The Certified Information Security Manager®(CISM®) certification program was developed by the Information Systems Audit and Controls Association (ISACA®). It has been designed specifically for experienced information security managers and those who have information security management responsibilities. The Complete Guide to CISM ® Certification examines five functional areas―security governance, risk management, information security program management, information security management, and response management. Presenting definitions of roles and responsibilities throughout the organization, this practical guide identifies information security risks. It deals with processes and technical solutions that implement the information security governance framework, focuses on the tasks necessary for the information security manager to effectively manage information security within an organization, and provides a description of various techniques the information security manager can use. The book also covers steps and solutions for responding to an incident. At the end of each key area, a quiz is offered on the materials just presented. Also included is a workbook to a thirty-question final exam. Complete Guide to CISM ® Certification describes the tasks performed by information security managers and contains the necessary knowledge to manage, design, and oversee an information security program. With definitions and practical examples, this text is ideal for information security managers, IT auditors, and network and system administrators.
I read this book cover to cover, not because I liked it, but because I believed it would prepare me for the exam. Having taken the exam today, I now know that this book has falsely advertised its claim to be the "complete guide". Out of two hundred questions on the test, I can directly link one to content that I read in the book. Beyond that, there are other systemic problems with the book:
- there is no flow; you are constantly jumping from topic to topic within the chapters, - spelling errors, - grammatical errors, - diagrams and tables referenced in the text incorrectly, - diagrams so poorly constructed as to be useless, - the questions at the end of the chapters are poorly constructed and often repeated between chapters. The real questions on the exam are much much harder. Buy the test bank from ISACA. - lastly, parts of the book had been subcontracted out to other authors and it shows both in writing style and unprofessionalism. I would cite an example in the technology section which was subcontracted to the author's son where he references other parts of the book "that his dad wrote." And in chapter 5 where the author asks repeatedly in a condescending tone if "you've got it yet."
If you bought this book, return it for a refund. Get a different one - buy the CISSP book if you have to, this one will not adequately prepare you for the exam