December 2005
2004 CPE Audit
October 2005
CISM Job Practice Analysis Nears Completion
CISM Job Practice Analysis Nears Completion
The CISM job practice analysis, which will form the basis for the 2007 CISM examination, is coming to a conclusion.
Professional Examination Service, the project consultant, issued the complete report to the CISM Certification
Board for consideration and approval at its October meeting. To include a wider representation of security
management, the Information Systems Security Association, the Information Security Forum and ASIS International
were represented on the project task force.
The audit of documentation for 2004 continuing professional education (CPE) activities began
recently. A randomly selected group of those holding the CISA and CISM designations has been
sent an audit letter requesting written support documentation for 2004 CPE hours. Any questions
you have about the 2004 audit should be directed to the certification department at
certification@isaca.org or +1.847.253.1545, ext. 474, 471 or 403.
CISM Job Practice Analysis Nears Completion
The CISM job practice analysis, which will form the basis for the 2007 CISM certification
examination, is coming to a conclusion. In September, a survey will be sent to a representative
sample of CISMs who will be asked to evaluate job task statements as to their importance and criticality.
Knowledge statements that represent what competencies information security managers require will also be
submitted to CISMs as part of the survey. This information will be combined with the work of the task
force members and subject matter experts. The resulting definition of the information security manager
position will not only form the basis of the certification but also help clarify the security manager's
position. Professional Examination Service, the project consultant, will issue the complete report to the
CISM Certification Board for consideration and approval at its October meeting. To include a wider
representation of security management, the Information Systems Security Association, the Information
Security Forum and ASIS International were represented on the project task force.




