Certification CISM®: Certified Information Security Manager
CISM® (Certified Information Security Manager®) is an international certification for IT governance professionals. It recognises expertise in information security governance, information security programme management, risk management and incident management. Awarded by ISACA®, it is held by 50,000 professionals worldwide, including more than 7,500 chief information security officers (CISOs) and chief information officers (CIOs).
What is information security governance?
Information security governance is a set of policies, processes, standards and practices implemented within an organisation to protect information on IT systems and ensure its confidentiality, integrity and availability. Its purpose is to define a robust governance framework to address different cyber threats, including data breaches, ransomware attacks and DNS attacks.
Sound information security governance is essential to maintaining stakeholder and customer confidence, minimising security risks and protecting an organisation's critical data. It requires a holistic approach that embeds security in all operational processes and activities. The chief information security officer (CISO) is a key partner at both methodological and operational levels, playing a fundamental role in information security management and the implementation of security policies and programmes.
What is the Certified Information Security Manager (CISM®) certification?
Developed and awarded by the Information Systems Audit and Control Association (ISACA), CISM® specifically targets information security managers, compliance managers, IT directors and risk management professionals.
Recognised worldwide, it certifies knowledge and skills in the following 4 domains:
- Information security governance: establishing the culture, regulations and organisational structure of corporate governance in line with the company's strategic objectives.
- Information security risk management: identifying, assessing and managing information security risks to achieve business objectives.
- Information security programme development: designing, implementing and managing processes, policies and procedures.
- Incident management and business continuity: preparing for and managing security incident responses and ensuring continuity during disruptions.
In short, CISM® is a valuable credential for professionals working in information security and risk management.
How can you earn the CISM® certification?
To prepare effectively for CISM®, it is essential to establish a structured preparation programme. The following recommendations can help:
- Attend intensive training: an online or classroom CISM course, such as the one offered by Oo2, helps you acquire or develop skills, take a mock examination and access learning resources.
- Check your eligibility: make sure you have at least 5 years of professional experience in information security management.
- Take the examination: register online on the ISACA website. The examination consists of 150 multiple-choice questions and lasts 4 hours.
- Read the official CISM examination preparation manual: it includes important information such as task and knowledge descriptions, self-assessment questions and a detailed glossary covering all examination concepts.
In summary, earning CISM certification takes time and commitment. It is valid for 3 years. To renew it, you must provide ISACA with evidence of your commitment to continually improving your information security management knowledge and skills. This may include continuing education, mentoring, research, publications or volunteering in information security.
Training related to CISM®: Certified Information Security Manager
CISM® is a registered trademark of ISACA®
fr
en