Security Manager Prep

Wishlist Share

About Course

The analyst builds the program. The manager runs it. This course puts you in the manager’s chair.

It is July 1 at Odapeeka State University, a year after a ransomware intrusion forced the board to demand a real security program. The board got its proof and, for once, said yes. Now you are the university’s first Information Security Program Manager, with a small team, a real budget, six audit findings, a defense contractor asking for a certification date, and an Audit Committee chair who says, “Don’t show me green. Show me what changed.”

What you will do

  • Turn a board mandate into a security strategy on one page, and a steering committee that can settle a disagreement with the most powerful person on campus.
  • Design the team, write a job description that doesn’t scare off good people, and make the build, buy or partner call on 24/7 monitoring with the full cost in front of you.
  • Build next year’s security budget under a flat-budget rule and write a business case a CFO will read.
  • Turn a one-paragraph risk appetite into categories, tolerances and key risk indicators, and report risk every quarter.
  • Run the policy lifecycle and clean up an exceptions register nobody has looked at in a year.
  • Build an awareness program that changes behavior, and negotiate phishing tests with the Faculty Senate and the staff union.
  • Manage the technology program at a manager’s altitude: architecture, identity, segmentation and zero trust, cloud and SaaS, secure development, and vulnerability management with service levels IT can staff to.
  • Answer an auditor with names and dates, govern a POA&M, get a research enclave ready for assessment, and triage a sprawl of SaaS apps.
  • Command a payroll-diversion incident: severity, decisions, notification clocks, counsel, the insurer, the bank, the reporter on the phone.
  • Report to the Audit Committee every quarter, and write a three-year program plan.

What you walk away with

A Three-Year Security Program Plan and the ten finished deliverables behind it: strategy, staffing plan, budget and business case, risk appetite and KRIs, policy calendar, awareness program, vulnerability management standard, audit responses, incident plan and decision log, and an Audit Committee report. Every organization in it is fictional, so it is yours to show in an interview.

Who it is for

GRC analysts, SOC leads, sysadmins and auditors who are being handed a team, a budget or “the program.” New security managers and ISSMs who got the title before the playbook. Veterans, project managers and IT managers moving into security leadership. Nothing to install. You need a spreadsheet, a word processor and your judgment.

How it is built

12 topics, 68 lessons including two “100 Terms” vocabulary videos, 10 deliverables, topic quizzes, a final assessment and a graded capstone. It continues the Odapeeka State story from GRC Analyst Prep. If you didn’t take it, you get the model version of that course’s capstone as your starting packet. Tyrone E. Wilson built it. He is a working vCISO and serves as CISO on an active CMMC Level 2 program.

What’s included

The course is free, and everything is included: all lessons, the case packets, the workbook and templates, the quizzes and final assessment, AI-assisted feedback on all ten deliverables and the capstone, the model answers (they open once you submit your own work), and your certificate.

Exam prep

The course maps to the domains tested by ISACA CISM (the outline in effect from November 3, 2026) and covers the management domains of ISC2 CISSP. CISM or CISSP exam prep is sold separately, and it will be included in CISO Prep (vCISO II) when that course opens. Both certifications require verified work experience, and the course walks you through those requirements. Practice scores are study signals, not predictions.

Let your work be seen

When you finish, you can opt in to Chrysalus, Cover6’s talent network. Employers looking for security leadership can see your certificate and the work you choose to share. One of those employers may be Cover6.

Level, CPE and what comes next

This is vCISO I, the first level of the Cover6 vCISO Pathway. You earn it by passing the final assessment at 70% or higher and scoring 80% or higher on the graded capstone, with no rubric criterion at the lowest score and a plan that passes the honesty gate: no overstated claims. Your certificate shows the level and 34 CPE hours. CPE hours may be submitted to your certifying body (CompTIA, ISC2, ISACA and others) according to its rules. Each body decides what it accepts.

The course is aligned with DoD 8140 work role 722, Information Systems Security Manager, at the Basic level. Alignment is not approval: qualifying for a work role also takes on-the-job qualification and continuing education.

Next on the pathway: CISO Prep (vCISO II), where your program plan becomes the board’s packet.

It is hard on purpose, and you will not do it alone.

Show More

Course Content

Topic 0: Welcome to Year Two

  • From Analyst to Manager: What Changes
  • Year Two at Odapeeka: The Brief
  • How This Course Works: The Program Plan
  • Ground Rules: Fictional Data and Professional Codes
  • Topic 0 Quiz: Welcome to Year Two

Topic 1: Strategy and Governance

Topic 2: Building and Leading the Team

Topic 3: Budget and the Business Case

Topic 4: Running the Risk Program

Topic 5: The Policy Lifecycle

Topic 6: Awareness, Training and Culture

Topic 7: The Technology You Manage

Topic 8: Assurance: Audits, Assessments and Vendors

Topic 9: Incident Command and Resilience

Topic 10: Metrics, Reporting and Managing Up

Topic 11: Capstone, Career and Next Rung

Student Ratings & Reviews

No Review Yet
No Review Yet
Shopping Cart
Scroll to Top