CISM Certification Requirement
Guys,
I need some help here for my CISM certification requirements. I am trying to appear CISM exam this June 2010 and have a question in mind. Senior guys please help me.
I have more than 14 years of experience in IT System Administrator/Support experience, Worked as a IT Manager for 3 years and System Admin as a more than 8 years. Question: Is my experience is sufficient to qualify for Certification if I sit on Exam in June 2010. Or do I need specific title in my job role to gain the certification.
Thanks,
LeoStar
I need some help here for my CISM certification requirements. I am trying to appear CISM exam this June 2010 and have a question in mind. Senior guys please help me.
I have more than 14 years of experience in IT System Administrator/Support experience, Worked as a IT Manager for 3 years and System Admin as a more than 8 years. Question: Is my experience is sufficient to qualify for Certification if I sit on Exam in June 2010. Or do I need specific title in my job role to gain the certification.
Thanks,
LeoStar
Comments
profile: linkedin.com/in/astorrs
Forum Admin at www.techexams.net
--
LinkedIn: www.linkedin.com/in/jamesdmurray
Twitter: www.twitter.com/jdmurray
OK, maybe I am being dense today, but I am not sure I understand what is meant by 'a minimum of three years of information security management work experience in three or more of the job practice analysis areas. Is it People Management? Risk Management? Incident Management? Doesn't seem very clear (to me at least) what kind of management it is looking for.
Then a little bit further down the list of requirements:
'The experience substitutions will not satisfy any portion of the three-year information security management work experience requirement.' -So I basically have to have an IAM title to qualify?
Exception: Two years as a full-time university instructor teaching the management of information security can be substituted for every one year of information security experience. -The way this is phrased, 'teaching management of information security' leads me to think that it is not referencing 'People Management,' or any instructor teaching an HR class would technically be qualified for the exception. What springs to mind, is the MIS (Management of Information Systems) Degree as being kind of what I am referring to, although after re-reading, I still don't think I am explaining it very well.
I am interested in pursuing this cert, but I am not sold on the fact that it is a requirement that I have people working under me to get it.
Have you done Information Security Governance, Risk Management, InfoSec Program Development or Management or Incident Management and/or Response? Have you managed any such programs?
It's really as simple as applying what you know and what you've done to the criteria. Focus on the five domains (that I paraphrased above) and your experiences. For example, if you've managed your company's firewalls and IPSs and developed policies for those, that counts. Managing a help desk with four techs, doesn't.
Don't get too wrapped around degree programs or being a supervisor. Those things may help, but are by no means required.
Good luck with this and on the exam should you decide to go forward,
Mr. Ye