* Dual Certification Program *

Summary | Cost | Why ISLF | Who | Objectives | What You Get | Notes | Agenda | Exam


CISPCM Cert Badge PrintThe Certified Information Security Program Compliance Manager (CISPCM™) course is a three-day information packed learning experience designed to develop a level of competence to support the internal and external compliance management of an organizational Information Security Program for defined controls under ISO 27001, as well as additionally mandated control under the mandatory Legal & Regulatory review requirement of the standard. Drawing upon best practices from ISO 27001 and ISO 19011, students will learn the fundamental requirements to build internal compliance and audit programs and perform a certification audit.

To develop a well rounded understanding of the standard’s expectations, students will be familiarized with the supplementary guidance offered by ISO using ISO 17021, ISO 27024 ,ISO 27002, ISO 27006, ISO 27007, and more.


The course will be offered as an intense three-day course at ISLF Chapter conferences. For specific dates and locations, please refer Events > 2017 Conferences > (available locations), from the main menu on our site.

Why ISLF Training

The Certified Information Security Governance Leader training’s development was led by experienced international ISO certified instructors with years of implementation, audit as well as, training development and delivery experience. The ISLF training program is unique in that the ISLF establishes the training and certification scheme, and the training material. How do we differ from other offerings you might find out on the market:

  • We offer high-demand certification training at accessible prices
  • Our training courses are based on an official study guide
  • We minimize out of office time, by offering pre-course reading assignments, and allowing students to complete their exams fully online after the training, at the comfort of your own home or office.
  • Courses are developed based on standards developed by the ISLF, which includes a course training standard (scheme) and exams.
  • Our industry leading exam pass guarantee – If you don’t pass, you can attend another session of the course within the next 12 months for free to help you get prepared to rewrite the exam.
  • Our instructors go through a rigorous screening and training process, resulting in the assignment of the credential as an ISLF Certified Instructors


Who Should Take This Course?

  • Compliance Managers and staff seeking to incorporate Information Security within the scope of their holistic compliance program, and demonstrate required competence for the purposes of ISO 27001 certification.
  • Auditor Managers and Auditors seeking to incorporate Information Security within the scope of their holistic audit program, and demonstrate required competence for the purposes of ISO 27001 certification.
  • Information Security professionals and managers involved in any aspect of the development, roll-out or operational maintenance of an Information Security Program.
  • IT Managers and professionals, Project Managers, and consultants wanting to prepare and to support an organization in the implementation or maintenance of an Information Security Program.
  • Auditors who want to understand and be able to demonstrate competence in an Information Security Management System implementation
  • Persons responsible for information security or its conformity in an organization
  • Consultants looking to understand and support clients implementing and information security management system and specifically the strategy and policy & standards components.
  • Corporate / industrial / physical security specialists
  • Technical experts wanting to prepare for an Information Security management function or for an information security project management role
  • Attorneys supporting the legal aspects of an information security program


Learning Objectives

  • Understand the requirements for information security compliance (including internal and external audit) mandated by the ISO 27001standard, including those mandated under legal and regulatory requirements, and general best practices.
  • Master the concepts, approaches, standards, methods and techniques required for the effective planning, design, development, implementation and maintenance of information security compliance.
  • Understand how to engage stakeholders in the process to secure their buy-in and support.
  • Develop the expertise to identify legal and legislative requirements mandated for your organization’s compliance.
  • Master the approach to collate and organize the high volume of requirements, and develop a structured compliance framework to build upon.


What You Get!

Students will receive:

  1. a copy of all slides presented during the class, in electronic format;
  2. a certificate of completion awarding 27 Continuing Professional Development (CDP) units;
  3. A Student Information Package (SIP) with study tips and other helpful and insightful information for the course and exam; and
  4. An exam and certification application voucher.



  • Student are prohibited from recording any session(s).
  • Prior to the course, students will be enrolled by their assigned instructor in the ISLF’s Learning Center and receive per-course reading assignments. It will be assumed at the beginning of the course, these reading assignments have been completed.
  • All student material for this course will be provided in electronic format. All material will be sent to the student prior to the first day of the course. Due to courses being continually updated, it is typically delivered within the two weeks prior to the course commencement.

AgendaCourse Agenda

Day 1 – Introduction and Planning for the Audit and Certification of an Information Security Management System (ISMS) based on ISO 27001

  • Normative, regulatory and legal framework related to information security
  • Fundamental principles of information security
  • The ISO 27001 certification process
  • The Information Security Management System (ISMS)
  • Detailed presentation of the clauses 4 to 8 of the ISO 27001 standard
  • Fundamental audit concepts and principles
  • Audit approach based on evidence and on risk
  • Preparation of an ISO 27001 certification audit
  • Documenting of an ISMS audit
  • Conducting an opening meeting

Day 2Conducting an ISO 27001 Audit

  • Communication during the audit
  • Audit procedures: observation, document review, interview, sampling techniques, technical verification, corroboration and evaluation
  • Drafting test plans
  • Formulation of audit findings
  • Drafting of nonconformity reports

Day 3 – Concluding and ensuring the follow-up of an ISO 27001 audit

  • Audit documentation
  • Quality review
  • Conducting a closing meeting and conclusion of an ISO27001 audit
  • Evaluation of corrective action plans
  • Surveillance audit
  • Audit management program
  • Internal audit and second party audit


Exams are administered online, following the training. Our online proctored exams are available 24 hours a day, seven (7) days week for your convenience. After the course is complete, you will receive information by e-mail explaining the online exam proctoring process and the web page to log in, as well as other relevant information. The exam must be taken within 90 days from completion of the course.

Already certified in the development of information security strategy and policy & standards? If you have an existing certification with another recognized certification authority covering both of these topics and would like to convert over to an ISLF certification, you may elect to challenge our exam for a free of $30 + $100 for your first year’s certification maintenance fee.

Have the experience but no training, and want to challenge the exam? If you already meet the certification experience criteria and want to challenge the exam, we’re happy to accommodate.  You can purchase an exam voucher and application fee and sit for an exam without taking the training. We strongly recommend, before taking this option, you purchase a copy of the course study guide and review it in detail, after it published and available for purchase.