Course Information
Course Overview
Overview
CISM® is a globally recognized standard of achievement of information security management. The CISM certification was developed specifically for experienced information security managers and those with information security management responsibilities who include Information Security Managers, Aspiring Information Security Managers, IS/IT Consultants and Chief Information Officers.
About the Certification
- Awarded by Information Systems Audit and Control Association (ISACA)
- Designed for those who manage, design, oversee and assess an enterprise’s information security function
- Official Website: http://www.isaca.org/
Training Highlights
- 21-hour intensive examination preparation workshop
- Conducted by renowned, experienced industrial expert
- Real case study will be adopted with experience sharing
- Eligible for 21 units of PDU / CPE
Examination Highlights
- The CISM® exam is based on 200 questions and the maximum allotted time for candidates to complete it is 4 hours
- CISM® uses what is known as a 800-point maximum scale, with scaled score of 450 being the lowest passing score
What You’ll Learn
Module 1: Information Security Governance
- Enterprise Governance Overview
- Organizational Culture, Structures, Roles and Responsibilities
- Legal, Regulatory and Contractual Requirements
- Information Security Strategy
- Information Governance Frameworks and Standards
- Strategic Planning
Module 2: Information Security Risk Management
- Risk and Threat Landscape
- Vulnerability and Control Deficiency Analysis
- Risk Assessment, Evaluation and Analysis
- Information Risk Response
- Risk Monitoring, Reporting and Communication
Module 3: Information Security Program Development and Management
- IS Program Development and Resources
- IS Standards and Frameworks
- Defining an IS Program Road Map
- IS Program Metrics
- IS Program Management
- IS Awareness and Training
- Integrating the Security Program with IT Operations
- Program Communications, Reporting and Performance Management
Module 4: Information Security Incident Management
- Incident Management and Incident Response Overview
- Incident Management and Response Plans
- Incident Classification/Categorization
- Incident Management Operations, Tools and Technologies
- Incident Investigation, Evaluation, Containment and Communication
- Incident Eradication, Recovery and Review
- Business Impact and Continuity
- Disaster Recovery Planning
- Training, Testing and Evaluation
- Learning Objectives:
- Distinguish between incident management and incident response
- Outline the requirements and procedures necessary to develop an incident response plan
- Identify techniques used to classify or categorize incidents.
- Outline the types of roles and responsibilities required for an effective incident management and response team
- Distinguish between the types of incident management tools and technologies available to an enterprise.
- Describe the processes and methods used to investigate, evaluate and contain an incident
- Identify the types of communications and notifications used to inform key stakeholders of incidents and tests.
- Outline the processes and procedures used to eradicate and recover from incidents.
- Describe the requirements and benefits of documenting events.
- Explain the relationship between business impact, continuity and incident response.
- Describe the processes and outcomes related to disaster recovery.
- Explain the impact of metrics and testing when evaluating the incident response plan.