- Cursusduur25 uur
- CertificeringCISM
- Examen/CertificaatCISM Examen
- TaalEngels
- Online toegang6 maanden
- Waardering
- OrganisatieISACA
In deze CISM training / cursus leert u als IT security manager de verschillende kennisdomeinen van de Certified Information Security Manager (CISM) certificering kennen. Na het volgen van deze training bent u optimaal voorbereid op het CISM examen.
De CISM certificering is gericht op IT managers die verantwoordelijk zijn voor het IT security management binnen hun organisatie. De nadruk ligt dan ook op het ontwerpen, plannen, managen en auditen van de IT security processen binnen een organisatie.
Er is uitgebreid aandacht voor alle 5 CISM kennisdomeinen: Information Security Governance, Information Risk Management, Information Security Program Development, Information Security Program Management, Incident Management and Response.
Uw resultaat
Na het volgen van de training beschikt u over kennis van de verschillende kennisdomeinen die het CISM certificaat voorschrijft. Ook bent u optimaal voorbereid om het CISM certificeringsexamen met succes af te ronden.
Doelgroep
IT security professionals / managers die de Certified Information Security Manager certificering van het ISACA willen halen. Tevens geschikt voor iedereen die handvaten wil om IT security management professioneel in te richten binnen een zakelijke omgeving.
Inhoud CISM training
De training / cursus CISM: Certified Information Security Manager (ISACA) is opgebouwd uit verschillende lessen:
- Identify the tasks within the information security governance job practice area
- Recognize the outcomes of information security governance
- Recognize the difference between corporate governance and information security governance
- Match senior management roles with their corresponding responsibilities related to information security governance
- Identify the elements of the information security business model
- Recognize the interconnections between the elements of the information security business model
- Recognize key concepts related to information security governance
- Identify the optimal reporting relationship between senior management and the information security manager
- Label examples of reports about information security according to their intended recipients within an organization
- Identify the goal of converging security-related functions
- Identify categories of key goal indicators
- Recognize key concepts related to information security management
- Match the key participants in developing an information security strategy with their corresponding responsibilities
- Recognize appropriate models for developing an information security strategy
- Label examples of pitfalls that organizations may encounter as they develop an information security strategy
- Assess the effectiveness of a given management team's efforts to develop an information security strategy
- Recognize questions that an information strategy should answer
- Recognize two types of objectives an information security strategy should have
- Identify the key elements of a business case for an information security program
- Recognize key concepts related to approaches for determining the desired state of security
- Identify the aspects of security that must be assessed when determining the current state
- Identify the components of a roadmap for achieving security objectives
- Match constraints that must be considered when developing an information security strategy to their corresponding descriptions
- Assess the efforts of a given management team to create a roadmap for its information security strategy
- Match organizational resources with descriptions of how they are used in developing an information security strategy
- Distinguish between policies, standards, procedures, and guidelines
- Match employee-related resources with descriptions of how they impact development of an information security strategy
- Identify risk-related resources that become part of an information security strategy
- Match strategies for addressing risk to corresponding examples
- Recognize key concepts related to information security strategy resources
- Match the components of an information security action plan with their corresponding roles within the strategy
- Identify types of metrics used to monitor progress toward achieving information security objectives
- Match indicators that security objectives have been met with their corresponding descriptions
- Recognize the key facts about the components of an information security strategy
- Identify the tasks within the information risk management job practice area
- Identify the outcomes of risk management
- Sequence the steps in planning a risk management program
- Recognize the qualities of a good risk management plan
- Match roles in risk management program development with their corresponding responsibilities
- Recognize the steps of the risk management process
- Distinguish between the concepts of risk management, risk analysis, and risk assessment
- Recognizing activities of the risk management program planning process
- Associate steps in the risk management process with specific outcomes of an effective risk management program
- Label examples as either threats or vulnerabilities
- Recognize examples of risk categories
- Recognize the process for conducting a semiquantitative risk analysis
- Match quantitative risk analysis methods with their corresponding descriptions
- Match common risk assessment methodologies with corresponding descriptions
