Requirements for CISM Certification4) Work experience in the field of information security Submit verified evidence of a minimum of five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas. The work experience must be gained within the ten-year period preceding the application date for certification or within five years from the date of originally passing the exam.Experience Substitutions The following security-related certifications and information systems management experience can be used to satisfy the indicated amount of information security work experience.Two Years: Certified Information Systems Auditor (CISA) in good standing Certified Information Systems Security Professional (CISSP) in good standing Post-graduate degree in information security or a related field (e.g., business administration, information systems, information assurance) One Year: One full year of information systems management experience One full year of general security management experience Skill-based security certifications (e.g., SANS Global Information Assurance Certification (GIAC), Microsoft Certified Systems Engineer (MCSE), CompTIA Security +, Disaster Recovery Institute Certified Business Continuity Professional (CBCP), ESL IT Security Manager) Completion of an information security management program at an institution aligned with the Model Curriculum The experience substitutions will not satisfy any portion of the three-year information security management work experience requirement.
JDMurray wrote: » Based on the info on the CISM Requirements page the Andrew beat me to posting, I'd say you need to emphasize at least five years of InfoSec management-related work on your resume.