Certified Information Security Manager (CISM) adalah sertifikasi professional yangnditujukan untuk para Manajer keamanan informasi yang berpengalaman dan bertanggung jawab terhadap manajemen keamanan informasi yang dikeluarkan oleh Information Systems Audit and Control Association (ISACA). Sertifikasi CISM bertujuan untuk personil yang bekerja pada bidang keamanan informasi dan mencakup empat domain, yaitu: Information Security Governance, Information Risk Management and Compliance, Information Security Program Develoment and Management, dan Information Security Incident Management.
Pelatihan ini akan memberikan pemahaman bagi para peserta terkait empat domain yang membentuk Body of Knowledge, memberikan pengetahuan untuk membangun keterampilan teknis dalam mengelola, mendisain, mengawasi dan menilai keamanan informasi suatu organisasi, dan dalam mempersiapkan untuk mengikuti ujian sertifiaksi CISM.
Information Security Governance
• Explains the fundamentals of security governance.
• Defines roles, responsibilities, and organizational structure.
• Addresses third-party security considerations.
• Uses metrics to measure governance effectiveness.
Information Security Strategy
• Assesses the current security posture.
• Develops a security strategy aligned with business goals.
• Considers resources, constraints, and implementation planning.
• Establishes and manages the information security program to support the strategy.
Information Risk Management and Compliance
• Identifies, evaluates, and manages information security risks.
• Applies risk assessment and analysis methodologies.
• Determines asset value and required security controls.
• Integrates risk management throughout system life cycles.
• Includes training, documentation, and ongoing risk communication.
Information Security Program Development and Management
• Designs and builds the enterprise security program structure.
• Defines scope, framework, and security architecture.
• Implements operational security controls and countermeasures.
• Monitors performance using security metrics.
• Addresses common challenges in security program administration.
Information Security Incident Management
• Establishes incident response processes and teams.
• Evaluates current incident response capabilities.
• Develops and maintains incident response plans, Business Continuity, and Disaster Recovery.
• Tests, executes, and improves response plans.
• Conducts post-incident review and investigation activities.
| Syifa (082130264999) |
| Arga (081227728242) |
| Margi (081394000042) |
| Tuti (081321237948) |