Exam topics
There are four work-related domains that an individual must prove his/her expertise in when looking to grow or build out the organization. The topics to learn are listed below:
1. Information Security Governance – 24%
Each section will have the theoretical and practical evaluation of your skill set and knowledge base, and this area is not an exception. The knowledge statement includes the following:
- Knowledge of worldwide information security governance and its role in strategy development;
- Knowledge of using and establishing available methods of reporting in an organization.
- Strength, opportunities, weaknesses, threats, and all the required techniques to develop a successful information security strategy;
- Knowledge of this field in relation to the objectives and goals of a business;
- Knowledge and skills in implementing the methods of information security governance;
Reference: https://www.isaca.org/credentialing/cism/cism-exam-content-outline
3. Information Security Program Development and Management – 27%
The next area that you should learn will evaluate your knowledge base whether it contains the following or not:
- Knowledge of the techniques to communicate this program to the stakeholders.
- Knowledge and skills in implementing the rules into contracts, agreements, and third-party management processes;
- Knowledge and skills in managing, identifying, and defining the necessary requirements for internal and external resources;
- Knowledge and ability to implement the proper effectiveness and procedures of information security along with its policies;
- Knowledge of the certifications, training, and skills required for information security;
ISACA CISM Deutsch Exam Overview:
| Certification Vendor: | ISACA |
|---|---|
| Exam Name: | Certified Information Security Manager (CISM) Exam |
| Exam Number: | CISM |
| Passing Score: | 450 (scaled score 200–800) |
| Exam Duration: | 240 minutes |
| Exam Format: | Linear format, Computer-based, Multiple choice |
| Exam Price: | USD 575 (ISACA member), USD 760 (non-member) |
| Certificate Validity Period: | 3 years |
| Available Languages: | Japanese, Chinese (Simplified), English, Korean, Spanish |
| Real Exam Qty: | 150 |
| Related Certifications: | CRISC CGEIT CDPSE CISA |
| Recommended Training: | CISM Online Review Course CISM Review Manual |
| Exam Registration: | ISACA Official Registration |
| Sample Questions: | ISACA CISM Deutsch Sample Questions |
| Exam Way: | Computer-based testing at PSI authorized centers or remotely proctored online |
| Pre Condition: | No mandatory exam prerequisites; certification requires 5+ years of professional information security management experience, with at least 3 years across 3+ domains, within 10 years before application or 5 years after passing exam |
| Official Syllabus URL: | https://www.isaca.org/credentialing/cism/cism-exam-content-outline |
ISACA CISM Deutsch Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Incident Management | 30% | - Business continuity and disaster recovery coordination - Stakeholder communication and reporting - Incident response planning and preparation - Containment, eradication and recovery - Post-incident review and improvement - Detection, analysis and classification of incidents |
| Information Security Program | 33% | - Security architecture and control design - Security awareness, training and education - Program performance measurement and reporting - Resource management, budget and staffing - Program development and alignment with strategy - Control implementation, testing and evaluation |
| Information Security Risk Management | 20% | - Third-party and supply chain risk management - Risk identification and assessment - Risk response and treatment strategies - Threat and vulnerability analysis - Risk monitoring, reporting and communication |
| Information Security Governance | 17% | - Align security strategy with business objectives - Establish and maintain governance framework - Define security roles, responsibilities and organizational structure - Develop and maintain policies, standards and procedures - Monitor compliance and regulatory requirements |
We're so confident of our products that we provide no hassle product exchange.


By Boyce