- Recognize risk assessment concepts
- Perform quantitative risk analysis, given a scenario
- Identify examples of information assets that should be valuated
- Match valuation methods with corresponding examples
- Recognize how to classify information assets
- Match disaster recovery terms with their corresponding definitions
- Recognize considerations related to outsourcing security services to a third-party provider
- Determine information asset valuation methodologies used by a given information security manager
- Perform information asset classification
- Distinguish between examples of RTOs and RPOs
- Match risk treatment options with corresponding examples of their use
- Classify examples of controls
- Identify types of controls
- Recognize considerations when planning controls and countermeasures
- Identify the key responsibilities of an information security manager related to risk monitoring and communication
- Recognize methods of integrating risk management processes with other life-cycle processes within an organization
- Determine appropriate actions to effectively manage a given risk
- Recognize elements that are essential for a successful security program
- Identify the tasks within the information security program development job practice area
- Recognize organizational attributes that would inhibit the development of an effective information security program
- Label responsibilities of an information security program as being those of the executive management or those of the information security manager
- Recognize challenges an information security manager may face during information security program development
- Determine who is responsible for carrying out given information security activities
- Recognize how an information security program supports the objectives of information security governance
- Identify the purpose of an information security review
- Assess a given security review
- Sequence excerpts from a security review
- Identify the elements of an information security roadmap
- Recognize strategies for ensuring an information security program supports strategic objectives
- Create a roadmap for an information security program
- Recognize the definition of information security architecture
- Recognize key concepts of the SABSA Model for security architecture development
- Recognize how to use personnel-related resources during information security program development and implementation
- Recognize examples of activities that build a security culture
- Recognize the results of commonly used risk analysis methods
- Recognize the key concepts related to information security architecture
- Recognize the methods for managing human resources during the development and implementation of an information security program
- Distinguish between various risk analysis methods
- Recognize principles of effective security control
- Match types of information security controls with corresponding examples
- Match technologies with their corresponding definitions
- Recognize audit and enforcement activities given a scenario
- Recognize security controls and control principles
- Recognize the role that a given technology plays in ensuring an information security program is effective
- Recognize the role that policies, audits, and compliance enforcement play in ensuring an information security program is effective
- Categorize examples of information security metrics
- Determine whether a given metric would be effective
- Identify methods for measuring the achievement of information security governance outcomes
- Assess the effectiveness of metrics used for an information security program
- Recognize the responsibilities of an information security manager during program implementation
- Recognize the key activities of the PDCA methodology
- Recognize the responsibilities of an information security manager with regards to implementing an information security program
- Identify COBIT control objectives
- Recognize the elements of the Plan-Do-Check-Act cycle
- Identify the types of activities that are involved in managing information security
- Identify the tasks within the information security program management job practice area
- Match security management outcomes with corresponding descriptions of how to achieve each outcome
- Identify common challenges to information security management
- Match information security management roles to their corresponding responsibilities
- Recognize examples of information security management activities
- Recognize strategies for overcoming challenges related to information security management
- Determine the responsibilities of personnel given a specific information security outcome
- Match components of the information security management framework with corresponding examples
- Recognize examples of metrics used to measure performance of an information security program
- Recognize key concepts related to information security components and performance
- Identify information security management tasks with regard to policies, standards, and procedures
- Identify key points regarding controls and countermeasures that are important during information security program implementation
- Identify key points regarding audits that an information security manager should remember during program implementation
- Recognize the results of commonly used risk analysis methods
- Recognize how technologies and human resources are used to manage information security
- Recognize key points about governing documentation, controls, and audits
- Recognize key points about risk analysis resources used in information security management
- Recognize key points about technologies and human resources
- Identify key points regarding the evaluation of an information security program
- Recognize actions that an information security manager should take when implementing an established program
- Recognize responsibilities of an information security manager during program implementation
- Recognize key points about evaluating an information security program
- Recognize key points related to information security management
- Recognize key points related to the responsibilities of an information security manager
- Identify the tasks within the incident management and response job practice area
- Recognize incident management planning considerations
- Order the steps in the incident management process
- Recognize the elements of an incident management plan
- Match causes of challenges in developing an incident management plan with corresponding solutions
- Recognize key points related to incident management planning
- Matching key incident management roles and their corresponding responsibilities
- Identify the roles that make up an incident response team
- Recognize examples of personal skills required by members of an incident response team
- Recognize examples of technical knowledge required by members of an incident response team
- Recognize the activities that are performed during a business impact analysis
- Conduct a business impact analysis using incident management resources
- Determine the appropriate method for identifying the current state of response capability for a given company
- Identify the factors that determine incident response capability
- Match phases of an incident response plan with their corresponding descriptions
- Match members of response and recovery teams with their corresponding responsibilities
- Recognize examples of individuals who may require notification in case of a serious security incident
- Recognize the types of insurance coverage that an organization may have
- Label descriptions of different types of recovery sites
- Determine the appropriate type of recovery site given examples of requirements
- Recognize methods for recovering communication and computing systems
- Distinguish between the characteristics of an incident response plan and a recovery plan
- Recognize the method being used to test incident response and recovery plans
- Recognize examples of metrics used for testing incident response and recovery plans
- Identify important aspects of executing incident response and recovery plans
- Recognize key concepts related to testing and incident management
De training bevat een speciale kennistest als afronding. Tijdens deze kennistest wordt al het geleerde nog een keer getest en krijgt u een goed beeld of u uzelf alle lesstof eigen heeft gemaakt.
Benodigde voorkennis
U heeft algemene kennis van IT concepten. Tevens is het is aanbevolen dat u in het merendeel van de onderwerpen praktijkervaring heeft. Voor het behalen van het CISM certificaat moet u aantonen dat u over praktijkervaring beschikt. Zie voor meer informatie: Examen via ISACA.
Examen via ISACA
U boekt uw examen zelf via de certificeringsorganisatie ISACA. U kunt op de website van het ISACA alle informatie vinden met betrekking tot het aanmelden voor een examen. Tevens vindt u hier de gedetailleerde exameneisen.
De globale exameneisen zijn als volgt:
- Minimaal 5 jaar werkervaring in IT security of u bent in het bezit van een aantal specifieke security gerelateerde certificeringen zoals CompTIA Security+, CISSP, MCSE, CBCP, GIAC en/of ESL IT Security Manager.
- Minimaal 3 jaar werkervaring in IT security management
- Minimaal 3 jaar werkervaring in 3 van de 5 kennisdomeinen
Vragen stellen aan een mentor
In deze training is het mogelijk om, via de mail, vragen te stellen aan een gecertificeerde trainer. U stelt de vragen in het Engels.
Trainingsvorm online training / e-learning
Bij icttrainingen.nl leert u via ons innovatie leerconcept: Social Learning. Hoogwaardige online e-learning trainingen gecombineerd met een online kenniscommunity voor een optimale leerervaring. U kunt na uw bestelling direct online starten. Alle trainingen zijn 24 uur per dag en 7 dagen per week toegankelijk.
> Meer informatie
E-learning
E-learning is een interactieve digitale trainingsvorm. Deze trainingsvorm stelt u in staat om in uw eigen tempo en wanneer het u uitkomt de training te volgen. Het enige dat u nodig heeft is een PC met internettoegang.
Onze E-learning trainingen zijn volledig zelfstandig. U heeft dus geen aanvullende zaken als boeken en dergelijke nodig. Alles wat nodig is voor het succesvol afronden van de training en het eventueel bijbehorende examen is opgenomen in de E-learning training.
Meer informatie over E-learning.
Online kennis community
Tijdens en na uw training heeft u onbeperkt toegang tot de online kennis community. Binnen deze community staat het delen van kennis centraal. U vindt er achtergrondinformatie, artikelen door experts, informatieve filmpjes en discussies voor en door ICT experts. We nodigen u van harte uit deel te nemen aan deze expert community. Meer informatie over de kennis community.
Certificaat van icttrainingen.nl
Na het succesvol afronden van uw training ontvangt u altijd een certificaat van icttrainingen.nl als bewijs dat u de training met succes heeft gevolgd. Dit certificaat kunt u eenmalig, na afronding van de training, zelf genereren en downloaden.