Shall I immediately target a CISM certification?
I am a CISSP, CCSP, CEH, CCNP, Triple CCNA and ITIL Certified with over 7 years of broad and variant experience, currently an Information Security manager.
Passed CCSP on 7 Jan, which seems to cover a lot of the topics and domains of the CISM, same goes for CISSP which I passed on ~ Oct. 2017
I just finished doing the CISM Self Assessment on ISACA.ORG and results were;
Your score is 76%. (38/50)
1: Information Security Governance 91%
2: Information Risk Management and Compliance 75%
3: Information Security Program Development and Management 69%
4: Information Security Incident Management 66%
Do you think it would be realistic to target passing the exam within a 21-day period, as their concepts are similar to a lot of CISSP/CCSP concepts I want to take advantage of still having fresh information and go for it as soon as possible.
I am yet to do any research about the material, the idea just popped into my mind.
This would be my first ISACA exam, any 'de facto' books for CISM?
Passed CCSP on 7 Jan, which seems to cover a lot of the topics and domains of the CISM, same goes for CISSP which I passed on ~ Oct. 2017
I just finished doing the CISM Self Assessment on ISACA.ORG and results were;
Your score is 76%. (38/50)
1: Information Security Governance 91%
2: Information Risk Management and Compliance 75%
3: Information Security Program Development and Management 69%
4: Information Security Incident Management 66%
Do you think it would be realistic to target passing the exam within a 21-day period, as their concepts are similar to a lot of CISSP/CCSP concepts I want to take advantage of still having fresh information and go for it as soon as possible.
I am yet to do any research about the material, the idea just popped into my mind.
This would be my first ISACA exam, any 'de facto' books for CISM?
Comments
Cheers,
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
I am referring to the items mentioned in my previous post; not rushing into actions, report as much as you can, get the management support, evaluate based on risk, support and decide based on business taking risk into consideration, answer each question as a manager not a technical person, and other similar mindsets.
I find them to be somehow similar, just shuffled through some questions in a mobile App and doing well.
Just purchased the Q&A book, but a bit confused. What is the point of getting the 9th edition for double the price of the 8th as long as the questions are not actually exam questions?
Feeling good but I am honestly disappointed by the shallowness of the question when it comes to the technical aspects, like seriously, since CISM is not a technical certificate don't ask technical questions in it, and if we do make sure to be convincing! How on earth would "Employing packet filtering to drop suspect packets" be the best mitigation for DoS attacks! I can see where the one who asked the question is coming from but it is very far from being a decent question! I can justify the rest of the answers to be way better than the mentioned answer.