Skip to Main Content

Meetings Stub Page [mx-stub]

Certified Information Security Manager (CISM)

Agenda
 

1 - INFORMATION SECURITY GOVERNANCE
  • Develop an Information Security Strategy
  • Align Information Security Strategy with Corporate Governance
  • Identify Legal and Regulatory Requirements
  • Justify Investment in Information Security
  • Identify Drivers Affecting the Organization
  • Obtain Senior Management Commitment to Information Security
  • Define Roles and Responsibilities for Information Security
  • Establish Reporting and Communication Channels
2 - INFORMATION RISK MANAGEMENT
  • Implement an Information Risk Assessment Process
  • Determine Information Asset Classification and Ownership
  • Conduct Ongoing Threat and Vulnerability Evaluations
  • Conduct Periodic BIAs
  • Identify and Evaluate Risk Mitigation Strategies
  • Integrate Risk Management into Business Life Cycle Processes
  • Report Changes in Information Risk
3 - INFORMATION SECURITY PROGRAM DEVELOPMENT
  • Develop Plans to Implement an Information Security Strategy
  • Security Technologies and Controls
  • Specify Information Security Program Activities
  • Coordinate Information Security Programs with Business Assurance Functions
  • Identify Resources Needed for Information Security Program Implementation
  • Develop Information Security Architectures
  • Develop Information Security Policies
  • Develop Information Security Awareness, Training, and Education Programs
  • Develop Supporting Documentation for Information Security Policies
4 - INFORMATION SECURITY PROGRAM IMPLEMENTATION
  • Integrate Information Security Requirements into Organizational Processes
  • Integrate Information Security Controls into Contracts
  • Create Information Security Program Evaluation Metrics
5 - INFORMATION SECURITY PROGRAM MANAGEMENT
  • Manage Information Security Program Resources
  • Enforce Policy and Standards Compliance
  • Enforce Contractual Information Security Controls
  • Enforce Information Security During Systems Development
  • Maintain Information Security Within an Organization
  • Provide Information Security Advice and Guidance
  • Provide Information Security Awareness and Training
  • Analyze the Effectiveness of Information Security Controls
  • Resolve Noncompliance Issues
6 - INCIDENT MANAGEMENT AND RESPONSE
  • Develop an Information Security Incident Response Plan
  • Establish an Escalation Process
  • Develop a Communication Process
  • Integrate an IRP
  • Develop IRTs
  • Test an IRP
  • Manage Responses to Information Security Incidents
  • Perform an Information Security Incident Investigation
  • Conduct Post-Incident Reviews
You are using an unsupported version of Internet Explorer. To ensure security, performance, and full functionality, please upgrade to an up-to-date browser.