Preparing for CISM
I will dedicate this thread to follow up my whole journey towards -hopefully- being a CISM.
I am an Information Security manager, with over 7 years of experience in networks and Information Security, I currently hold the following certificates: CCNP R&S - CCNA Voice - CCNA Security - ITIL Foundation - CEH - CISSP - CCSP
The most recent was CCSP, and I decided to take it from there as CCSP covers a lot of the topics within CISSP, and CISSP and CISM have a good over-lap percentage, I have done several test exam and been scoring 75-80% before starting the preparation.
I am yet to decide when to book the exam I just plan to go through the chosen material and book it three weeks after am done. Will update this thread accordingly.
Resources I have;
- CISM Review Manual, 15th Edition
- CISM Review Questions, Answers & Explanations, 9th Edition
- Cybrary Videos (Obviously) and old CBT Nuggets videos (Outdated)
I started to read the Review Manual, loved the covered topics but didn't like the book at all, it is boring and I just kept getting out of focus everytime I started reading! I am considering to have a different approach, rely on videos (Cybrary maybe?) and do a selective reading from the Review Manual on topics that I feel require further understanding.
How would you rate Cybrary videos in CISM? Are there any less boring material?
Any general advises or guidance please..
I am an Information Security manager, with over 7 years of experience in networks and Information Security, I currently hold the following certificates: CCNP R&S - CCNA Voice - CCNA Security - ITIL Foundation - CEH - CISSP - CCSP
The most recent was CCSP, and I decided to take it from there as CCSP covers a lot of the topics within CISSP, and CISSP and CISM have a good over-lap percentage, I have done several test exam and been scoring 75-80% before starting the preparation.
I am yet to decide when to book the exam I just plan to go through the chosen material and book it three weeks after am done. Will update this thread accordingly.
Resources I have;
- CISM Review Manual, 15th Edition
- CISM Review Questions, Answers & Explanations, 9th Edition
- Cybrary Videos (Obviously) and old CBT Nuggets videos (Outdated)
I started to read the Review Manual, loved the covered topics but didn't like the book at all, it is boring and I just kept getting out of focus everytime I started reading! I am considering to have a different approach, rely on videos (Cybrary maybe?) and do a selective reading from the Review Manual on topics that I feel require further understanding.
How would you rate Cybrary videos in CISM? Are there any less boring material?
Any general advises or guidance please..
Comments
As an alternative method of studying, try going through the QAE DB first (I think its like 500-800 questions if I remember), and then supplement the wrong questions by reading the manual so that way you're not constantly reading the book.
I spoke to soon as I was writing this post but when I was writing the CISM exam, they didn't have the updated McGraw AIO CISM guide out, but you can find it here: https://www.mheducation.ca/professional/products/9781260027037/cism+certified+information+security+manager+all-in-one+exam+guide/
Honestly I find a lot of topics in the CISM material interesting and I would like to read about, but I don't like the dry language of the official material.
For CISSP/CCSP & CISM holders, how would an ISACA's mindset differ from ISC's? If I treated ISACA as an ISC am I good to go? I find them to be really close so far, ISACA seems to more into doing the action compared to the passive, patient mindset of ISC, but still very close
CISSP | CISM | CISA | CASP | SSCP | Sec+ | Net+ | A+
If I could take a stab on the subtle differences between the ISACA vs the CISSP mindset is that both gravitate towards a managerial mindset first off. IMO ISACA's answers are geared towards more of the business and risk based outcomes from a security manager vs. CISSP comes from the perspective of what is best answer in that scenario (regardless its a technical/administrative). I hope that helps clarify things. When do you plan on taking your exam?
One question regarding some .VCE files available, I am aware that there is no du-m-p-s for CISM and obviously not looking for any, but are the available .VCE files useful and help preparing for the exam? I like the way you can interact with .VCE files, tracking the progress, ... etc.
CISSP | CISM | CISA | CASP | SSCP | Sec+ | Net+ | A+
I am not sure how you feel about BOSON but I had a positive experience with their CISSP exam simulator.