Transcription of February – May 2019 ISACA Certification Exam Candidate Guide
1 February May 2019. ISACA Certification Exam Candidate Guide Exam Prep Exam Prep Exam Prep Exam Prep by ISACA by ISACA by ISACA by ISACA . ISACA Certification Exam Candidate Guide Table of Contents Section I - Candidate Guide Introduction .. 1. Candidate Guide Overview .. 1. ISACA Overview and Code of Ethics .. 2. ISACA Certification Program Summary .. 3. Section II - Registration and Exam Scheduling .. 8. Registration and Scheduling Overview .. 6. Before You Register .. 7. Registering for the Exam .. 8. Registration Changes .. 10. Scheduling the Exam Appointment .. 11.
2 Rescheduling and Cancelling Exams .. 12. Section III - Exam Preparation .. 13. Exam Preparation Overview .. 13. Getting Ready for the Exam .. 14. Exam Day Rules .. 17. Exam Administration .. 21. Section IV - After the Exam .. 23. Post Exam Overview .. 23. Exam Scoring .. 24. Post Exam 26. Certification .. 27. 28. 2019 ISACA . All Rights Reserved. ISACA Certification Exam Candidate Guide Section I - Candidate Guide Introduction Candidate Guide Overview Introduction The Candidate Guide provides you with everything you need to prepare and take the following Certification exams: Certified Information Systems Auditor (CISA).
3 Certified in Risk and Information Systems Control (CRISC). Certified Information Security Manager (CISM). Certified in Governance of Enterprise IT (CGEIT). Information The Candidate Guide has four major sections: covered in the Candidate Guide In this section This section contains the following topics: Topic See Page ISACA Overview and Code of Ethics 2. ISACA Certification Programs Summary 3. 2019 ISACA . All Rights Reserved. 1. ISACA Certification Exam Candidate Guide ISACA Overview and Code of Ethics What is ISACA helps global professionals lead, adapt, and assure trust in an ISACA ?
4 Evolving digital world by offering innovative and world-class knowledge, standards, networking, credentialing, and career development. ISACA is a global nonprofit association established in 1969. ISACA is made up of 140,000 professionals in 180 countries. What ISACA ISACA offers the following: Offers Cybersecurity NexusTM (CSX) a holistic cybersecurity resource COBIT -- a business framework to govern enterprise technology Certifications to build business critical skills through the following globally respected certifications and credentials: o Certified Information Systems Auditor (CISA ).
5 O Certified in Risk and Information Systems ControlTM (CRISCTM). o Certified Information Security Manager (CISM ). o Certified in Governance of Enterprise IT (CGEIT ). Code of Ethics ISACA sets forth a Code of Professional Ethics to Guide the professional and personal conduct of members of the association and/or its Certification holders. Members and those certified are required to abide by the Code. Failure to comply with this Code of Professional Ethics can result in an investigation into a member's and/or Certification holder's conduct and, ultimately, disciplinary measures.
6 View the Code of Professional Ethics online at: Membership If you are currently not a member, consider joining to save on exam and Contact fees, study materials and global conferences. For more information on Information membership, visit: ISACA Membership. For other inquiries, you can reach ISACA online or by phone. Online: Phone: 1-847-660-5505; Fax: 1-847-253-1443. 2019 ISACA . All Rights Reserved. 2. ISACA Certification Exam Candidate Guide ISACA Certification Program Summary Certification The information below provides a summary of the four ISACA . Summary certifications addressed in this Guide .
7 CISA CRISC CISM CGEIT. Description The CISA designation is a CRISC Certification is The management- CGEIT recognizes a wide range of globally recognized designed for those focused CISM professionals for their knowledge Certification for IS audit, experienced in the Certification promotes and application of enterprise IT. control, and security management of IT risk, international security governance principles and practices. professionals. and the design, practices and implementation, recognizes the monitoring and individual who maintenance of IS manages, designs, controls.
8 Oversees and assesses an enterprise's information security. Eligibility Five (5) or more years of Three (3) years of work Five (5) or more years Five (5) or more years of experience Requirements experience in IS audit, experience managing IT of experience in managing in an advisory or control, assurance, or risk by designing and security management. oversight role and/or supporting the security. Waivers are implementing IS controls, Waivers are available governance of the IT-related available for a maximum of including experience for a maximum of two contribution to an enterprise three years.
9 Across at least two (2) years. including a minimum of one year of CRISC domains of which experience related to the definition, one must be in domain 1 establishment, and management of or 2. There are no a framework for the governance of substitutions or IT. There are no substitutions or experience waivers. experience waivers. Domain (%) Domain 1 - The process of Domain 1 IT Risk Domain 1 Domain 1 Framework for the Auditing Information Identification (27%) Information Security Governance of Enterprise IT (25%). Systems (21%) Domain 2 IT Risk Governance (24%) Domain 2 Strategic Management Domain 2 - Governance Assessment (28%) Domain 2 (20%).
10 And Management of IT Domain 3 Risk Information Risk Domain 3 Benefits Realization (16%) Response and Mitigation Management (30%) (16%). Domain 3 Information (23%) Domain 3 Domain 4 Risk Optimization Systems Acquisition, Domain 4 - Risk and Information Security (24%). Development and Control Monitoring and Program Development Implementation (18%) and Management Domain 5 Resource Optimization Reporting (22%) (15%). Domain 4 - Information (27%). Systems Operation, Domain 4 . Maintenance and Service Information Security Management (20%) Incident Management Domain 5 Protection of (19%).