Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Welcome new CISAs and CISMs, or not

Newly certified? Didn't make the cut? Either way, here's what to do

February 11, 2007 12:00 PM ET

Computerworld - While the masses were milling about RSA, long-anticipated emails and letters started arriving in homes and offices across the globe, announcing results of intensive examinations administered at the end of last year. 

Until recently, the Information Systems Audit and Control Association (ISACA) only gave the Certified Information Systems Auditor (CISA) examination once annually, in the summer. Arguably the top dog among vendor-independent security certifications, CISA brings the aura of competence and experience to information security and privacy practitioners even outside the realm of audit.

In the summer of 2003, ISACA began offering a new Certified Information Security Manager (CISM) designation to address demand for an identifier or label that conveys competence outside of audit, in leadership areas of applied information security. In mid 2005, ISACA responded again to pressure, and began offering both tests biannually, in December as well as June. 

These designations are some of the most respected in the industry, and it's a very big deal for many people.  If you just took the exam, or if you're still pondering what a previous exam meant, I've got some advice.

Bad news?

First, if the first sentence of the letter included the word unfortunately, don't be too discouraged, or take a low score as a personal indictment.  A lot of people don't make it on their first try, and no test is fair to its entire audience.  There are always distractions, misunderstandings, strange terminology, and neighbors' dogs that keep you up the night before a test.  If you're working in the industry, you know your own worth and competence.  Sign up now for the next round and get on with studying.  The final registration deadline is in April. 

Keep working; find out where you missed the most questions.  ISACA is kind enough to provide scoring in individual subject areas.  Pick your weakest area and keep studying. 


Better yet, try to find a project at work that will give you practical experience.  While academic learning and test cases may give practical knowledge of how to do things such as perform a risk assessment or build an information security program, there's nothing like actually doing it.  Focusing on areas of weak knowledge often has the osmotic effect of strengthening the rest of your skillset where you already know how to categorize and use information.  It's a lot easier to stare down the next test when you can look forward and backward through your own experience.

Congratulations?

If you passed the CISA or CISM test, congratulations.  But remember that you're still a candidate -- you have to fill out the certification form from ISACA, and submit evidence of applied experience and references. You'll need to break out your resume -- the long one that lists every project you've participated in or led -- and create a few mappings of relevant positions, individual projects, experience in each area, and years of experience for the application. 



Jump to comments

Jon espenschied

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs