training → Competency Assessment → Certification Decision → Credential Maintenance

The framework supports independent assessment of advanced cybersecurity management competency and continued professional development throughout the certification lifecycle.

Commitment to Credentialing Quality

Through its certification framework, IBACTP® seeks to maintain CICSM® as a credible, rigorous, competency-based, vendor-neutral, and internationally relevant cybersecurity management credential.

The quality objective is to support:

CICSM®

CICSM® Leadership Progression

  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Protect
  • Defend
  • Respond
  • Measure
  • Lead
  • Transform

This progression reflects the transition from understanding enterprise cyber risk to leading cybersecurity as a strategic organizational capability.

CICSM®

CICSM® Leadership Progression

  • Cybersecurity Strategy + Governance + Risk + Technology + Cyber Defense + Resilience + Investment + People + Enterprise Value
  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Defend
  • Respond
  • Measure
  • Lead
  • Transform

Collectively, these outcomes prepare CICSM® participants to connect:

CICSM®

CICSP® vs. CICSM®

AreaCICSP®CICSM®
Level Professional Advanced / Manager
Primary Focus Perform cybersecurity Lead enterprise cybersecurity
Security Architecture Apply and evaluate Govern and prioritize
Network Security Protect and monitor Govern architecture
IAM Apply controls Establish strategy
Cloud Security Apply controls Govern enterprise cloud risk
Vulnerabilities Assess and remediate Govern exposure management
SOC Monitor and investigate Lead and optimize
Incident Response Respond and investigate Direct incidents and crises
Forensics Support investigations Govern readiness
Risk Assess Govern enterprise cyber risk
Compliance Apply requirements Lead assurance
Technology Use and evaluate Select, fund, and govern
AI Security Identify and mitigate Govern enterprise AI security
Metrics Report findings Establish KPIs and KRIs
Workforce Collaborate Build and lead teams
Executive Communication Report findings Advise executives and boards
Primary Outcome Cybersecurity Professional Cybersecurity Manager
CICSM®

Certified International Cybersecurity Manager (CICSM®)

Govern Cyber Risk. Lead Cyber Defense. Build Resilience. Protect Enterprise Value.

Cybersecurity leadership has evolved far beyond managing security technologies, responding to incidents, or supervising technical teams.

Today's cybersecurity managers must connect cyber risk with enterprise strategy. They are expected to establish governance, oversee security architecture, direct cyber-defense capabilities, manage major incidents and crises, prioritize investments, measure performance, govern emerging technology risks, develop high-performing teams, and communicate cybersecurity priorities effectively to executives and boards.

The Certified International Cybersecurity Manager (CICSM®) is an advanced, vendor-neutral professional certification designed to validate the strategic, managerial, analytical, governance, and leadership competencies required to lead cybersecurity across modern enterprises.

Offered by the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

CICSM® represents the advanced management level of the IBACTP® cybersecurity certification pathway and prepares professionals to move from managing individual security activities to leading cybersecurity as an integrated enterprise capability.

CICSM®

Lead Cybersecurity as an Enterprise Capability

CICSM® develops advanced management competency across:

Cybersecurity Strategy • Governance • Enterprise Cyber Risk • Security Architecture • Zero Trust • SOC & Cyber Defense Leadership • Incident & Crisis Management • Cyber Resilience • Security Investment • AI & Emerging Technology Risk • Workforce Leadership • Executive & Board Communication

The certification focuses on the decisions cybersecurity leaders must make:

What risks matter most? → What capabilities should we prioritize? → Where should we invest? → How should security be governed? → How prepared are we for a major incident? → How do we measure performance? → How do we communicate cyber risk to leadership?

CICSM®

The CICSM® Leadership Model

CICSM® connects the major responsibilities of modern cybersecurity management:

Strategy + Governance + Risk + Architecture + Cyber Defense + Resilience + Technology + Investment + People + Enterprise Value

The CICSM® leadership progression is:

CICSM®
  • Assess
  • Strategize
  • Govern
  • Protect
  • Defend
  • Respond
  • Measure
  • Lead
  • Transform

The objective is to develop cybersecurity leaders capable of transforming:

  • Cyber Risk into Strategy → Strategy into Security Capabilities → Capabilities into Resilience → Resilience into Protected Enterprise Value
CICSM®

Who Should Pursue CICSM®?

CICSM® is designed for experienced professionals seeking to lead, govern, or advance enterprise cybersecurity capabilities, including:

Cybersecurity Managers • Security Leaders • SOC Managers • Cyber-Risk Managers • Security Architects • GRC Leaders • Incident Response Managers • IT Managers • Security Consultants • Technology Leaders • Aspiring CISOs • Cybersecurity Program Leaders

Professionals progressing from CICSP® or possessing equivalent cybersecurity, technology, risk, governance, or management experience can use CICSM® to advance toward enterprise cybersecurity leadership.

CICSM®

Advance from Cybersecurity Professional to Cybersecurity Leader

  • Professional Level
  • Advanced / Management Level
  • Strategize → Govern → Prioritize → Lead → Transform

CICSP®

Certified International Cybersecurity Professional

CICSM®

Certified International Cybersecurity Manager

The progression represents the transition from:

Protect → Detect → Analyze → Respond

to:

CICSM®

Lead Cybersecurity. Govern Risk. Strengthen Resilience. Protect Enterprise Value.

APPLY NOW | REGISTER FOR THE EXAM | ENROLL IN TRAINING | EXPLORE THE CAPSTONE

Here is a more executive-focused and marketable version, with the long lists consolidated while preserving the breadth of CICSM®.

CICSM®

More Than Managing Cybersecurity

CICSM® is designed for professionals who must connect cybersecurity with broader organizational priorities.

The CICSM® manager understands that effective cybersecurity leadership requires the integration of:

Strategy + Governance + Risk + Architecture + Cyber Defense + Resilience + Investment + Technology + People + Enterprise Value

The certification emphasizes the ability to make risk-informed, business-aligned, and defensible management decisions rather than simply demonstrating knowledge of cybersecurity terminology or technologies.

CICSM®

The CICSM® Leadership Advantage

CICSM® positions cybersecurity management as more than supervision of security teams, technologies, or operations.

A CICSM® professional is prepared to connect:

  • Cyber Risk
  • Strategy
  • Governance
  • Investment
  • Cyber Defense
  • Resilience
  • Performance
  • Enterprise Value

The CICSM® leadership progression is:

CICSM®
  • Assess
  • Strategize
  • Govern
  • Prioritize
  • Protect
  • Defend
  • Respond
  • Measure
  • Lead
  • Transform

CICSM® Management Objective

The ultimate objective is to develop cybersecurity leaders capable of transforming:

Cyber Risk into Strategy → Strategy into Action → Action into Resilience → Resilience into Protected Enterprise Value

CICSM® is designed for professionals ready to move beyond managing cybersecurity activities and toward leading cybersecurity as a strategic, measurable, and resilient enterprise capability.

CICSM®

CICSM® Integrated Cybersecurity Management Framework

CICSM® integrates:

  • Strategy + Governance + Risk + Architecture + Cyber Defense + Resilience + Compliance + Technology + Investment + People + Performance + Enterprise Value

Strategy

Establish cybersecurity direction, strategic priorities, operating models, and transformation roadmaps.

Governance

Define accountability, policies, decision rights, oversight structures, and control ownership.

Risk

Identify, prioritize, treat, monitor, and communicate enterprise cyber risk.

Architecture

Govern Zero Trust, IAM, network, cloud, application, data, and infrastructure protection.

Cyber Defense

Lead SOC, threat intelligence, monitoring, detection, vulnerability management, and security operations.

Resilience

Direct incident response, crisis management, recovery, continuity, and organizational resilience.

Compliance

Manage control frameworks, privacy, regulatory requirements, assurance, and third-party obligations.

Technology

Evaluate security platforms, architecture, automation, AI, vendors, and emerging technologies.

Investment

Prioritize resources and cybersecurity programs based on enterprise risk and value.

People

Build teams, define roles, develop capabilities, and strengthen security culture.

Performance

Establish cybersecurity KPIs, KRIs, maturity metrics, and executive reporting.

Enterprise Value

Connect cybersecurity investment with risk reduction, trust, business continuity, resilience, and strategic objectives.

CICSM®

The CICSM®–IBACTP® Advanced Cybersecurity Management Model

The model defines eight integrated leadership dimensions.

1. Cybersecurity Strategy Leadership

Align cybersecurity priorities, maturity, operating models, investments, and transformation with enterprise objectives.

2. Governance, Risk, Compliance, and Executive Oversight

Establish accountability, policies, risk frameworks, privacy, compliance, assurance, and executive oversight.

3. Security Architecture and Technology Governance

Govern Zero Trust, IAM, networks, endpoints, cloud, applications, data, infrastructure, and security platforms.

4. Cyber Defense Leadership

Lead SOC capabilities, detection, threat intelligence, vulnerability management, exposure management, and defensive operations.

5. Incident, Crisis, and Resilience Leadership

Direct incident response, cyber crisis management, recovery, continuity, forensic readiness, and resilience.

6. Investment, Performance, Vendor, and Third-Party Leadership

Prioritize cybersecurity investments, manage vendors, allocate resources, establish KPIs and KRIs, and demonstrate value.

7. AI Security and Emerging Technology Risk Leadership

Govern AI, GenAI, cloud, IoT, OT, DevSecOps, supply chains, and emerging cybersecurity risks.

8. Workforce, Culture, and Transformation Leadership

Build teams, develop talent, strengthen security culture, communicate with executives, and lead organizational transformation.

CICSM®

Tools, Technologies, and Enterprise Security Environments

CICSM® is vendor-neutral and does not depend on mastery of any single cybersecurity product or platform. Instead, cybersecurity managers develop the ability to evaluate, select, integrate, govern, measure, and optimize enterprise security technologies according to organizational risk, architecture, performance, cost, and strategic requirements.

01 / 07

1. Security Operations and Cyber Defense Technologies

CICSM® managers evaluate technologies supporting enterprise monitoring, detection, analysis, and response, including:

Management Focus: Detection coverage, integration, automation, operational effectiveness, scalability, and SOC performance.

  • SIEM
  • SOAR
  • EDR/XDR
  • Threat-intelligence platforms
  • Security analytics
  • Log-management and monitoring platforms
  • Detection and response technologies
02 / 07

2. Identity and Access Security

Managers evaluate technologies supporting secure identity lifecycle and access governance, including:

Management Focus: Least privilege, access governance, privileged access, identity risk, user experience, scalability, and regulatory requirements.

  • IAM
  • MFA
  • SSO
  • Privileged Access Management (PAM)
  • Identity federation
  • Identity Governance and Administration (IGA)
  • Zero Trust access technologies
03 / 07

3. Network, Endpoint, and Infrastructure Security

Managers oversee security capabilities protecting enterprise technology environments, including:

Management Focus: Architecture, control effectiveness, interoperability, resilience, visibility, and risk reduction.

  • Firewalls
  • IDS/IPS
  • Network segmentation
  • Endpoint-security platforms
  • Secure remote access
  • Zero Trust technologies
  • Network-security monitoring
  • Infrastructure-security controls
04 / 07

4. Vulnerability, Exposure, and Configuration Management

Managers govern technologies used to identify, prioritize, and reduce enterprise cyber exposure, including:

Management Focus: Asset visibility, risk-based prioritization, remediation governance, exposure reduction, and performance measurement.

  • Vulnerability scanners
  • Asset discovery and inventory
  • Attack Surface Management (ASM)
  • Exposure-management platforms
  • Configuration-management technologies
  • Patch and remediation-management solutions
05 / 07

5. Cloud, Application, API, and DevSecOps Security

Managers evaluate security capabilities across modern application and cloud environments, including:

Management Focus: Secure cloud adoption, shared responsibility, application risk, integration, development lifecycle security, and cloud governance.

  • Cloud-security platforms
  • CSPM and cloud-security concepts
  • Application-security technologies
  • API security
  • DevSecOps
  • Container and workload security
  • Software supply-chain security
06 / 07

6. Incident Response, Forensics, and Resilience Technologies

Managers oversee technologies supporting organizational response, investigation, recovery, and resilience, including:

Management Focus: Readiness, escalation, evidence preservation, recovery capability, continuity, crisis coordination, and organizational resilience.

  • Incident-management platforms
  • Digital-forensics technologies
  • Case-management systems
  • Backup and recovery technologies
  • Disaster-recovery platforms
  • Business-continuity technologies
  • Crisis-management and communication tools
07 / 07

7. AI, Automation, and Emerging Security Technologies

CICSM® also addresses technologies reshaping cybersecurity management, including:

Management Focus: Security value, AI risk, data protection, human oversight, reliability, integration, governance, and responsible adoption.

  • AI-assisted security analytics
  • Generative AI security tools
  • Automated threat detection
  • AI-assisted SOC capabilities
  • Security orchestration and automation
  • AI governance and monitoring technologies
  • Emerging cyber-defense technologies

Swipe or scroll sideways to see each part →

CICSM®

CICSM® Technology Management Perspective

CICSM® managers are not assessed primarily on their ability to operate individual security products. They are expected to understand how security technologies contribute to the enterprise cybersecurity architecture and risk-management strategy.

The management perspective emphasizes:

Evaluate → Select → Integrate → Govern → Secure → Measure → Optimize

Technology decisions are evaluated through the combined lens of:

Risk + Security Effectiveness + Architecture + Integration + Scalability + Cost + Compliance + Resilience + Enterprise Value

This enables CICSM® professionals to make informed cybersecurity technology decisions without being dependent on a particular vendor, platform, or product ecosystem.

.

CICSM®

CICSM® Framework Application Progression

  • Understand
  • Interpret
  • Assess
  • Prioritize
  • Govern
  • Measure
  • Improve

The objective is to enable CICSM® professionals to translate recognized standards and frameworks into practical governance, risk decisions, security priorities, measurable performance, and stronger enterprise resilience.

Framework alignment does not constitute accreditation, certification, recognition, approval, or endorsement by the organizations responsible for these standards and frameworks.

CICSM®

AI Security and Cybersecurity Management

Artificial Intelligence is both a cybersecurity capability and an enterprise risk.

CICSM® addresses management considerations involving:

  • Enterprise AI inventories
  • Generative AI use
  • AI access control
  • Sensitive-data exposure
  • Prompt injection
  • AI supply-chain risk
  • AI-assisted cyberattacks
  • AI-assisted defensive technologies
  • Model and application vulnerabilities
  • AI monitoring
  • Human oversight
  • AI incident management
  • Responsible AI security
  • CICSM® AI Security Management Cycle
  • Inventory
  • Classify
  • Assess
  • Govern
  • Protect
  • Monitor
  • Respond
  • Improve

The objective is to enable AI innovation without creating unmanaged security and privacy risk.

CICSM®

Enterprise Cyber Resilience Focus

CICSM® prepares managers to establish capabilities involving:

The objective is not simply to prevent incidents.

It is to ensure the organization can withstand, respond to, recover from, and adapt following cyber disruption.

  • Incident readiness
  • Crisis governance
  • Business continuity
  • Disaster recovery
  • Backup resilience
  • Recovery priorities
  • Cyber exercises
  • Executive escalation
  • Communication
  • Post-incident improvement
CICSM®

Cybersecurity Investment and Value

CICSM® prepares managers to translate cybersecurity into business terms.

Managers evaluate:

The objective is to move from:

  • Risk reduction
  • Control effectiveness
  • Budget
  • Resource allocation
  • Technology investment
  • Vendor value
  • Incident avoidance
  • Resilience
  • Regulatory confidence
  • Operational continuity
  • Stakeholder trust
  • Measurable Enterprise Resilience

Cybersecurity Spending

to:

Risk-Informed Security Investment

to:

CICSM®

Executive and Board Communication

CICSM® prepares professionals to communicate cybersecurity in language relevant to organizational leadership.

Managers learn to present:

The goal is to transform technical cybersecurity information into clear executive decision support.

  • Cyber risk
  • Material exposures
  • Strategic priorities
  • Investment requirements
  • Risk acceptance decisions
  • KPIs
  • KRIs
  • Maturity
  • Incident impact
  • Third-party risk
  • Regulatory exposure
  • Cyber resilience
  • Strategic recommendations
CICSM®

Certified International Cybersecurity Manager (CICSM®)

Example:

Jane Smith, CICSM®

The designation represents advanced professional competency in cybersecurity strategy, governance, risk, architecture oversight, cyber defense, resilience, investment, performance, and leadership.

CICSM®

Certified International Cybersecurity Manager (CICSM®)

Credential holders may use the CICSM® designation in accordance with applicable IBACTP® credential-use policies.

Example:

Jane Smith, CICSM®

How long is the CICSM® certification valid?

The recommended CICSM® certification cycle is three years, subject to applicable IBACTP® certification policies.

Credential holders maintain their professional standing through applicable Continuing Professional Education (CPE), professional development, ethics, and recertification requirements.

This helps ensure that certified professionals remain current as cybersecurity technologies, threats, regulations, management practices, and enterprise risks evolve.

What career areas can CICSM® support?

CICSM® can support professional advancement toward roles involving:

Cybersecurity Management • Information Security Management • SOC Leadership • Cyber-Risk Management • Security Governance • Security Architecture Leadership • Incident & Crisis Management • GRC Leadership • Cybersecurity Program Management • Security Consulting • Technology Risk • Cyber Resilience • CISO-Track Leadership

Specific job requirements remain determined by individual employers.

What professional level does CICSM® represent?

CICSM® represents the advanced management and leadership level of the IBACTP® cybersecurity pathway.

Professional Level

CICSP® — Certified International Cybersecurity Professional

Advanced / Management Level

CICSM® — Certified International Cybersecurity Manager

The progression moves from:

Protecting, Detecting, Analyzing, and Responding

to:

Strategizing, Governing, Prioritizing, Measuring, Leading, and Transforming

CICSM®
  • Transform Cyber Risk into Strategy
  • Strategy into Action
  • Action into Resilience
  • Resilience into Protected Enterprise Value

CICSM® is designed for professionals ready to move beyond managing individual cybersecurity activities and toward leading cybersecurity as a strategic, measurable, resilient, and enterprise-wide capability.

Here is a stronger, more polished closing CTA section for the CICSM® landing page.

CICSM®

Certified International Cybersecurity Manager (CICSM®)

  • Govern Cyber Risk. Lead Cyber Defense. Build Resilience. Protect Enterprise Value.

Offered by the

International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

Assess → Strategize → Govern → Prioritize → Defend → Respond → Measure → Lead → Transform

Lead Cybersecurity with Strategy. Govern with Confidence. Build Enterprise Resilience.

CICSM®

CICSM®

Certified International Cybersecurity Manager

Focus:

Strategize • Govern • Prioritize • Defend • Measure • Lead • Transform

Professional Progression

Protect and Defend → Govern and Lead → Build Enterprise Cyber Resilience

CICSM®

CICSM®

Certified International Cybersecurity Manager

The progression moves from:

  • Strategizing, Governing, Leading, and Transforming Enterprise Cybersecurity

Protecting and Defending Technology Environments

to:

CICSM®

Start Your CICSM® Journey

Choose the pathway that aligns with your experience and professional objectives.

  • APPLY NOW →
  • REGISTER FOR THE CICSM® EXAM →
  • ENROLL IN CICSM® TRAINING →
  • Strategy → Cyber Risk → Governance → Architecture → Cyber Defense → Resilience → Investment → Performance → Transformation
  • EXPLORE THE CICSM® CAPSTONE →
  • DOWNLOAD THE CICSM® PROGRAM GUIDE →

Apply for CICSM® Certification

Ready to demonstrate advanced cybersecurity management and leadership competency?

Begin your application for the Certified International Cybersecurity Manager (CICSM®) designation.

Register for the CICSM® Certification Examination

Already prepared to demonstrate your advanced competency?

Complete the CICSM® examination pathway and demonstrate your ability to make strategic, governance, risk, architecture, cyber-defense, resilience, investment, and leadership decisions.

Enroll in Advanced CICSM® Training

Develop the advanced capabilities required to manage cybersecurity as an enterprise function.

Training addresses eight integrated management domains spanning strategy, governance, risk, architecture, cyber defense, resilience, investment, AI security, workforce leadership, and organizational transformation.

Choose the Enterprise Cybersecurity Management Capstone

Prefer an applied management pathway?

Eligible instructor-led candidates may demonstrate advanced competency through the CICSM® Enterprise Cybersecurity Management Capstone.

Develop an integrated enterprise solution addressing:

Download the CICSM® Certification Guide

Explore the complete advanced certification framework, including:

  • Certification requirements and eligibility
  • CICSM® Body of Knowledge
  • Eight management competency domains
  • Course learning outcomes
  • Certification testing outcomes
  • Applied management labs
  • Examination and Capstone pathways
  • International standards and framework alignment
  • Credentialing quality framework
  • Professional ethics
  • Continuing Professional Education
  • Recertification requirements
  • CICSP® → CICSM® progression
CICSM®

Ready to Lead Enterprise Cybersecurity?

Move Beyond Managing Security Controls. Lead Cybersecurity as an Enterprise Capability.

Modern organizations need cybersecurity leaders who can connect technology, risk, governance, resilience, investment, people, and business strategy.

CICSM® prepares professionals to lead the decisions that shape enterprise cybersecurity.

Develop the Leadership Competency to:

  • Set Enterprise Cybersecurity Strategy
  • Govern Cyber Risk and Compliance
  • Lead Security Architecture and Zero Trust
  • Direct SOC Operations and Cyber Defense
  • Manage Major Cyber Incidents and Crises
  • Strengthen Business Continuity and Cyber Resilience
  • Prioritize Cybersecurity Investments and Resources
  • Govern AI Security and Emerging Technology Risk
  • Manage Vendors and Third-Party Cyber Risk
  • Build and Lead High-Performing Cybersecurity Teams
  • Measure Cybersecurity Performance and Enterprise Value
  • Communicate Cyber Risk to Executives and Boards
CICSM®

Become CICSM® Certified

Advance from cybersecurity operations to strategy, governance, leadership, and enterprise transformation.

APPLY NOW →

Start your application for the CICSM® professional designation.

REGISTER FOR THE CICSM® EXAM →

Ready to demonstrate your advanced cybersecurity management competency?

ENROLL IN ADVANCED CICSM® TRAINING →

Build competency across all eight CICSM® cybersecurity management domains.

EXPLORE THE MANAGEMENT CAPSTONE →

Demonstrate advanced competency through an applied enterprise cybersecurity management project.

DOWNLOAD THE CICSM® PROGRAM GUIDE →

Explore the complete Body of Knowledge, eligibility requirements, curriculum, assessment pathways, standards alignment, and certification requirements.

The examination

Exam & Certification Details

Everything you need to plan your sitting.

CICSM-200

Exam code for the Advanced Manager-level Cybersecurity credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of five years of experience, including two years in a supervisory, lead or management role.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CICSM® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
Questions

Frequently Asked Questions — CICSM®

The following frequently asked questions provide an overview of the Certified International Cybersecurity Manager (CICSM®) certification, including its purpose, target audience, competency areas, assessment pathways, technology coverage, professional progression, and credential maintenance.

What is CICSM®?

The Certified International Cybersecurity Manager (CICSM®) is an advanced, vendor-neutral professional certification designed to validate the strategic, managerial, governance, risk, analytical, and leadership competencies required to manage cybersecurity as an enterprise capability.

CICSM® focuses on the responsibilities of cybersecurity leaders who must connect technical security with business objectives, enterprise risk, governance, investment, resilience, workforce capability, and executive decision-making.

