The CISM certification program is designed to validate the knowledge and skills of information security professionals in various areas such as information security governance, risk management, information security program development and management, and incident management. CISM-JPN exam covers the latest information security practices and frameworks, including the NIST Cybersecurity Framework, ISO 27001, and COBIT.
The CISM certification exam is designed to test the candidate's knowledge and skills in four domains: Information Security Governance, Information Risk Management and Compliance, Information Security Program Development and Management, and Information Security Incident Management. CISM-JPN exam consists of 150 multiple-choice questions, which must be completed in a four-hour time limit. CISM-JPN exam is administered by Prometric, a leading provider of testing and assessment services.
Reference: https://www.isaca.org/credentialing/cism/cism-exam-content-outline
The CISM certification exam is designed for experienced information security professionals who have a minimum of five years of experience in the field of information security management. Candidates must demonstrate their expertise in the areas of information security strategy, policy, and procedures, as well as risk management, incident response, and compliance. CISM-JPN exam consists of 150 multiple-choice questions, which must be completed within four hours. Candidates must achieve a score of 450 or higher on a scale of 200-800 to pass the exam.
ISACA CISM日本語 Exam Overview:
| Certification Vendor: | ISACA |
|---|---|
| Exam Name: | Certified Information Security Manager |
| Exam Number: | CISM |
| Passing Score: | 450 (out of 800) |
| Exam Format: | Multiple Choice |
| Exam Price: | $575 (Member) / $760 (Non-Member) |
| Exam Duration: | 240 minutes |
| Certificate Validity Period: | 3 years (requires maintenance fees and CPE) |
| Related Certifications: | CISM |
| Available Languages: | French, English, Japanese, German, Chinese-Simplified, Spanish |
| Real Exam Qty: | 150 |
| Sample Questions: | ISACA CISM日本語 Sample Questions |
| Exam Way: | Computer-based testing at authorized PSI testing centers or remotely proctored. |
| Pre Condition: | To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. |
| Official Syllabus URL: | https://www.isaca.org/credentialing/cism |
ISACA CISM日本語 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Information Security Program Development and Management | 33% | - Establish and/or maintain the information security program in alignment with the information security strategy - Align the information security program with the operational objectives of other business functions - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Develop and maintain a security awareness, training and education program for all stakeholders - Monitor and manage the information security program - Integrate information security requirements into organizational processes - Establish and maintain information security architectures (people, process, technology) - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) |
| Information Security Incident Management | 30% | - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Establish and maintain processes to investigate and document information security incidents - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Establish and maintain incident escalation and notification processes - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities - Test, review and revise the incident response plan - Develop and implement processes to ensure the timely identification of information security incidents |
| Information Security Risk Management | 20% | - Determine appropriate risk treatment options - Integrate risk management into business and IT processes - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Identify legal, regulatory, organizational and other applicable compliance requirements - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Identify and/or recommend risk treatment options - Monitor and communicate the information security risk posture |
| Information Security Governance | 17% | - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Obtain commitment from senior management and other stakeholders for the information security program - Define and communicate the roles and responsibilities for information security throughout the organization - Develop business cases to support investments in information security - Establish, monitor, evaluate and report information security management metrics - Identify internal and external influences to the organization that affect the information security strategy and program - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization |
We're so confident of our products that we provide no hassle product exchange.


By Irene

