Professional track

Information Security Manager

Develop the capability to implement, manage and continuously improve an effective Information Security Management System aligned with ISO/IEC 27001

ManagerInformation SecurityISO/IEC 27001
Information security managers reviewing systems in a professional office setting, representing leadership and governance of an information security management system.

Make information security part of everyday management

By embedding risk-based thinking, governance and operational controls into normal management processes, this track shows how an ISMS remains effective, usable and resilient over time.

Overview

What this track is about

This track prepares you to build, operate and continuously improve an Information Security Management System (ISMS) in line with ISO/IEC 27001 and related standards. You develop the skills to manage risk, design controls, align stakeholders and keep the system effective beyond the initial certification project.

The Information Security Manager Track is designed for professionals who are responsible for establishing and running an Information Security Management System (ISMS) in their organisation. Rather than focusing only on “implementation projects”, this programme covers the full lifecycle: from understanding context and risk through to day-to-day operation, performance evaluation and continual improvement.

Audience

Who it is for

The Information Security Manager Track prepares professionals to design, implement, operate, and improve Information Security Management Systems (ISMS) aligned with ISO 27001.

Practitioners, implementers, and consultants involved in the design, implementation, or improvement of information security management systems (ISMS) aligned with ISO/IEC 27001

Individuals with project or overall responsibility for establishing or evolving an information security management system

Current or aspiring information security managers, ISMS managers, or system owners responsible for operating and steering an existing ISMS

Members of information security, risk, or governance teams who play an active role in shaping, evolving, and continually improving information security management practices

Outcomes

Learning outcomes

4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.

01

Design and build an ISMS that actually works

Translate ISO/IEC 27001 into practical, organisation-specific governance and processes

Integrate information security coherently into the organisation’s existing management systems

02

Take ownership of information security governance

Define roles, responsibilities and decision rights for information security

Position information security clearly within management and operational decision-making

03

Manage information security risks and performance

Identify and assess information security risks before they turn into incidents or audit findings

Define monitoring and controls that provide management with meaningful security information

04

Lead audits and improvement with confidence

Prepare and support internal and external ISMS audits professionally

Use audit results, incidents and performance data to drive targeted improvements

Professional positioning

Establish a recognised competence profile as Information Security Manager, with a foundation for senior security roles in ISO 27001-based organisations

Take responsibility for the implementation of a new ISMS or the coordination of an existing system

Act as a competent counterpart to senior management, clients, auditors and certification bodies

Credentials

Scalable credential model

Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.

Core credential

Diploma in Management System Management

Cross-domain management system foundation: the 19 core modules

Applicable across every ISO standard we teach

Reusable across every further specialisation in the same role

Specialisation credential

Halderstone Certified Information Security Manager

Domain competence in information security

Translation of generic management system concepts to information security

Aligned with ISO/IEC 27001 requirements

Registered credentials

Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.

How registered credentials work →
Registered credentials: Halderstone Certified Information Security Manager

The following Registered credentials can be applied for:

Registered Associate Manager in Information Security Management

Registered Professional Manager in Information Security Management

Registered Lead Manager in Information Security Management

Registered Senior Lead Manager in Information Security Management

Application requires meeting the experience requirements for the respective level.

For employers

How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.

View the credential framework →

Track price

CHF 10,000

All 23 modules, the capstone and the examination

approx. €10,520 · invoiced in CHFapprox. £8,780 · invoiced in CHFapprox. US$12,430 · invoiced in CHF

No VAT is charged.

Start with a single module at any time · credited in full if you continue

Bought from us before? Sign in to see the modules you already hold.

Track facts

Track ID
HAT-IS-M
ISO standard
ISO/IEC 27001

Modular approach

The core carries into every discipline

The 19 core modules are the same in every manager track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about information security.

Core modules

Manager capabilities across disciplines

19 modules · shared by every manager track

Awarded as the Diploma in Management System Management: the credential you keep whichever discipline you specialise in.

A second manager track is 3–5 modules, not 23

Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.

Compare the manager tracks →

Curriculum

How the modules fit together

Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.

Core

Shared with every manager track. Complete them once and they count towards any further qualification in the same role.

Any order
Management core
HAM-AG-MC-01Decision AnalysisStructure complex decisions, clarify objectives, evaluate trade-offs, and make defensible choices under uncertaintyHAM-AG-MC-02Implementation & TransformationImplement and evolve management systems so new processes, controls and improvements are adopted effectively
Management system core
HAM-AG-C-01System FramingAnalyse organisational context, stakeholders and system boundaries to support effective management systemsHAM-AG-C-02System LeadershipDefine clear policy direction and accountability through effective leadership responsibilities in management systemsHAM-AG-C-03Policy ManagementDesign coherent, auditable policy frameworks that align with strategy, scale across entities, and stay current without excess bureaucracyHAM-AG-C-04Governance DesignBuild the decision rights, governance meetings, escalation paths and evidence trails that make management systems work in practiceHAM-AG-C-05Resource ManagementEnsure management systems are supported with sufficient people, time, budget, infrastructure and external supportHAM-AG-C-06Documentation & Knowledge ManagementControl documented information, records and organisational knowledge so they stay accurate, accessible and usable in management systemsHAM-AG-C-07Risk ManagementBuild the capability to surface, structure and act on risk while action is still possibleHAM-AG-C-08Objectives & Performance ManagementDefine and govern management system objectives and KPIs with clarity and consistencyHAM-AG-C-09Process DesignDesign, document and maintain usable processes with clear boundaries, flows, handovers, controls and evidenceHAM-AG-C-10Competence, Awareness & CommunicationPlan and ensure competence, awareness and communication for people within the scope of a management systemHAM-AG-C-11Operational ControlEstablish and run operational control with clear operating criteria, checks, records and deviation handlingHAM-AG-C-12Supplier ManagementManage suppliers and outsourced processes across requirements, selection, onboarding, oversight, change and exitHAM-AG-C-13Monitoring & MeasurementDesign and run monitoring activities and measurement methods to generate reliable performance data for evaluation and improvementHAM-AG-C-14Performance EvaluationEvaluate monitoring and measurement results, interpret trends and deviations, and summarise conclusions to support management decisionsHAM-AG-C-15Internal AuditingPlan, perform and use internal audits effectively to support governance and improvementHAM-AG-C-16Management ReviewConduct effective management reviews with structured inputs, clear decisions and audit-ready evidenceHAM-AG-C-17Improvement ManagementBuild disciplined corrective action and continual improvement through root cause analysis, action planning, implementation and effectiveness verification

Information Security Management

These modules carry the same management system work into ISO/IEC 27001. The method does not change; the material does. What is at stake, which controls are proportionate and which obligations bind are specific to the standard, and so are the judgements that go with them. The aim is a system the organisation runs, not one it maintains for the certificate.

Any order

The capstone engagement

Practical application of the learned ISMS competencies

Demonstrates ability tackle a concrete information security management challenge in a real-world scenario

Based on case proposed by the candidate or provided by Halderstone

The final examination

Confirms solid and actionable understanding of information security management principles

Assesses the ability to design, implement and manage an ISMS based on ISO/IEC 27001 requirements

Covers all core and specialization modules of the track

Method

How you learn it

Two things separate knowing a standard from being able to run a management system to it: what is trained, and what it is trained on.

Practical reflexes, not topics covered

Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.

Three examples from this track’s modules:

Real ownership and escalation

Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.

Residual exposure and explicit acceptance

See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.

Risk criteria and acceptance authority

Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.

Trained on one organisation

Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.

One organisation, carried across modules

Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.

It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones

Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in

Why it matters

Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.

How we teach →

Related track

The same discipline, the other role

The same discipline is taught from the auditor’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.

Track price

CHF 10,000

23 modules, the capstone and the examination

Getting it signed off

Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.

Not sure this is the one?

Start with a single module and have it credited in full later. If the work is assessing other people’s systems rather than running your own, the auditor track is the one. Tell us the situation and we will say which, honestly.

Browse the modules →

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this track is the right one, or point you at a better fit.
About Information Security Manager Track · HAT-IS-M

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.