The certification covers major leadership areas including:

Cybersecurity Strategy • Governance • Enterprise Cyber Risk • Security Architecture • Zero Trust • Cyber Defense • SOC Leadership • Vulnerability & Exposure Management • Incident & Crisis Management • Cyber Resilience • Security Investment • Third-Party Risk • AI Security • Performance Management • Workforce Leadership • Executive Communication

Who is CICSM® designed for?

CICSM® is designed for experienced cybersecurity, technology, risk, governance, and management professionals seeking to develop or validate advanced enterprise cybersecurity leadership capabilities.

The certification may be particularly relevant to:

CICSM® is also suitable for professionals transitioning from senior technical cybersecurity roles into management and leadership responsibilities.

  • Cybersecurity Managers
  • Information Security Managers
  • SOC Managers and Security Operations Leaders
  • Cyber-Risk and GRC Managers
  • Security Architects
  • Incident Response Managers
  • Cloud and Infrastructure Security Leaders
  • IT and Technology Managers
  • Cybersecurity Program Managers
  • Security Consultants
  • Governance and Compliance Professionals
  • Technology Risk Leaders
  • Aspiring CISOs and security executives
How is CICSM® different from CICSP®?

CICSP® and CICSM® represent two different levels of the IBACTP® cybersecurity certification pathway.

CICSP® — Professional Level

The Certified International Cybersecurity Professional (CICSP®) focuses primarily on applying cybersecurity knowledge and supporting the protection, monitoring, detection, analysis, response, recovery, and governance of technology environments.

CICSM® — Advanced / Management Level

The Certified International Cybersecurity Manager (CICSM®) focuses on leading cybersecurity at the organizational level through strategy, governance, prioritization, investment, risk management, architecture oversight, cyber-defense leadership, resilience, workforce management, and executive communication.

The progression can be summarized as:

CICSM®: Assess → Strategize → Govern → Prioritize → Measure → Lead → Transform

CICSP®: Protect → Detect → Analyze → Respond → Recover

Do I need CICSP® before pursuing CICSM®?

CICSP® provides the recommended professional pathway into CICSM® because it establishes broad cybersecurity competency before progression into advanced management and leadership.

Candidates possessing equivalent education, professional cybersecurity experience, information-security experience, technology-management experience, risk-management experience, or other qualifying professional backgrounds may satisfy applicable CICSM® eligibility requirements in accordance with current IBACTP® certification policies.

However, CICSP® is not necessarily the only pathway.

Is CICSM® vendor-neutral?

CICSM® is designed around transferable cybersecurity management competencies rather than a particular technology vendor, cloud provider, SIEM platform, firewall manufacturer, endpoint product, or security ecosystem.

Candidates are expected to understand how to:

security technologies according to organizational requirements, architecture, cyber risk, cost, scalability, interoperability, resilience, and enterprise value.

  • Yes.
  • Evaluate → Select → Integrate → Govern → Measure → Optimize
Does CICSM® cover enterprise cyber-risk management?

Yes. Enterprise cyber-risk management is a core CICSM® competency.

Candidates learn to evaluate:

The management emphasis is on transforming technical cybersecurity information into risk-informed enterprise decisions.

  • Cyber-risk identification and assessment
  • Threat and vulnerability information
  • Asset criticality
  • Business impact
  • Risk appetite and tolerance
  • Risk treatment
  • Residual risk
  • Risk acceptance and escalation
  • Control effectiveness
  • Cyber-risk indicators
  • Third-party risk
  • Emerging technology risk
  • Executive risk reporting
Does CICSM® cover cybersecurity governance?

CICSM® addresses governance structures, decision rights, policies, standards, accountability, oversight, control frameworks, assurance, risk ownership, compliance responsibilities, and executive reporting.

Candidates learn how cybersecurity governance establishes clear relationships among:

Authority → Accountability → Risk → Controls → Performance → Executive Oversight

Yes.

Does CICSM® cover security architecture and Zero Trust?

CICSM® addresses security architecture from a management and governance perspective.

Coverage includes:

Managers are expected to evaluate whether architecture and technology decisions appropriately support enterprise risk, business requirements, scalability, resilience, and security objectives.

Yes.

  • Enterprise security architecture
  • Zero Trust
  • IAM
  • Privileged access
  • Network security
  • Segmentation
  • Endpoint security
  • Application and API security
  • Cloud security
  • Data protection
  • Infrastructure security
  • Security platforms
  • Architectural integration
  • Technology modernization
Does CICSM® cover SOC leadership and cyber defense?

CICSM® addresses the strategic and managerial aspects of Security Operations Centers and enterprise cyber defense.

Topics include:

The focus is not simply on operating SOC technologies, but on governing and improving the effectiveness of enterprise detection and defensive capabilities.

Yes.

  • SOC strategy and operating models
  • Security monitoring
  • SIEM
  • SOAR
  • EDR/XDR
  • Threat intelligence
  • Detection capabilities
  • Alert management
  • Threat hunting
  • Escalation processes
  • SOC workforce
  • Automation
  • Cyber-defense performance
  • Security operations metrics
Does CICSM® cover vulnerability and exposure management?

