|
INFORMATION SECURITY GOVERNANCE
Establish and maintain a framework to provide assurance
that information security strategies are aligned
with business objectives and consistent with applicable
laws and regulations. The objective of this core competency,
which accounts for 21% of the exam content, is to
focus on the need for a stable security program.
RISK MANAGEMENT Identify and manage information
security risks to achieve business objectives. This
topic area tests the applicant's knowledge in the area
of risk identification and management as they relate to
business needs. This area accounts for 21% of the
exam contents.
EXAM OVERVIEW In this section we'll review the
requirements to sit for the CISM exam and how to
maintain the certification after successful completion.
We'll give you tips on the best ways to study
and prepare for the exam, including techniques
used by other successful candidates.
|
INFORMATION SECURITY PROGRAM Design,
develop and manage an information security program
to implement the information security governance
framework. This topic area stresses the skills and
knowledge necessary to create and implement the
information security framework. This section accounts
for 21% of the examination material.
INFORMATION SECURITY MANAGEMENT
Oversee how the internal and external resources for
information security are identified, appropriated and
managed. Candidates will have to show proficiency in
their understanding of the tools required to manage an
information security program. This topic area accounts
for 24% of the examination total.
RESPONSE MANAGEMENT Develop and manage
a capability to respond to and recover from disruptive
and destructive information security events. This section
addresses the need for development and implementation
of policies and procedures, and accounts for
13% of the exam.
|