Professional track
Information Security Manager
Develop the capability to implement, manage and continuously improve an effective Information Security Management System aligned with ISO/IEC 27001
Make information security part of everyday management
By embedding risk-based thinking, governance and operational controls into normal management processes, this track shows how an ISMS remains effective, usable and resilient over time.
Overview
What this track is about
This track prepares you to build, operate and continuously improve an Information Security Management System (ISMS) in line with ISO/IEC 27001 and related standards. You develop the skills to manage risk, design controls, align stakeholders and keep the system effective beyond the initial certification project.
The Information Security Manager Track is designed for professionals who are responsible for establishing and running an Information Security Management System (ISMS) in their organisation. Rather than focusing only on “implementation projects”, this programme covers the full lifecycle: from understanding context and risk through to day-to-day operation, performance evaluation and continual improvement.
Audience
Who it is for
The Information Security Manager Track prepares professionals to design, implement, operate, and improve Information Security Management Systems (ISMS) aligned with ISO 27001.
Practitioners, implementers, and consultants involved in the design, implementation, or improvement of information security management systems (ISMS) aligned with ISO/IEC 27001
Individuals with project or overall responsibility for establishing or evolving an information security management system
Current or aspiring information security managers, ISMS managers, or system owners responsible for operating and steering an existing ISMS
Members of information security, risk, or governance teams who play an active role in shaping, evolving, and continually improving information security management practices
Outcomes
Learning outcomes
4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.
Design and build an ISMS that actually works
Translate ISO/IEC 27001 into practical, organisation-specific governance and processes
Integrate information security coherently into the organisation’s existing management systems
Take ownership of information security governance
Define roles, responsibilities and decision rights for information security
Position information security clearly within management and operational decision-making
Manage information security risks and performance
Identify and assess information security risks before they turn into incidents or audit findings
Define monitoring and controls that provide management with meaningful security information
Lead audits and improvement with confidence
Prepare and support internal and external ISMS audits professionally
Use audit results, incidents and performance data to drive targeted improvements
Professional positioning
Establish a recognised competence profile as Information Security Manager, with a foundation for senior security roles in ISO 27001-based organisations
Take responsibility for the implementation of a new ISMS or the coordination of an existing system
Act as a competent counterpart to senior management, clients, auditors and certification bodies
Credentials
Scalable credential model
Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.
Core credential
Diploma in Management System Management
Cross-domain management system foundation: the 19 core modules
Applicable across every ISO standard we teach
Reusable across every further specialisation in the same role
Specialisation credential
Halderstone Certified Information Security Manager
Domain competence in information security
Translation of generic management system concepts to information security
Aligned with ISO/IEC 27001 requirements
Registered credentials
Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.
Registered credentials: Halderstone Certified Information Security Manager
The following Registered credentials can be applied for:
Registered Associate Manager in Information Security Management
Registered Professional Manager in Information Security Management
Registered Lead Manager in Information Security Management
Registered Senior Lead Manager in Information Security Management
Application requires meeting the experience requirements for the respective level.
For employers
How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.
Track price
CHF 10,000
All 23 modules, the capstone and the examination
No VAT is charged.
Start with a single module at any time · credited in full if you continue
Bought from us before? Sign in to see the modules you already hold.
Track facts
- Track ID
- HAT-IS-M
- Discipline
- Information Security
- ISO standard
- ISO/IEC 27001
- Target audience
- Management System Manager
Modular approach
The core carries into every discipline
The 19 core modules are the same in every manager track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about information security.
Core modules
Manager capabilities across disciplines
19 modules · shared by every manager track
Awarded as the Diploma in Management System Management: the credential you keep whichever discipline you specialise in.
Specialisation · 3–5 modulesHighlighted: this track
A second manager track is 3–5 modules, not 23
Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.
Curriculum
How the modules fit together
Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.
Core
Shared with every manager track. Complete them once and they count towards any further qualification in the same role.
Information Security Management
These modules carry the same management system work into ISO/IEC 27001. The method does not change; the material does. What is at stake, which controls are proportionate and which obligations bind are specific to the standard, and so are the judgements that go with them. The aim is a system the organisation runs, not one it maintains for the certificate.
The capstone engagement
Practical application of the learned ISMS competencies
Demonstrates ability tackle a concrete information security management challenge in a real-world scenario
Based on case proposed by the candidate or provided by Halderstone
The final examination
Confirms solid and actionable understanding of information security management principles
Assesses the ability to design, implement and manage an ISMS based on ISO/IEC 27001 requirements
Covers all core and specialization modules of the track
Method
How you learn it
Two things separate knowing a standard from being able to run a management system to it: what is trained, and what it is trained on.
Practical reflexes, not topics covered
Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.
Three examples from this track’s modules:
Real ownership and escalation
Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.
Residual exposure and explicit acceptance
See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.
Risk criteria and acceptance authority
Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.
Trained on one organisation
Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.
One organisation, carried across modules
Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.
It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones
Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in
Why it matters
Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.
Related track
The same discipline, the other role
The same discipline is taught from the auditor’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.
Track price
CHF 10,000
23 modules, the capstone and the examination
Getting it signed off
Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.
Not sure this is the one?
Start with a single module and have it credited in full later. If the work is assessing other people’s systems rather than running your own, the auditor track is the one. Tell us the situation and we will say which, honestly.