CICSM® addresses vulnerability management as an enterprise risk-management capability.

Candidates evaluate vulnerability findings in the context of:

Severity + Exploitability + Threat Intelligence + Asset Criticality + Business Impact + Existing Controls + Enterprise Exposure

Coverage includes vulnerability management, attack-surface management, asset visibility, remediation governance, configuration risk, exposure management, remediation priorities, exceptions, and performance measurement.

Yes.

Does CICSM® cover incident response and cyber-crisis management?

CICSM® addresses cybersecurity incidents from a management, governance, escalation, and enterprise-resilience perspective.

Coverage includes:

Managers learn to distinguish between a technical security event, cybersecurity incident, major incident, and enterprise cyber crisis, and to determine the appropriate level of organizational response.

Yes.

  • Incident-response governance
  • Incident classification
  • Severity determination
  • Escalation criteria
  • Executive decision-making
  • Crisis-management structures
  • Containment priorities
  • Investigation oversight
  • Legal and regulatory coordination
  • Stakeholder communication
  • Executive and board communication
  • Recovery
  • Business continuity
  • Disaster recovery
  • Post-incident review
  • Cyber resilience
Does CICSM® cover business continuity and cyber resilience?

CICSM® recognizes that cybersecurity leadership extends beyond prevention and detection.

Candidates examine how incident response integrates with:

The objective is to ensure that organizations can prepare for, withstand, respond to, recover from, and adapt following significant cyber disruption.

Yes.

  • Business continuity
  • Disaster recovery
  • Critical business services
  • Recovery priorities
  • Technology dependencies
  • Backup and restoration
  • Crisis management
  • Recovery validation
  • Cyber exercises
  • Resilience measurement
  • Lessons learned
Does CICSM® cover AI and Generative AI security?

Managers examine governance and cybersecurity considerations involving:

The emphasis is on helping managers integrate AI security into existing cybersecurity governance, enterprise risk, privacy, architecture, incident management, and technology-management processes.

Yes. AI security is an important component of CICSM®.

  • Enterprise AI inventories
  • Generative AI
  • Large Language Models
  • AI agents
  • Prompt injection
  • Sensitive-data exposure
  • AI identity and access controls
  • Model and application vulnerabilities
  • AI supply-chain risk
  • Third-party AI services
  • AI-assisted cyberattacks
  • AI-assisted cyber defense
  • Security automation
  • AI monitoring
  • Human oversight
  • AI incident management
  • Responsible AI security
Does CICSM® cover privacy and compliance?

CICSM® examines the relationship between cybersecurity, privacy, compliance, risk, and organizational accountability.

Candidates learn to evaluate privacy and compliance requirements as part of broader cybersecurity governance rather than treating them as isolated administrative functions.

Yes.

Does CICSM® address third-party and supply-chain cyber risk?

Modern organizations depend extensively on vendors, cloud providers, technology partners, managed services, software suppliers, contractors, and other external parties.

CICSM® therefore addresses:

Managers learn to evaluate third-party cybersecurity as an extension of enterprise risk.

Yes.

  • Third-party risk assessment
  • Vendor cybersecurity requirements
  • Due diligence
  • Contractual security requirements
  • External access
  • Cloud and service-provider risk
  • Software supply-chain exposure
  • Concentration risk
  • Continuous monitoring
  • Vendor performance
  • Incident notification
  • Third-party resilience
  • Exit and transition considerations
Does CICSM® cover cybersecurity investment and budgeting?

CICSM® prepares managers to evaluate cybersecurity initiatives as enterprise investments.

Candidates learn to consider:

The objective is to help managers answer not simply “What security technology can we buy?” but “Which cybersecurity investments provide the greatest strategic and risk-management value?”

Yes.

  • Cybersecurity business cases
  • Budget priorities
  • Resource allocation
  • Risk reduction
  • Capability maturity
  • Regulatory requirements
  • Technology lifecycle
  • Total cost considerations
  • Vendor alternatives
  • Operational effectiveness
  • Benefits realization
  • Enterprise value
Does CICSM® include cybersecurity metrics and performance management?

Candidates examine:

Effective CICSM® reporting focuses on translating technical information into risk, performance, resilience, and business impact.

  • Yes.
  • CICSM® emphasizes measurable cybersecurity management.
  • Key Performance Indicators (KPIs)
  • Key Risk Indicators (KRIs)
  • Security operations metrics
  • Vulnerability and remediation metrics
  • Incident metrics
  • Control-effectiveness measures
  • Maturity indicators
  • Resilience measures
  • Investment-performance measures
  • Risk trends
  • Executive dashboards
  • Board-level cybersecurity reporting
Does CICSM® cover executive and board communication?

Cybersecurity managers must be able to communicate complex technical risks in language appropriate for organizational leadership.

