Exam details
ISACA CISM is used to be a manual exam, but over the years it has evolved into a Computer-Based Testing method, which ensures even more accuracy and reliability for its candidates. It is consisting of 150 questions that you need to clear within 240 minutes. This exam is available in various languages, such as Chinese, English, Japanese, Korean, and Spanish. It is held at the PSI testing centers around the world.
The exam voucher is valid for one year after it is released. For the ISACA members, the price of the CISM test is $575, but the non-members should pay $760. To pass this certification exam, an individual should score at least 450 points or higher.
Who should take the CISM exam
The ISACA Certified Information Security Manager CISM Exam certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled as Certified Information Security Manager. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The ISACA Certified Information Security Manager CISM Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge and skills that are required to pass the ISACA Certified Information Security Manager CISM Exam then he should take this exam.
Reference: https://www.isaca.org/credentialing/cism/cism-exam-content-outline
ISACA CISM: What career benefits can you get?
Holding the CISM certification will support your career growth. If you are an IT Security Architect, an Information Security Analyst, or a Chief Information Security Officer, this certificate will help you significantly get a promotion or find a new job. It demonstrates your knowledge in the information security sphere and makes finding a new job easier.
In addition, you will surely earn more. The average salary for those professionals who have the CISM certification ranges from $52,400 to $243,600 per year. Therefore, if you want to get a pay raise, this certificate is the right choice for you.
The CISM exam cannot be taken by every IT professional because a potential candidate should have at least five years of experience in information security and three years of experience in at least three or more of the following sectors:
- Information security governance;
- Information security governance.
- Information security program development and management;
- Information security incident management;
Furthermore, the experience mentioned above should be gained not less than ten years before applying for the exam or within five years after passing it.
ISACA CISM 中文 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Information Security Incident Management | 30% | - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain processes to investigate and document information security incidents - Establish and maintain incident escalation and notification processes - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Develop and implement processes to ensure the timely identification of information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Test, review and revise the incident response plan |
| Information Security Governance | 17% | - Identify internal and external influences to the organization that affect the information security strategy and program - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Establish, monitor, evaluate and report information security management metrics - Define and communicate the roles and responsibilities for information security throughout the organization - Obtain commitment from senior management and other stakeholders for the information security program - Develop business cases to support investments in information security |
| Information Security Risk Management | 20% | - Integrate risk management into business and IT processes - Monitor and communicate the information security risk posture - Identify and/or recommend risk treatment options - Identify legal, regulatory, organizational and other applicable compliance requirements - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Determine appropriate risk treatment options |
| Information Security Program Development and Management | 33% | - Establish and/or maintain the information security program in alignment with the information security strategy - Establish and maintain information security architectures (people, process, technology) - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Integrate information security requirements into organizational processes - Develop and maintain a security awareness, training and education program for all stakeholders - Align the information security program with the operational objectives of other business functions - Monitor and manage the information security program - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) |














0 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
