Becoming CISM: Tips for Revision and Exam Day Success

The CISM examination is difficult. Not only is there a lot of material to know and revise, but the exam is long—at four hours, it is much longer than many of us will have experienced during our formal education. Here are some tips from my own experience to help you through the ISACA exam process for all certifications.

Revision

Start with the practice exam in the CISM review book. You will find it to be hard work. I had to force myself to read each question carefully towards the end. Self-marking this exam identifies the areas for improvement in revision. Going through these questions will help you to understand the question format on the exam. These questions are not actual or even retired questions from an exam.

Revising effectively consists of three stages:

  1. Reviewing the practice exam—was that wrong answer a careless mistake or a lack of knowledge?
  2. Tailoring the revision—ISACA’s resources and other security publications are extremely useful. Make sure you learn ISACA’s preferred terminology.
  3. The questions in the review book explain the correct answer and why the other options are false. This ensures both your knowledge and reasoning are sound. In hindsight, this was the most valuable part of my revision programme.

With the real exam nearing, re-take the practice test. I felt less tired and more in control this time around. I improved my score significantly, with consistent results across all the knowledge domains. Make sure to review incorrect answers and learn from them. However, do not be over confident if you pass these practice exams. They are used for review and are not reflective of the questions being tested on the exam.

The Exam

Read all the provided information about the exam administration—specifically the Candidates Guide, and take everything you need (particularly suitable ID) with you!

Most people will need to travel to the exam venue. Try to stay in a local hotel the night before as stress from delays or traffic will not help your chances of success. A good night’s rest is an excellent investment.

Once you arrive for the exam, after registration you will enter the exam room itself (often it will be rows of school desks). Relax. If you suffer from pre-exam nerves, try to delay your registration a little to minimise the time you spend waiting at your desk.

With a few hundred people in the room, it is quiet, but not silent. There will be a background of rustling paper, coughing and creaking chairs. Earplugs are provided, but you are not allowed to bring your own or noise-cancelling headphones.

A good exam technique is the method I was taught many years ago:

  1. Answer quick wins on a first pass.
  2. Spend longer on more difficult questions, but do not be afraid to move on.
  3. Revisit remaining questions, using reasonable methods to find an answer.

What’s Reasonable? You could:

  1. Identify wrong answers. This is why it is important to know not only why an answer is correct, but also why the other three are false.
  2. Use facts from other questions. If you are stuck on “What type of control is a firewall?” another question might ask “Preventive controls such as firewalls are useful in which scenarios?” You’ve been given the answer—thanks ISACA!
  3. Finally, copy your answers to the answer sheet. Having learnt from previous mistakes, I now use this method:
    • Copy the question book answers onto the answer sheet
    • Ensure the correct dots are filled for each question
    • Ensure exactly 200 dots are filled (as a final check)

If you have finished early, you can put your hand up and you can leave once an invigilator has collected your papers. You will be tired afterwards, so plan to relax, get some fresh air, some lunch and move about a bit. Nobody wants to finish their exam day with an accident caused through tiredness.

Now, wait a few weeks for your results email… Good luck!

Darren Hampton, CISM
Head of Information Security at the University of Southampton

[ISACA]

The Cost to a CFO of Ignoring the Obvious

Companies pay a high price for assuming existing safeguards will prevent a data breach. According to a CB Insights article, Cybersecurity Startups Have Raised $7.3 Billion Over 1,028 Deals, a litany of high-profile security breaches impacting both the private and public sector have made cybersecurity start-ups an increasingly hot area for investment. Since 2010, deals and dollars increased steadily growing by more than 100 percent in both areas. Funding in 2014 broke the US $2 billion barrier for the first time, while deals continued their steady ascent, growing 4.3 percent from 2013 to 269 deals.

The importance of online security and the necessity of companies and individuals to avoid business practices that leave their information vulnerable are in the news several times a week, if not daily. Apple’s Tim Cook, the CEO of the first US company in the world to reach a market capitalization of US $700 billion, spoke recently at the White House Summit on Cybersecurity and Consumer Protection at Stanford University, highlighting that this problem is a concern for even some of the largest players in the market.

The rise of the mobile workforce and the movement to cloud technologies open up more opportunities than ever for hackers, competitors and other potential criminals to access sensitive data surreptitiously. In 2013, more than 13 million Americans were victims of identity theft, now one of America’s fastest growing crimes. The average annualized cost of cybercrime for U.S. companies was US $12.7 million in 2014, up from US $11.6 million the year before, according to the Ponemon Institute.

What should be of particular concern to company CFOs is that the hackers are becoming as skilled as the employees whose job it is to safeguard precious information. They are doing everything they can do to breach virtual protections in place and utilize the gathered data for illegal gains. Cyberattacks happen across all industries and to companies of all sizes, making it important for every organization to create and implement an effective risk strategy.

CFOs can apply a simple yet effective, three-step approach to digital risk mitigation, as noted in Armanino’s recent article. By creating strong internal controls, maintaining open communication across departments and investing in cyberinsurance, CFOs will be well-positioned to adapt to new threats and reduce their company’s digital risk on an ongoing basis.