CICSM® develops the ability to communicate:

Risk Exposure • Business Impact • Strategic Priorities • Investment Requirements • Incident Severity • Performance • Resilience • Decision Options

The objective is to support informed executive and board-level cybersecurity decisions.

Yes.

Does CICSM® cover cybersecurity workforce leadership?

CICSM® addresses the people and organizational dimensions of cybersecurity management, including:

Cybersecurity leadership requires effective management of people, capabilities, culture, and change, not only technologies.

Yes.

  • Organizational structures
  • Cybersecurity roles
  • Workforce planning
  • Skills assessment
  • Capability gaps
  • Professional development
  • Team leadership
  • Talent development
  • Security culture
  • Awareness
  • Stakeholder engagement
  • Change management
  • Professional ethics
  • Organizational transformation
What technologies are covered in CICSM®?

CICSM® addresses major categories of enterprise cybersecurity technologies, including:

SIEM • SOAR • EDR/XDR • IAM • MFA • SSO • PAM • Firewalls • IDS/IPS • Vulnerability Management • Attack-Surface Management • Cloud Security • CSPM • Application Security • API Security • DevSecOps • Container Security • Threat Intelligence • Incident Management • Digital Forensics • Backup & Recovery • AI-Assisted Security

Because CICSM® is vendor-neutral, the emphasis is on selection, architecture, integration, governance, risk, cost, performance, and value rather than operation of a specific product.

How many CICSM® modules are included?

The CICSM® Body of Knowledge is organized around eight advanced management domains:

Together, these domains provide an integrated framework for enterprise cybersecurity leadership.

  • Enterprise Cybersecurity Strategy and Organizational Alignment
  • Governance, Risk, Compliance, and Executive Oversight
  • Security Architecture and Technology Governance
  • Cyber Defense, Threat, Vulnerability, and Exposure Management
  • Incident, Crisis, Recovery, and Resilience Management
  • Cybersecurity Investment, Performance, Vendor, and Third-Party Management
  • AI, Privacy, and Emerging Cyber Risk
  • Cybersecurity Leadership, Workforce, and Transformation
How is CICSM® assessed?

CICSM® provides two assessment pathways.

Option 1 — CICSM® Certification Examination

Candidates may demonstrate advanced management competency through a secure certification examination consisting of advanced multiple-choice and scenario-based questions.

The assessment emphasizes:

Strategy • Governance • Risk Judgment • Architecture Decisions • Cyber Defense Leadership • Incident Decisions • Investment Prioritization • Executive Leadership

Option 2 — Enterprise Cybersecurity Management Capstone

Eligible candidates participating through an approved instructor-led pathway may demonstrate competency through the CICSM® Enterprise Cybersecurity Management Capstone.

The Capstone requires candidates to integrate strategy, governance, cyber risk, architecture, operations, resilience, investment, workforce, and executive recommendations within an applied enterprise scenario.

Is CICSM® practical or primarily theoretical?

CICSM® emphasizes managerial application and professional judgment.

Candidates are expected to evaluate realistic cybersecurity situations, compare alternatives, prioritize actions, assess tradeoffs, interpret risk, make management recommendations, and justify decisions.

The management progression is:

How long is the recommended CICSM® training?

The recommended CICSM® program consists of approximately 60 instructional hours.

Actual duration may vary according to training format, delivery schedule, practical management labs, Capstone activities, and the approved training provider.

Is CICSM® aligned with recognized international frameworks?

CICSM® incorporates principles and practices relevant to enterprise cybersecurity management from recognized frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005, ISO/IEC 27701, ISO 31000, ISO/IEC 42001, ISO/IEC 23894, the NIST Cybersecurity Framework, NIST NICE Workforce Framework, NIST AI RMF, and relevant NIST and CISA cybersecurity guidance.

CICSM® emphasizes applying these frameworks to management and governance decisions rather than memorizing standards.

Is CICSM® accredited by ANAB, NCCA, or another external organization?

The CICSM® certification framework incorporates credentialing-quality principles associated with ISO/IEC 17024, ANAB, NCCA, I.C.E., and international personnel-certification practices.

However, alignment with these principles does not itself constitute accreditation, endorsement, recognition, or approval.

IBACTP® represents CICSM® as formally accredited or recognized by an external organization only after such status has been officially awarded by the applicable authorized body.

Is CICSM® internationally applicable?

CICSM® is designed as a vendor-neutral and internationally applicable cybersecurity management certification.

Its competencies focus on transferable areas of cybersecurity strategy, governance, risk, architecture, operations, resilience, technology management, and leadership that can be applied across industries and organizational environments.

Recognition or acceptance of any credential remains subject to individual employer, institutional, governmental, regulatory, and jurisdictional requirements.

What designation do successful candidates earn?

Candidates who successfully satisfy applicable certification requirements earn the professional designation:

28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission