Transcription
This video is the launch of my CISM exam prep series. And here, I'm going to unpack what's on the test, how to prepare, and how to clear this exam without wasting time or money. And in the process, I aim to bring some much-needed clarity to the process. I think you don't find in a lot of sources.
It's important to recognize that CISM isn't just about technical knowledge. It's about security leadership, infosec governance, risk management, program development, and even incident handling, all from a manager's perspective. And while CISM requires less technical depth than other exams like CISSP, it does assume that you have a lot of that foundational knowledge and you're able to apply that knowledge in real-world scenarios. So, if you've already cleared the CISSP exam or even Security+, you're in luck because that technical foundation gives you a big head start on your CISM preparation. And if you haven't, in this series, I'll also tune you up on the underlying tech you need for exam day. So, wherever you are in this video, I'll get you pointed in the right direction with the right study resources in your hands and a solid plan for exam prep. Let's dig [Music] in.
Welcome to my CISM exam prep series. Here in the series intro, I'll acquaint you with my recommended exam prep strategy that's worked for many thousands before you. I'll share recommended study materials, as well as some key insights about how to approach this exam and what makes CISM different than any security exam you've taken before.
A bit about me. So, while I am a cybersecurity exam instructor, in my spare time, in my 9-to-5, I am a cybersecurity strategist of VC. So, for a regional bank, I am employing these skills in the real world. And I can promise you that the skills you'll learn in preparing for the CISM exam will prepare you for your 9-to-5, just as they help me. More importantly, last year, I helped thousands around the world achieve cybersecurity certifications like the CISSP, the CCSP, the Security+. I'm bringing those same proven formulas to the CISM exam.
As with all my videos, you'll find a PDF copy of this presentation available in the video description, so you can follow along as you wish.
Now, about this series. The CISM exam consists of four domains. Each of those domains can be broken down into two sections: a Part A and a Part B. So, for domain one, we have A and B, and the same for domains two through four. So, in this series, in addition to this intro video, I'll produce eight installments, one for each Part A and B throughout those four domains.
Now, based on the ISACA certification guide, here are a few key details about the CISM exam you should remember. First, the exam is 150 multiple-choice questions. You have 4 hours to complete the exam. It's a computer-based exam administered at a testing center or via online if you prefer the remote testing experience. So, that's a minute and a half, roughly, per question. That means time management is going to be a key aspect of your exam preparation that you'll want to have sorted before exam day.
So, let's quickly get through a few more mundane details of the exam. Your scores range from 200 to 800, with 450 being the minimum passing score. 800 is a perfect score. There's no mention of needing to pass individual domains, but of course, you should go into that testing center prepared to pass all four domains. Preliminary pass/fail results will be shared with you immediately upon completion of the exam. You'll receive an official score in the mail within 10 working days. You have testing locations around the world. You can also choose to take the online proctored version if you'd prefer to test from home. The exam, at the time of this recording, costs $575 US for ISACA members, $760 for non-members, bearing in mind that the price may vary around the world and ISACA membership does come at a cost. So, most are going to take the exam as non-members. The exam comes in a handful of languages, though most of you will be testing in English.
The exam consists of four domains: Domain One: Information Security Governance. Domain Two: Information Risk Management. Domain Three: Information Security Program. And Domain Four: Incident Management. Now, you'll notice that domains three and four have been elevated in terms of their focus in the latest release of the exam, and thus there's more material to cover there.
Now, I'd like to dive into each of these domains with you briefly and look at the structure of the exam, which is very logical in terms of process flow. So, if we start with domain one, which is Information Security Governance, it begins with Part A: Enterprise Governance, where we'll focus on organizational culture, legal, regulatory, and contractual requirements, organizational structure, roles, and responsibilities. And then moving into Information Security Strategy, which will be guided by our governance efforts. We have strategy development, governance frameworks and standards, and strategic planning. So, governance followed by strategy, very logical flow. You will find a heavy focus on alignment with business needs. All of these efforts around security are worth not if they don't align with the needs of our business. You'll hear some folks mention it as "it's all about the business." That's a fact. You're going to see it mentioned repeatedly and it will surface in questions.
Moving into domain two, where we'll focus on Information Risk Management. This begins with Information Security Risk Assessment. We'll look at the emerging risk and threat landscape, followed by vulnerability and control deficiency analysis, and then risk assessment and analysis. This then flows naturally into Information Security Risk Response, where we'll look at risk treatment and risk response options, risk and control ownership, and risk monitoring and reporting. Now, in domain two, we see that natural flow from assessment to response. And the risk formulas from the CISSP exam and also from the Security+ exam are covered in the CISM, although not quite as directly. They receive a bit more specific focus and tend to really focus on the bottom line, getting down to the annualized loss expectancy. In the event you're not already acquainted with these formulas, you'll be very familiar by the time we complete this series.
Now, moving into domain three, Information Security Program. We're now moving into that area of the exam that receives increased focus in this latest release, and there's a lot of material to cover here. In fact, domain three, I would say, is probably the largest of the exam. It begins with Information Security Program Development, and we see here very much development-focused activities, looking first at our program resources: people, tools, technologies, moving into information asset identification and classification, identifying what we need to secure, industry standards and frameworks for information security that can guide our efforts, policies, procedures, and guidelines, information security program metrics to measure results. And then moving into Part B: Information Security Program Management, where we'll look at control design and selection. So, this is where your knowledge of technology is going to surface. Control implementation and integration here. So, when we're picking controls and implementing controls, that's where having some of that high-level technology knowledge and experience is going to come in handy. Control testing and evaluation to make sure that our controls are effective, and information security awareness and training, how we educate our user population, and management of external services, then supply chain risk management and security, and finally, program communications and reporting, so reporting our state and results back to senior leadership. So, development followed by management, again, we see that very logical flow from a process perspective.
The exam expects familiarity with security technologies, but it focuses more on how to choose and apply those controls in risk scenarios. So, let's take a quick sidebar and talk about technology knowledge expectations on the exam. Because the CISM definitely includes coverage of an array of cybersecurity technologies. You'll see cryptography, references to PKI, network security, cloud security, code security, and a whole lot more. But remember, the CISM is a management exam, and it's a management exam to a greater degree than other security leadership exams you've taken in the past. So, how will tech be referenced on the exam? Well, you'll need to understand how to choose and apply security controls rather than delving into their detailed design or operation. So, knowing use cases and high-level functionality is going to be helpful. So, for technologies like X, M, IDS, and DLP, having some high-level knowledge of where they apply is going to be helpful. Knowing how IDS in a host-based scenario versus network IDS can be helpful. Cloud DLP versus network DLP, understanding the difference in the use cases, definitely useful knowledge. Focus on thinking like a manager, understanding the strategic why and how, not the deep technical specifics.
Now, moving into domain four, Incident Management. So, this begins with Incident Management Readiness, and here we see the development-type activities we would expect in Part A of any of these domains. Incident response plan, business impact analysis, business continuity plan, disaster recovery plan, incident classification and categorization, and finally, incident management training, testing, and evaluation. Very logical flow that then leads into Part B, Incident Management Operations. So, here we'll touch on incident management tools and techniques, incident investigation and evaluation. You'll see forensic techniques surface here. Incident containment methods, so our incident response, incident response communications, eradication and recovery, and post-incident review practices, how we continually improve our incident management program. So, again, that very logical flow from readiness to operations, just as we saw in the first three domains.
So, there are two things I hope you noticed in our review of the CISM exam syllabus. So, number one, the process flow from a security life cycle perspective is very logical from beginning to end. And number two, there was almost no direct mention of cybersecurity technologies in the exam syllabus. So, that technical muscle you've developed in your cybersecurity knowledge from exams like Security+ or CISSP or something else are already there. You have that muscle. Now, you just need to learn to apply that knowledge to the leadership problems that we're going to focus on here in the CISM exam. Now, I'm going to take a couple of minutes and walk you through a few visualizations that will give you a look at the focus of the CISM exam from another perspective. But just know that technology is not going to be your greatest challenge on the CISM exam.
Now, I'd like to pivot here and talk through some strategic aspects of the CISM exam versus other exams you've taken in the past. And you're going to find that the CISM trends a bit more strategic than say, the CISSP exam, which is definitely a security leadership exam, but it trends a bit more technical than the CISM. It gets a bit more in the weeds on the technology. It's a bit more tactical in its problem-solving tasks that you're presented with on the exam. What I will say is, if you've taken the CISSP or even the Security+ and especially if you've taken either of those recently, your technical knowledge of security should pretty well be adequate for the CISM exam. In fact, many candidates have used my CISSP material to help study for the CISM because if you have that CISSP technology knowledge still in your head, you're going to be pretty well prepared when you get into domain three of the CISM and you're looking at control selection and application.
