Isaca Cisa Cism
Isaca Cisa Cism
Isaca Cisa Cism
Programs Overview
Prof. Ing. Claudio CILLI
CISA, CISM, CGEIT, CISSP, CSSLP, CIA, M.Inst.ISP
ISACA Facts
• Career Advancement
– To obtain credentials that employers seek
– To enhance your professional image
• Worldwide Recognition
– To be included with over 60,000 other professionals who
have gained the CISA designation worldwide
CISA in the Workplace
Oceania
3% Asia/Mid-East
26%
Central/South
America
North America 3%
47% Europe/Africa
21%
CISA Job Practice Areas
• Security managers
• Security directors
• Security officers
• Security consultants
• Security staff
Recent CISM Recognition
• The US Department of Defense (DoD) includes the CISM certification in its list of
approved certifications for its information assurance professionals.
• SC Magazine selected CISM as a finalist for its 2008 Awards in the "Best
Professional Certification Program" category. CISM was chosen as a finalist by a
panel of 18 chief information security officers (CISOs) at major corporations and
large public-sector organizations.
• CIO Magazine, SC Magazine and Foote Partners research continually cite CISA as
a credential earning that earns top pay among other credentials
• In Certification Magazine’s 2007 salary survey, CISA and CISM ranked in the top
five highest paying certifications.
• CISM recognized in the following publications as a unique security management
credential:
– Information Security Magazine
– CSO Magazine Online
– eWeek
– Computerworld Today (Australia)
– Security Magazine (Brazil)
– Cramsession.com
CISMs by Job Title
IT Directors, IS Security
Managers, 38%
Consultants
18%
CISMs by Geographic Area
Europe/Africa
23%
CISM General Requirements
• Individual
Defines the roles and responsibilities of professionals performing IT
governance work and recognizes their professional knowledge and
competencies; skill-sets; abilities and experiences
• Enterprise
Supports through the demonstration of a visible commitment to
excellence in IT governance practices
• Business
Increases the awareness of IT governance good practices and issues
• Profession
Supports those that provide IT governance management, advisory or
assurance direction and strategy
CGEITs by Job Category
Other
5% Executive Level
IS/IT Audit 19%
26%
IS Security
Professionals
13%
Compliance
and Risk IT Directors, Managers
12% and Consultants
25%
CGEITs by Geographical Area
Oceania
3% Asia/Middle East
17%
South/Central America
5%
Job Practice: A job practice serves as the basis for the exam and the
experience requirements to earn the CGEIT certification. Each job
practice consists of task and knowledge statements, organized by
domains and are intended to depict the tasks performed by individuals
who have a significant management, advisory, or assurance role
relating to the governance of IT and the knowledge required to perform
these tasks. The domains are as follows:
1. IT Governance Framework (required)
2. Strategic Alignment
3. Value Delivery
4. Risk Management
5. Resource Management
6. Performance Measurement
IT Governance Framework
• Define the requirements and objectives for, and drive the establishment of, IT governance in an enterprise, considering
values, philosophy, management style, IT awareness, organization, standards and policies.
• Ensure that an IT governance framework exists and is based on a comprehensive and repeatable IT process and
control model that are aligned with the enterprise governance framework.
• Establish appropriate management governance structures, such as an enterprise investment committee, IT strategy
committee, IT steering committee, technology council, IT architecture review board, business needs committee and IT
audit committee.
• Ensure that the enterprise and IT governance frameworks enable the enterprise to achieve optimal value for the
enterprise.
• Confirm that the IT governance framework ensures compliance with applicable external requirements and ethical
statements that are aligned with, and confirm delivery of, the enterprise’s goals, strategies and objectives.
• Obtain independent assurance that IT conforms with relevant external requirements; contractual terms; organizational
policies, plans and procedures; generally accepted practices; and the effective and efficient practice of IT.
• Apply IT best practices to enable the business to achieve optimal value from implementation of IT services and IT-
enabled business solutions.
