🇬🇧 United Kingdom · IT
CISMP (Certificate in Information Security Management Principles) Syllabus
BCS-awarded UK entry-level information security qualification, popular for government and public-sector roles.. The complete CISMP (Certificate in Information Security Management Principles) outline — 7 subjects, 22 chapters and 81 topics — laid out so you can see exactly what has to be covered and tick each item off as you go.
CISMP (Certificate in Information Security Management Principles) subjects
Each subject below has its own page with the full chapter → topic → sub-topic tree and a set of real exam-style flashcards.
3 chapters · 12 topics · 27 sub-topics
Information Risk Management3 chapters · 12 topics · 18 sub-topics
Information Security Frameworks, Law and Compliance3 chapters · 11 topics · 20 sub-topics
Procedural and People Security Controls3 chapters · 9 topics · 17 sub-topics
Technical Security Controls4 chapters · 15 topics · 26 sub-topics
Physical, Environmental and Operational Security3 chapters · 10 topics · 14 sub-topics
Business Continuity, Incident Management and Assurance3 chapters · 12 topics · 18 sub-topics
CISMP (Certificate in Information Security Management Principles) flashcard decks
387 question-and-answer cards across 7 decks, written against this syllabus. Preview any deck free.
- Information Security Management Principles and Concepts — 50 cards
- Information Risk Management — 51 cards
- Information Security Frameworks, Law and Compliance — 50 cards
- Procedural and People Security Controls — 51 cards
- Technical Security Controls — 73 cards
- Physical, Environmental and Operational Security — 51 cards
- Business Continuity, Incident Management and Assurance — 61 cards
How to work through the CISMP (Certificate in Information Security Management Principles) syllabus
The outline on this page is arranged the way the syllabus itself is: subject, then chapter, then topic, then sub-topic. That last level is what most study plans skip, and it is where coverage actually goes wrong — a chapter marked "done" often has three sub-topics inside it that were never touched.
Weight your plan accordingly: Technical Security Controls carries 15 topics while Procedural and People Security Controls carries 9. Giving both the same number of weeks is the most common planning mistake for CISMP (Certificate in Information Security Management Principles).
The ~90 hour estimate above is a first pass only: roughly 45 minutes per topic plus 12 minutes per sub-topic. Revision cycles, past papers and mocks sit on top of that number.
CISMP (Certificate in Information Security Management Principles) syllabus FAQ
What subjects are in the CISMP (Certificate in Information Security Management Principles) syllabus?
CISMP (Certificate in Information Security Management Principles) covers 7 subjects: Information Security Management Principles and Concepts, Information Risk Management, Information Security Frameworks, Law and Compliance, Procedural and People Security Controls, Technical Security Controls, Physical, Environmental and Operational Security and Business Continuity, Incident Management and Assurance. Together they contain 22 chapters and 81 named topics.
How many topics does the CISMP (Certificate in Information Security Management Principles) syllabus contain?
The full CISMP (Certificate in Information Security Management Principles) outline breaks down into 22 chapters, 81 topics and 140 sub-topics. Technical Security Controls is the largest single subject with 15 topics across 4 chapters.
How long does it take to cover the whole CISMP (Certificate in Information Security Management Principles) syllabus?
Roughly 90 hours for one full pass. That estimate allows about 45 minutes per topic plus 12 minutes per sub-topic, so it is first-pass coverage — revision, past papers and mock tests sit on top of it. At 3 hours a day that is about 4 weeks.
Are there CISMP (Certificate in Information Security Management Principles) flashcards?
Yes — 387 question-and-answer flashcards across 7 decks, one per subject, written against this syllabus. A sample of every deck is readable on this site for free, and the complete decks are in the Examius app.
Is this CISMP (Certificate in Information Security Management Principles) syllabus free to use?
Yes. Every page here is free to read, and importing the CISMP (Certificate in Information Security Management Principles) syllabus into the Examius app to tick off topics as you finish them is free too, in United Kingdom and everywhere else. No account is needed to start.
Related IT syllabuses
BCS (The Chartered Institute for IT) professional registration recognising senior IT practitioners in the UK.
CompTIA A+ / Network+ / Security+ syllabusVendor-neutral foundational IT certifications widely used in the UK for support, networking and cybersecurity roles.
ITIL Foundation syllabusAxelos/PeopleCert certification in IT service management best practice, widely required in UK IT operations.
Microsoft Azure Certifications (e.g. AZ-104, AZ-900) syllabusMicrosoft's role-based cloud certifications for administering and architecting solutions on Azure.
AWS Certified Solutions Architect syllabusAmazon Web Services certification validating skills in designing distributed systems on AWS.
Certified Ethical Hacker (CEH) syllabusEC-Council certification for penetration testing and ethical hacking skills.
Certified Information Security Manager (CISM) syllabusISACA certification focused on information security management and governance.
Certified Information Systems Auditor (CISA) syllabusISACA certification for professionals who audit, control, and assess information systems.
Certified Information Systems Security Professional (CISSP) syllabusISC2 advanced certification for experienced information security professionals.