Now, let's talk about success factors of a program and the focus of our organization. So, we have a board of directors, steering committee, business stakeholders that are going to provide input and influence to our senior leadership. We have governance and strategy, which is implemented from the top down, and you're going to see that reference frequently on this exam. Which is better? Well, governance and strategy needs to come from the top down. We need support and guidance from our senior management. Now, incident reports, risk indicators, business unit and operations feedback comes bottom up, and that helps inform our leaders in terms of their decisions.
Now, if we look at it a bit differently by role here, we see that our CEO is more focused on organizational strategy, the CIO on IT strategy, the CISO on information security strategy. And as we go down the list here, you see we're moving from strategic to tactical to operations and execution to the day-to-day implementation and operation at that security technician level. So, strategic planning tends to happen in the three to five-year timeframe. Tactical, typically an annual roadmap. And operational, one to three months at the outermost.
I want to take a quick look at the process flow that we see frequently in the CISM exam prep material. So, it begins with our business stakeholders, our leaders that are going to develop our business goals and objectives. That flows into our information security policy and procedure development, the implementation of our information security program, where that foundational technical knowledge is going to come into play in selecting security controls and implementing those controls appropriately. Our implementation evolves over time. This is the real-world application, and we can then measure our program results. This is where key performance indicators are going to tell us how effective our implementation is, and ultimately, this impacts our business.
Now, there are some lessons to be learned here. Our implementation is going to evolve over time and inform our program managers of the need for any updates. Our KPIs that measure our program results may lead to updates to policies and procedures, and our business impact may surface the need to update our business goals, maybe identifying new opportunities even. So, if we look at it from another perspective, mapping back to some of the statements I made earlier, business needs set the direction for information security. It all starts there. We develop policies and procedures and an information security program that align with our business. We identify the assets that we need to protect. We assess the risk and we choose our controls. We can level up by using a maturity model for guidance to measure the level of our implementation, and then we measure our results through key performance indicators and assess business impact. So, at the end of the day, we want to be familiar with the process flow, and the technology is really going to be secondary in this exam.
So, I want to shift gears and talk about exam prep strategy, starting with the materials you use to prepare for the exam. So, we have official study resources from ISACA. You might choose. So, here we have the CISM Review Manual and the accompanying Questions, Answers, and Explanations manual. Now, what I'll say about that review manual, there's no coverage of the technology there. In fact, it's not standalone. The guide itself says you'll need more than just this book to pass the exam. It lists the technologies you should know, but it does not cover them. Now, the Questions, Answers, and Explanations has a thousand questions, good set of questions sorted by domain and also by quiz format where they group all domains into a quiz format. There's an online database version available, but it is expensive, at least at the time of this recording. It's somewhere in the neighborhood of $300 to $400, depending on your ISACA membership or lack thereof. But each of these guides is $135 or more if we go out and look on Amazon or the ISACA website. So, I'm not sure that's necessarily the best use of your money. You have to make a decision here because you're looking at fairly expensive resources that are not going to be comprehensive in your preparation.
Now, if we go to Amazon, we have three different books. We have the All-in-One Guide, which is 650 pages. It has practice questions at the end of each chapter and 300 questions online in their quiz engine. The CISM Prep Guide from Sybex is 430 pages with a similar practice question count, a little more at the end of each chapter, but again, 300 in their online engine. And then the Packet Publishing CISM Prep Guide is 718 pages, and that is largely due to the fact that they have hundreds of practice questions spread throughout that book. So, it's not that there's substantially more conceptual material to cover, it's that they have more practice questions spread throughout the book. And like the other two, they have 300 in their online engine. So, if I look at these three guides, we have an equal number of practice questions. So, one element to think about. Something else to consider is the flow of the material. So, with the All-in-One Guide, the chapters follow the domains sequentially. Chapter one maps to 1A, chapter two to 1B, etc. The Packet Publishing Guide similarly, the chapters follow the domain sequentially, more or less. Now, the Sybex guide, the chapters jump around a bit. The authors explain why at the beginning of that guide, they felt a bit of shifting around of the topics more effectively allowed them to help you in preparing for the exam. I'm not sure I agree, but to each their own. So, really, if you were choosing any one of these guides, there's not one that is definitely, absolutely, positively better than the others. If I were to pick the happy middle, I think I would probably choose that All-in-One CISM Exam Prep Guide. And based on your previous experience with any one of these publishers or recommendations from your fellow exam candidates or reviews you read online, you might make a different choice than I would, and that's okay. I'm here to advise, not to judge. You pick the material that makes the most sense for you.
