CISM, the Certified Information Security Manager, is a new credential from the Information Systems Audit and Control Association (ISACA).
It is specifically geared towards experienced information security managers and those who have information security management responsibilities. CISM is designed to provide executive management with assurance that those earning the designation have the required knowledge and ability to provide effective security management and consulting.
It is business-oriented and focuses on information risk management while addressing management, design and technical security issues at a conceptual level. While its central focus is security management, all those in the IS profession with security experience will certainly find value in CISM.
The first exam will be offered in June 2003. The exam will be available in Johannesburg, Cape Town, Durban and Kimberly. There will be over 200 test sites in more than 75 countries. Candidates may take the CISM examination prior to meeting the experience requirements for certification. This practice is acceptable and encouraged, although the credential will not be awarded until all requirements are met. The CISM will cover five areas:
* Information security governance;
* Risk management;
* Information security programme management;
* Information security management; and
* Response management.
The format of the exam is 200 multiple choice questions from the five areas listed above. The exam must be answered within four hours. The exam will be written on the 14 June 2003. ISACA has contracted an internationally recognised professional testing agency to administer the examination. This not-for-profit enterprise organises the exam around the world.
Info Sec Africa has scheduled training courses for 2003. Study material will be available from December 2002. Exam registration closes on the 2 April 2003. An early bird discount will be available until January 2003.
Further information can be found at www.isaca.org.za.
Editorial contacts

