Course Overview
The Certified Information Security Manager (CISM®) qualification by ISACA promotes international security practices and recognizes the individual who manages designs, and oversees and assesses an enterprise’s information security. This training course equips professionals with the knowledge and skills for proficiency in information security management. It also helps in passing the certification examination successfully.
Learning Objectives
Candidates should expect to gain competencies in the following areas after successful completion of the training course:
Information Security Governance
Information Risk Management and Complia nce
Information Security Program Development and Management
Information Security Incident Management.
Who Should Attend?
Instructor Profile: Syed Shahzad Tayyeb (CISM)
1
Chief Information Officers
2
Chief Information Security Officers
3
Security Professionals who are taking or considering taking the CISM examination
4
Anyone seeking an overall understanding of essential IT security risks and controls.
Curse Agenda
Day 1 – Domain 1: Information Security Governance
1
Methods to develop an information security strategy
2
Relationship among information security and business goals, objectives, functions, processes and practices
3
Fundamental concepts of governance and how they relate to information security
4
Integrate information security into corporate governance
5
Develop security policies
6
Develop business cases with budgetary planning
7
Information security management roles and responsibilities
8
Methods to select, implement and interpret metrics
9
Methods to implement an information security framework
Day 2 – Domain 2: Information Risk Management and Compliance
1
Methods to establish an information asset classification model consistent with business
2
Information asset valuation methodologies
3
Methods to assign the responsibilities for and ownership of information assets and risk
4
Risk assessment and analysis methodologies
5
Risk reporting and monitoring requirements
6
Risk treatment strategies and methods to apply them
7
Techniques for integrating risk management into business and IT processes
8
Techniques for integrating risk management into business and IT processes
9
Compliance reporting processes and requirements
Day 3 – Domain 3: Information Security Program Development and Management
1
Methods to align information security program requirements with other business functions
2
Methods to identify, acquire, manage and define requirements for internal and external resources
3
Methods to design information security controls
4
Methods to develop information security standards, procedures and guidelines
5
Methods to establish and maintain effective information security awareness and training programs
6
Methods to integrate information security requirements into organizational processes
Day 4 – Domain 4: Information Security Incident Management- Incident management concepts and practices
1
Business continuity planning (BCP) and disaster recovery planning (DRP) and their relationship to the incident response plan
2
Incident classification, damage containment, and escalation processes
3
Forensic requirements and capabilities for collecting, preserving and presenting evidence
4