menu image
AssuranceSecurityGovernanceMembers & LeadersProfessionals & PractitionersStudents & EducatorsExhibitors & Advertisers
menu shadow
CGEIT
CISA
CISM
 CISM in the News
 CISM Exam Info
Important Dates
spacer image
Print this page
spacer image

CISM logo

CISM Exam Job Practice Areas

CISM Job Practice Areas by Domain The CISM exam covers five information security management areas, each of which is further defined and detailed through Tasks & Knowledge statements.

These areas and statements were developed by the CISM Certification Board and represent a job practice analysis of the work performed by information security managers as validated by prominent industry leaders, subject matter experts and industry practitioners.

The following is a brief description of these areas, their definitions and approximate percentage of test questions allocated to each area.

To view specific Tasks & Knowledge statements that represent a current market perspective of what is performed — and what should be known by information security managers, click the Show/Hide Tasks & Knowledge Statements link next to each Job Practice area. This information provides the basis for the CISM exam and the qualifying experience for certification.

Information on the previous CISM Job Analysis areas for 2002-2006 is also still available.

The job practice domains and task and knowledge statements are as follows:

Display or Hide All Task & Knowledge Statements (toggle)
Display and Print All Task & Knowledge Statements (toggle)

Domain 1—Information Security Governance (23%)

Establish and maintain a framework to provide assurance that information security strategies are aligned with business objectives and consistent with applicable laws and regulations.

:: Display/Hide Domain 1 Tasks & Knowledge Statements ::

Domain 2—Information Risk Management (22%)

Identify and manage information security risks to achieve business objectives.

:: Display/Hide Domain 2 Tasks & Knowledge Statements ::

Domain 3—Information Security Program Development (17%)

Create and maintain a program to implement the information security strategy.

:: Display/Hide Domain 3 Tasks & Knowledge Statements ::

Domain 4—Information Security Program Management (24%)

Oversee and direct information security activities to execute the information security program.

:: Display/Hide Domain 4 Tasks & Knowledge Statements ::

Domain 5—Incident Management & Response (14%)

Plan, develop and manage a capability to detect, respond to and recover from information security incidents.

:: Display/Hide Domain 5 Tasks & Knowledge Statements ::


nav menu image
spacer image
Assurance | Security | Governance
Members & Leaders | Professionals & Practitioners | Students & Educators | Exhibitors & Advertisers
Info Request | Join | Bookstore | My ISACA | About ISACA
Home | Site Map | Shopping Cart | Logout | Contact Us
spacer image
menu shadow

Terms Of Use | Privacy Policy | IP Guidelines
© 2008 ISACA All rights reserved.
3701 Algonquin Road, Suite 1010, Rolling Meadows, Illinois 60008 USA