• Ensure the establishment of a framework for IT governance monitoring (considering cost/benefits analyses of controls,
return on investment for continuous monitoring, etc.), an approach to track all IT governance issues and remedial
actions to closure, and a lessons-learned process.
• Ensure that appropriate roles, responsibilities and accountabilities are established and enforced for information
requirements, data and system ownership, IT processes, and benefits and value realization.
• Report IT governance status and issues, and effect transparency in reporting.
• Establish a communications plan to continuously market, communicate and reinforce the need and value of IT
governance across the enterprise.
Strategic Alignment
Domain 2 -- Strategic Alignment: Develop, or be part of the development of, an enterprise’s IT strategy
that includes the following responsibilities and tasks.
• Define and implement a strategic planning framework, requiring and facilitating collaborative and integrated business
and IT management planning.
• Actively support/promote and participate in IT management planning by employing best practice enterprise
architecture (EA) frameworks.
• Ensure that appropriate policies and procedures are in place, understood and followed to support IT and business
strategic alignment.
• Identify and take action on barriers to strategic alignment.
• Ensure that effective communication and engagement exists between business and IT management regarding shared
strategic initiatives and performance.
• Ensure business and IT goals cascade down through the enterprise into clear roles, responsibilities and actions.
• Assist senior management by aligning IT initiatives with business objectives and facilitating prioritization of business
strategies that optimally achieve business objectives.
• Identify and monitor the interdependencies of strategic initiatives and their impact on value delivery and risk.
• Ensure that the strategic planning process is adequately documented, transparent and meets stakeholder needs.
• Maintain and update the IT management plans, artifacts and standards for the enterprise.
• Monitor, evaluate and report on the effectiveness of the alignment of IT and enterprise strategic initiatives.
• Monitor and assess current and future technologies and provide advice on the costs, risks and opportunities that they
bring.
Value Delivery
Domain 3 -- Value Delivery: Develop, or be part of the development of, a systematic, analytical and
continuous value governance process that includes the following responsibilities and tasks.
• Ensure that business takes ownership and accountability for business cases, business transformation, organizational
change, business process operation and benefit realization for all IT-enabled business investments.
• Ensure that all IT-enabled investments are managed as a portfolio of investments.
• Ensure that all IT-enabled investments are managed as programs and include the full scope of activities and
expenditures that are required to achieve business value.
• Ensure that all IT-enabled investments are managed through their full economic life cycle so that value is optimized.
• Recognize that different categories of investments need to be evaluated and managed differently.
• Ensure that all IT solutions are developed and maintained effectively and efficiently through the development life
cycle to deliver the required capabilities.
• Ensure that all IT services are delivered to the business with the right service levels.
• Ensure that IT services enable the business to create the required business value using assets (people, applications,
infrastructure and information) to deliver the appropriate capabilities at optimal cost.
• Define and monitor appropriate metrics for the measurement of solution and service delivery against objectives and
for the measurement of benefits realized, and respond to changes and deviations.
• Engage all stakeholders and assign appropriate accountability for delivery of business and IT capabilities and
realization of benefits.
• Ensure that IT investments, solutions and services are aligned with the enterprise
strategies and architecture.
Risk Management
Domain 4 -- Risk Management: Develop, enhance and maintain a systematic, analytical and continuous
enterprise risk management process across the enterprise that includes the following responsibilities
and tasks.
• Ensure that IT risk identification, assessment, mitigation, management, communication and monitoring
strategies are integrated into business strategic and tactical planning processes.
• Align the IT risk management processes with the enterprise business risk management framework
(where this exists).
• Ensure a consistent application of the risk management framework across the enterprise IT
environment.
• Ensure that risk assessment and management is included throughout the information life cycle.
• Define risk management strategies, and prioritize responses to identified risks to maintain risk levels
within the appetite of the enterprise.
• Ensure that risk management strategies are adopted to mitigate risk and to manage to acceptable
residual risk levels.
