0% found this document useful (0 votes)
13 views1 page

CISM Certification Course Overview

The CISM certification is designed for IT professionals with at least five years of experience, focusing on information security governance, program management, incident management, and risk management. The exam consists of 150 questions to be completed in four hours, and candidates must maintain their certification by earning 120 CPE hours every three years. The course covers various domains including governance, risk management, and incident management, with training options available online and in-person.

Uploaded by

toncik
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views1 page

CISM Certification Course Overview

The CISM certification is designed for IT professionals with at least five years of experience, focusing on information security governance, program management, incident management, and risk management. The exam consists of 150 questions to be completed in four hours, and candidates must maintain their certification by earning 120 CPE hours every three years. The course covers various domains including governance, risk management, and incident management, with training options available online and in-person.

Uploaded by

toncik
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Course Description

General Information

Designed for IT professionals with technical expertise and experience in IS/IT security and control looking to transition from
team player to manager. CISM can add credibility and confidence to interactions with internal and external stakeholders, peers
and regulators.

This certification indicates expertise in information security governance, program development and management, incident
management and risk management. If you are a mid-career IT professional aspiring to senior management roles in IT security
and control, CISM can get you the visibility you need.

There are 150 Questions on the exam which must be completed in four hours. It is available online via remote proctoring and
at in-person testing centers where available.

CISM Certification Candidates CPE Overview

CISM is intended for information security professionals with at To maintain your CISM, you must earn and report a minimum
least five years of relevant work experience and at least three years of 120 CPE hours every three-year reporting cycle and at least
in the role of information security manager. Job titles include: 20 hours annually. CISM awards up to one hour of CPE for every
„ CISO one hour of instructor led training. Online review course earns 20
CPEs and Virtual Instructor-Led Training (VILT) earns 14 CPEs.
„ CSO
„ Security Director/Manager/Consultant Course Duration
„ IT Director/Manager/Consultant „ Online Course: Approximately 16 hours
„ Compliance/Risk/Privacy Director and Manager „ In-person training or VILT: 2–4 days

Course Topics

Domain 1: Information Security Governance Domain 3: Information Security Program, continued


„ Enterprise Governance Overview „ IS Program Metrics
„ Organizational Culture, Structures, Roles „ IS Program Management
and Responsibilities „ IS Awareness and Training
„ Legal, Regulatory and Contractual Requirements „ Integrating the Security Program with IT Operations
„ Information Security Strategy „ Program Communications, Reporting and Performance
„ Information Governance Frameworks and Standards Management
„ Strategic Planning Domain 4: Incident Management
Domain 2: Information Security Risk Management „ Incident Management and Incident Response Overview
„ Risk and Threat Landscape „ Incident Management and Response Plans
„ Vulnerability and Control Deficiency Analysis „ Incident Classification/Categorization
„ Risk Assessment, Evaluation and Analysis „ Incident Management Operations, Tools and Technologies
„ Information Risk Response „ Incident Investigation, Evaluation, Containment and
„ Risk Monitoring, Reporting and Communication Communication
„ Incident Eradication, Recovery and Review
Domain 3: Information Security Program
„ Business Impact and Continuity
„ IS Program Development and Resources
„ Disaster Recovery Planning
„ IS Standards and Frameworks
„ Training, Testing and Evaluation
„ Defining an IS Program Road Map

I S A C A G L O B A L | 1700 E. Golf Road | Suite 400 | Schaumburg, IL 60173 | USA | [Link] © 2022 ISACA. All Rights Reserved.
R2022-04

You might also like