Now, there is one other book that I'm hopeful you'll choose to purchase, and that's CISM: The Last Mile. This is coming soon to Leanpub. In fact, I'm recording this video at the end of January. This book should be available in February. 350+ pages of clear, focused explanations. If you've used my materials before, you may appreciate how I distill concepts. It's going to cover every topic in the latest exam syllabus, dozens of full-color diagrams and reference tables. It distills the what, when, and why of key exam topics, and it's priced as low as $10. I wanted to make this a very easy decision for you and a logical accompaniment to your primary exam guide. So, if you'd like to get notified when it's published, go over to Leanpub and just put yourself on the list of interested readers. I don't see anything in the way of this guide coming to availability in the month of February 2025. So, I hope you consider making a purchase there. So, one of these guides with The Last Mile, I think, puts you in a happy place. I'm not suggesting you don't go buy the official ISACA exam resources. I'm simply saying I don't think it's strictly necessary. You're going to find that you spend about $40 on one of these study guides, $10 or so on The Last Mile, puts you at $50. I think it's a good use of your funds, and all of these resources are going to provide the necessary coverage of the technology for you to apply in the context of this exam. So, they are all collectively comprehensive.
Another important point. So, let's shift gears and talk about our exam strategy in terms of how to use these materials most effectively. So, a proven concept for successful exam prep is spaced repetition. So, when we learn a new topic, after we've studied for a time, we're going to forget some of that material over time. And when we come back and look at that material again, we're going to remember a bit more for a bit longer, and so on and so forth. What we see over multiple study sessions is that we remember a bit more, and it takes us a bit longer to forget, which is a good thing. We are retaining that material for longer periods of time. So, it's important to look at how long it takes us to memorize something, to truly learn something for the long term. So, if I want to memorize something quickly or to learn something quickly, my study sessions are going to be repeating within a few hours to a couple of days. I can commit something to short-term memory. This is something akin to what happens in a boot camp when you go learn a lot of information over the course of five days. Is there value in that for an exam? Absolutely. Now, to memorize something for a longer period of time, we have to space those repetitions out. And you can mix these up and learn topics for a long time, but come back and cram a bit more specifically as you get closer to an exam. There's value in both, but in the long term, it's great if we can retain a lot of this knowledge for a long period of time so we can take it into our career and use it. But life is short, so find the balance that works for you and go with it.
So, let's talk about our exam prep sources. The research clearly shows that everyone benefits from a variety of sources. So, we've talked about targeted reading in books, practice exams. We can perform a live quiz using a presentation or flashcards. That PowerPoint review, just looking at the written form of a video can be very helpful. So, I'm going to give you one method of combining these. You want to mix and match and repeat based on your preferences. I'm going to show you mine because it's a system I've used with thousands of learners, and I tend to think it works pretty well. The results have proven themselves. I like to start with video content because that gives me a good idea of what I do and don't know right out of the gate, so I can begin to narrow my focus to my weak areas. Reviewing that PowerPoint presentation during or after the presentation can be very helpful. You might use it to take notes, for example. I provide a PDF you can download to review and to write on if you wish. That PDF is great also for a self-quiz or with a partner. I've used a PDF with my lovely wife to prepare myself for exams like the CISSP.
Now, in terms of a practice exam, for best results, I suggest you keep these sessions at a manageable level. I like an hour or less, so I just don't get exhausted with questions, so I can keep my focus up. I also like to use practice exams to master my time management. Remember, you have about 90 seconds to answer each question. I like to make sure that time management is baked into my practice so it's automatic on exam day. Now, in terms of those study guides, I like to use the reading the guides to close knowledge gaps, not for cover-to-cover review. That's a lot of reading, you're not going to retain most of it. So, targeted reading where you need it is going to be more effective in terms of the use of your time. And really, what we need to look at is the 80/20 process or the Pareto principle. It's called. Think of your exam prep effort as a funnel. So, we have all exam content and study materials, and you want to filter this down to the weak topics you need to focus on. And you're going to filter down to those weak areas with practice exams, live review, flashcards, the video learning, etc. But you want to spend the bulk of your exam prep time on those weak areas that you need to be fully prepared for exam day. And at the end of the day, that's what's important. And that's what I have for you, my friends. I hope you found this session helpful. As always, if you have any questions, leave them here under the video or reach out on LinkedIn. I'll look forward to seeing you in the next session in this series, Domain One, Part A. And until next time, take care and stay safe.