It is the CFO’s responsibility to keep cybersecurity issues top-of-mind for the executive team, which is always dealing with several priorities vying for the same resources. It is imperative to ensure your company does not lose sight of the fact that digital risk needs to be addressed on an ongoing basis, lest they become part of the growing cost of managing the unfortunate outcome. Keeping in mind hackers’ growing sophistication, the key to warding off their unwelcomed infiltration is to create a culture where cybersecurity is a consistent part of the boardroom discussion.

Jeremy Sucharski, CISA, CRISC
Partner-in-Charge of Armanino’s Governance, Risk and Compliance (GRC) Practice

[ISACA]

Eliminating Passwords in the Enterprise

Passwords can be a pain for everyone. They are not secure and are prone to misuse. Isn’t it time to get rid of them entirely?

While issuing an enterprise credential with a strong password is fairly easy to accomplish, managing that password over the credential’s lifetime is more difficult. User password resets, compromised passwords and a lack of synchronized passwords across enterprise systems all cause problems for users, IT departments and security professionals.

And users truly hate passwords. There are too many to remember, each system has different rules, and there is a lack of standards for reset processes.

A positive associated with passwords is that they are well understood by both providers and end-users. They offer portability, through reuse and single sign-on, and are supported by all identity and access management (IAM) platforms. Corporate policies for using passwords with credentials are also well established.

But, usability and security of password-backed credentials are in decline and a passwordless future is something that keeps coming up in the IAM conversation. So what will it take?
I do not believe it will be any one technology or single method that replaces passwords in enterprise access management. There are simply too many user, business, application and compliance requirements out there for a one-solution-fits-all scenario.

In the online world we have an embarrassing number of authentication options. Biometrics examples include the iPhone fingerprint reader and the up-and-coming Nymi band. Hardware tokens have been here for a while. Smartphone tokens work fairly well. And this stuff is not really all that new—in 2007 I blogged about authenticators such as fobs, proximity cards and USB tokens.

With all of these options, it does not seem likely that any one technology will swoop in to corner the market and single-handedly replace passwords. But that’s okay—I don’t think we need a killer authenticator or login process. A better option is a flexible IAM solution that offers adaptive (or context-based) authentication.

Today, access management systems provide a traditional username plus password credential:

Figure 1 – Traditional Access Management

The access manager software has logic that determines that a username and password are required, and both must match the entry in the directory—pretty straight-forward stuff. But this is an old approach, invented when users’ screens were green and bellbottoms were cool.

If we want to eliminate passwords, we need a better access manager—one that supports adaptive authentication.

Let’s say we want to improve the experience by accepting either a username plus password, or a username plus equivalent authenticator. And, let’s assume we have issued mobile phones with contact-less technology to our users. In this case, the adaptive authentication process might work something like this:

Figure 2 – Adaptive Access Management

The access rules (white boxes) direct the authentication process. (This is a simple case—using adaptive access management, you can extend this flow to include multiple authenticators and checks.)

As products mature, the flexibility to add logic and capabilities to these processes will increase. The more rules you implement, the more secure—yet potentially just as easy—the access can become.

Wait: you mean secure OR easy right? Isn’t there always a trade off? Well, the implementation of adaptive authentication technology may be difficult, but the user experience can be simplified. If all we need is to eliminate passwords, then the alternate authenticator needs to be as strong and, hopefully, easier to manage. If the contact-less smartphone is that authenticator, we meet or improve on both security and ease-of-use.

The point is that the combination of authenticators—aligned with the level of assurance required by the network, application or service—is what matters. It does not matter that a password is involved.

Once the right technology is implemented, the process to migrate away from passwords is fairly straightforward: offer users an option to log in with their phones and watch the migration occur on its own. In six months, force the switch and you have eliminated passwords entirely.

There is a catch (of course). The organization’s password and access policies will need to change. In my experience, these policies are specific to passwords (length, composition, etc.) and cannot support adaptive authentication as I have just described.

It is critical to create policies and standards for authentication assurance (and identity proofing), based on the sensitivity of information. The types of rule sets necessary to implement compliant adaptive authentication can then be based on clear policy. IAM expertise is needed to do this effectively.

Because business, IT architecture, security and privacy teams need to be on board, the benefits and risks associated with adaptive authentication need to be understood. Critically, the organization’s leadership also needs be informed of the risks of current password-based access management in order to secure support. All this takes time and skill to do well.

Adaptive authentication, revamped policies and senior management support—that’s what it will take to eliminate passwords. Are you ready to say goodbye to your passwords?

Mike Waddingham
President, Code Technology Corp.
Blogger, CodeTechnology.ca

[ISACA]

Why You Shouldn’t Study for Certification Exams

People often ask me about the best way to prepare for a successful CISA, CISM, CGEIT or CRISC examination. They are usually surprised to hear my advice: Do not study for the exam at all—study for the knowledge!

