Who Is the Target Audience?
Now that you have an idea of the key topics of CISM, it's also relevant to know the main audience of the certification. First and foremost, it is created for individuals who have managerial roles. Their position allows them to design, supervise, and calculate the information security features of the organization. In addition, these professionals must have a minimum of 5 years of industry experience in managing information security. Isaca may allow a waiver of the number of working years for up to 2 years.
As for the practical skills, you should be able to perform the following tasks:
- Maintain the integration of a incident response plan and a disaster recovery plan.
- Establish proper information security incidents to allow the accuracy in responding to incidents;
- Make sure to test, review, and revise the incident response to ensure the effectiveness and improve response capabilities;
- Make sure to carry out reviews of incidents afterwards to know the exact cause of certain situations to avoid its probability in the future;
What Are the Important Exam Requirements You Need to Know?
Just like all other Isaca certification exams, CISM consists of 150 questions. These are structured in multiple-choice type, with a time limit of up to 4 hours or 240 minutes. The converted scale scores range from 200 to 800. In order to pass the test, you have to get at least 450 points. On the other hand, the exam fee differs for members and non-members. If you're a member, you only have to pay $575 while the non-members have to shell out $760.
Before taking the test, you will be given two delivery options. The first one is by in-person at a testing site. The second one is via a remote set-up in an online setting. Both options allow you to choose your preferred language options. As of this writing, there are 4 selections, including English, Japanese, Chinese Simplified, and Spanish.
Another thing to remember is the exam registration. You cannot take the CISM test if you will not register with Isaca and schedule it ahead. But don't worry because it doesn't mean that you have to sit for the exam as soon as possible after registration. You are given 12 months from the date of enrollment to take it. Henceforth, you have to take into account the eligibility period.
Important requirements
The IT consultants, information security managers, and aspiring managers are the target audience for the CISM certification exam that supports InfoSec program management. These specialists are expected to have an understanding of the relationship between information security and business objectives, as well as manage information security of a company, and develop policies and practices.
Reference: https://www.isaca.org/credentialing/cism/cism-exam-content-outline
ISACA CISM Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Information Security Risk Management | 20% | - Integrate risk management into business and IT processes - Identify and/or recommend risk treatment options - Monitor and communicate the information security risk posture - Identify legal, regulatory, organizational and other applicable compliance requirements - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Determine appropriate risk treatment options - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk |
| Topic 2: Information Security Incident Management | 30% | - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain processes to investigate and document information security incidents - Establish and maintain incident escalation and notification processes - Test, review and revise the incident response plan - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Develop and implement processes to ensure the timely identification of information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities |
| Topic 3: Information Security Governance | 17% | - Identify internal and external influences to the organization that affect the information security strategy and program - Develop business cases to support investments in information security - Obtain commitment from senior management and other stakeholders for the information security program - Define and communicate the roles and responsibilities for information security throughout the organization - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Establish, monitor, evaluate and report information security management metrics |
| Topic 4: Information Security Program Development and Management | 33% | - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Monitor and manage the information security program - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) - Align the information security program with the operational objectives of other business functions - Integrate information security requirements into organizational processes - Develop and maintain a security awareness, training and education program for all stakeholders - Establish and maintain information security architectures (people, process, technology) - Establish and/or maintain the information security program in alignment with the information security strategy |














783 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
