Table of Contents
About This Manual 13
Overview 13
Organization of This Manual 13
Format ofThis Manual 13
Evaluation ofThis Manual 13
Preparing for the CISM Exam 14
Getting Started 14
CISM Self-assessment 14
Using the CISM Review Manual 14
Manual Features 14
Using the CISM Review Manual With Other ISACA Resources 15
About the CISM Review Questions, Answers and Explanations Products 15
Types of Questions on the CISM Exam 15
Chapter 1:
Information Security Governance 17
Section One: Overview 18
Domain Definition 18
Learning Objectives 18
CISM Exam Reference 18
Task and Knowledge Statements 18
Task Statements , 18
Knowledge Statements 18
Relationship of Task to Knowledge Statements 19
Task Statement Reference Guide 20
Suggested Resources for Further Study 21
Self-assessment Questions 22
Answers to Self-assessment Questions 23
Section Two: Content 25
1.0 Introduction 25
1.1 Information Security Governance Overview 26
1.1.1 Importance of Information Security Governance 27
1.1.2 Outcomes of Information Security Governance 27
1.2 Effective Information Security Governance 28
1.2.1 Business Goals and Objectives 28
1.2.2 Determining Risk Capacity and Acceptable Risk (Risk Appetite) 30
1.2.3 Scope and Charter of Information Security Governance 30
1.2.4 Governance, Risk Management and Compliance 30
1.2.5 Business Model for Information Security 31
Dynamic Interconnections 32
1.2.6 Assurance Process Integration—Convergence 32
Convergence 33
1.3 Roles and Responsibilities 33
Skills 33
Culture 34
1.3.1 Board of Directors 34
1.3.2 Senior Management 35
1.3.3 Business Process Owners 35
1.3.4 Steering Committee 35
1.3.5 Chief Information Security Officer 35
За повече информация: 088 682 47 47