As to my opinion, what sets ISACA’s certifications apart from many other credentials on the market is that ISACA exams actually test your professional experience and not your exam cramming skills. Many exam items are mini scenarios that require you to apply your knowledge to typical issues arising in your daily work. You will hardly find any items that are definitional.

I recommend adapting your studying strategy and following a long-term learning approach. Using this process, try to avoid subjectivity in the sense of the idiosyncrasies of your organisation. Companies, both large and small, tend to become blind to the shortcomings in their methods and processes. And, particularly within SMEs, the number of staff in information security, risk management, IT audit or governance with whom to share insights is often limited.

To avoid these pitfalls, implement some means for acquiring and exchanging knowledge in your professional life. For example:

  • Follow your professional colleagues on social media sites such as Twitter or LinkedIn. Look at who they follow to identify the thought leaders within your domain.
  • Read or contribute articles for blogs and periodicals, e.g. the ISACA Journal or ISACA Now blog.
  • Follow a massive open online course (MOOC). Many universities offer free online courses and classes.
  • Visit professional conferences or seminars as a delegate or speaker. There are events for every budget, and speakers are often invited for free. Use the occasion to network with peers from other organisations or industry sectors.
  • Join or found a professional community. Meet with other colleagues from your region or vertical. This is also a good opportunity to receive hints from successful exam takers or find peers who are also preparing for the exam.
  • Volunteer at ISACA or another association. See who has an active chapter in your geographic area.

In addition to the tips above, regularly review for the exam using the study materials by ISACA including the review manual and the review questions. Keep in mind that the review manuals do not comprise a complete body of knowledge. Relate to the job practice areas (specifically the task and knowledge statements) that provide the basis for the exam. Identify your weak spots and adapt your focus of studying if necessary.

Once you are well prepared, register for the exam. During the exam, if you are unsure of the right answer, take a business perspective on the question. Ask yourself, ‘If this was my organisation, how would I like the issue to be solved?’

This approach to learning will not only help you to become certified, but also will benefit your professional skills in general. As a side note, it also allows you to easily and almost automatically earn your CPE hours and maintain your certification.

Tim Sattler, CISA, CISM, CGEIT, CRISC, CISSP, CCSK
IT Compliance Manager, Group Information Security Officer at Jungheinrich AG, Germany

[ISACA]

Security Management and Internal Audit: Becoming Two Sides of the Same Coin

Internal security audits are a valuable source of information and highlight the areas that require attention, but do not be overly driven by their findings and recommendations.

Excessively strengthened security controls can impact business negatively. Security-related audit findings must be viewed in context of the relationship between business goals, the threat profile and the security controls. Security management and internal audit are two separate streams, but are driven by similar goals and fundamentally can be two sides of the same coin.

Sometimes, security controls are relevant to/appropriate for the infrastructure, but not relevant for the business itself. This results in the organization’s internal audit team finding weaker security controls within the infrastructure. In such situations, collaboration between security management, internal auditors and business must resolve the trade-off between compliance and noncompliance to the organizational security policies. Security management must be able to explain the business rationale for weaker controls to the auditors and simultaneously communicate the risks clearly to the enterprise’s management of not being compliant to the strengthened security policies. By doing so, security management ensures that the risk is understood and accepted by management.

Utilizing a risk-based approach to security management practice and internal audit can enable both streams to add value to the organization. It can help security management to identify and prioritize the more vulnerable components of the infrastructure and address those exposures appropriately. Similarly, a risk-based audit approach can help auditors to perform audits on the more critical parts of the infrastructure, understand the business requirements properly, and, reduce time and cost by conducting a more focused audit.

Enterprises’ organizational data centers increasingly are being managed by outsourcing partners. When it comes to partners’ compliance with an organization’s security policies, outsourced contracts that are poorly defined with regards to security can raise financial and fulfillment issues, putting the whole business at risk. Therefore, security management must be involved in every stage of the outsourcing lifecycle—from initial negotiations through to sign-off and maintenance of the contract. Additionally, security management must convince management, internal auditors and outsourcing partners to reach an agreement on the best solution and the way forward for the organization while mitigating the risks highlighted by the audit team.

Well-defined security management practices and their alignment with the business and internal security audit ensure the protection of organization’s information, data and IT services, and helps the organization to meet its objectives. As larger organizations increasingly adopt outsourcing strategies, the onus on the security management practitioner is growing too. With new threats emerging and technologies evolving, ensuring overall security of the organization can become a challenge from cost, process and effort standpoints if outsourcing contracts do not accommodate security policy updates too. Hence, it is critical that business management involves its security management practice when outsourcing its infrastructure.

Depending on organization’s business goals, resources and threat profile, security management can take a risk-based approach to advise which components of the infrastructure should be outsourced and yet be compliant with policies while mitigating the findings of the internal audit team. Security management and internal audit must work hand in hand to effectively secure the business. Otherwise, the two streams can become counterproductive to the cause.

Muhammad Waheed Qureshi, CISA, CIPP/IT, CISSP, ITIL V3 Foundation
IT Security Analyst, Accenture -Sweden

[ISACA]

English
Exit mobile version