ISACA

www.isaca.org

The Information Systems Audit and Control Association (ISACA) administers the Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), and Certified in the Governance of Enterprise Information Technology (CGEIT) certifications. These certifications are helpful for professionals who work in organizations subject to various security regulations including Sarbanes-Oxley, Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), and the Payment Card Industry Data Security Standard (PCI DSS).

CISA

The 200-question multiple-choice CISA exam, offered biannually in June and December, covers the following six job-practice areas:

check.png Information Systems Audit Process

check.png Information Technology Governance

check.png Systems and Infrastructure Lifecycle Management

check.png Information Technology Service Delivery and Support

check.png Protection of Information Assets

check.png Business Continuity and Disaster Recovery

Minimum requirements for CISA certification include five years of current work experience (meaning within the past ten years or within five years of passing the exam) in the fields of Information Systems auditing, control, assurance, or security.

CISM

The 200-question multiple-choice CISM exam, offered biannually in June and December, covers the following five job-practice areas:

check.png Information Security Governance

check.png Information Risk Management

check.png Information Security Program Development

check.png Information Security Program Management

check.png Incident Management & Response

Minimum requirements for CISM certification include five years of current work experience (within the past ten years or within five years of passing the exam) in the field of information security. Of the five years of experience, at least three years must be in an information security management role.

CRISC

The four-hour, 200-question multiple-choice CRISC exam, offered biannually in June and December, covers the following five job-practice areas:

check.png Risk Identification, Assessment, and Evaluation

check.png Risk Response

check.png Risk Monitoring

check.png Information Systems Control Design and Implementation

check.png IS Control Monitoring and Maintenance

The minimum requirements for CRISC include three years of work experience in at least three of the domains just listed.

CGEIT

The 120-question multiple-choice CGEIT exam, offered biannually in June and December, covers the following six job-practice areas:

check.png IT Governance Framework

check.png Strategic Alignment

check.png Value Delivery

check.png Risk Management

check.png Resource Management

check.png Performance Measurement

Minimum requirements for CGEIT certification include five years of current work experience (within the past ten years or within five years of passing the exam), including specific evidence of management, advisory, or oversight experience associated with the governance of the IT-related contribution to the enterprise.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.17.162.214