• Implement timely reporting on risk events and responses to appropriate levels of management
(including the use of key risk indicators, as appropriate).
• Establish monitoring processes and practices to ensure the completeness and effectiveness of
established risk management processes.
Resource Management
Domain 5 -- Resource Management: Develop, or assist in the development of systematic and continuous
resource planning, management and evaluation processes that include the following responsibilities
and tasks.
• Ensure that the requirements for trained resources with the requisite skill sets are understood and are assessed
appropriately.
• Ensure the existence of appropriate policies for the training and development of all staff to help meet enterprise
requirements and personal/professional growth.
• Develop and facilitate the maintenance of systems to record the resources available and potentially available to the
enterprise.
• Undertake gap analyses to determine shortfalls against requirements to ensure that the business and IT resources
(people, application, information, infrastructure) are able to meet strategic objectives.
• Effectively and efficiently ensure clear, consistent and enforceable human resource allocation to investment programs
and services.
• Ensure that sourcing strategies are based on the effective use of existing resources and the identification of those that
need be acquired.
• Ensure that people, hardware, software and infrastructure procurement policies exist to effectively and efficiently
fulfill resource requirements.
• Through periodic assessment of the training requirements for human resources, ensure that sufficient, competent and
capable human resources are available to execute the current and future strategic objectives and that they are kept up
to date with constantly evolving technology.
• Ensure integration of resource identification, classification, allocation and periodic evaluation processes into the
business’s strategic and tactical planning and operations.
• Ensure that the IT infrastructure is standardized; economies of scale are achieved, wherever possible; and
interoperability exists, where required, to support the agility needs of the enterprise.
• Ensure that IT assets are managed and protected through their economic life cycle and are aligned with current and
long-term business operations requirements to support cost-effective achievement
of business objectives.
Performance Measurement
Domain 6 -- Performance Measurement: Develop, or assist in the development of, systematic and
continuous performance management and evaluation processes that include the following
responsibilities and tasks.
• Establish the enterprise's strategic IT objectives, with the board of directors and executive leadership team,
categorized into four areas financial (business contribution), customer (user orientation), internal process (operational
excellence), learning and growth (future orientation), or whatever areas are appropriate for the enterprise.
• Establish outcome and performance measures, supported by metrics, and targets that assess progress toward the
achievement of enterprise and IT objectives and the business strategy.
• Evaluate IT process performance, track IT investment portfolio performance, and measure IT service delivery through
the use of outcome measures and performance drivers.
• Use maturity models and other assessment techniques to evaluate and report on the health of the enterprise’s
performance level.
• Use continuous performance measurement to identify, prioritize, initiate and manage improvement initiatives and/or
appropriate management action.
• Report relevant portfolio, program and IT performance to relevant stakeholders in an appropriate, timely and accurate
manner.
CGEIT Experience Requirements
2009 exams:
Saturday, 13 June 2009
Saturday, 12 December 2009
– More than 260 test sites offered for each exam
administration
– Offered in every city where there is an ISACA chapter
or a large interest by individuals to sit for the exam
– Passing mark of 450 on a common scale of 200 to 800
2009 Registration Fees:
13 June 2009
Early Registration: On or before 11 February 2009:
• ISACA Member: US $395.00
• Non-Member: US $525.00
Exam fees must be paid in full to sit for the June exam. Those whose exam fees are
not paid will not be sent an exam entrance ticket and their registration will be
cancelled.
2009 Registration Fees:
12 December 2009
Early Registration: On or before 11 February 2009
• ISACA Member: US $395.00
• Non-Member: US $525.00
Exam fees must be paid in full to sit for the December exam. Those whose exam fees
are not paid will not be sent an exam entrance ticket and their registration will be
cancelled.
Bulletin of Information
and Registration Form
Bulletin Includes:
• Phone: +1.847.660.5660
• Fax: +1.847.253.1443
• E-mail: certification@isaca.org
• Web site: www.isaca.org