|
via Udemy |
Go to Course: https://www.udemy.com/course/issmp-information-systems-security-management-prof-qa-test/
ISSMP Information Systems Security Management Professional Exam Practice Test The Information Systems Security Management Professional (ISSMP) is security leader who specializes in establishing, presenting and governing information security programs and demonstrates management and leadership skills. ISSMPs direct the alignment of security programs with the organization's mission, goals and strategies in order to meet enterprise financial and operational requirements in support of its desired risk position.Proves your knowledge and leadership skills establishing, presenting and governing information security programsISSMP Exam Domain:-Domain 1: Leadership and Business ManagementEstablish security's role in organizational culture, vision and missionAlign security program with organizational governanceDefine and implement information security strategiesDefine and maintain security policy framework Determine applicable external standardsManage security requirements in contracts and agreementsManage security awareness and training programsDefine, measure and report security metricsPrepare, obtain and administer security budgetManage security programsApply product development and project management principlesDomain 2: Systems Lifecycle ManagementManage integration of security into Systems Development Life Cycle (SDLC)Integrate new business initiatives and emerging technologies into the security architectureDefine and oversee comprehensive vulnerability management programs (e.g., vulnerability scanning, penetration testing, threat analysis)Manage security aspects of change controlDomain 3: Risk ManagementDevelop and manage a risk management programConduct risk assessmentsManage security risks within the supply chain (e.g., supplier, vendor, third-party risk)Domain 4: Threat Intelligence and Incident ManagementEstablish and maintain threat intelligence programEstablish and maintain incident handling and investigation programDomain 5: Contingency ManagementFacilitate development of contingency plansDevelop recovery strategiesMaintain contingency plan, Continuity of Operations Plan (COOP), business continuity plan (BCP) and disaster recovery plan (DRP)Manage disaster response and recovery processDomain 6: Law, Ethics and Security Compliance ManagementIdentify the impact of laws and regulations that relate to information securityAdhere to the (ISC)2 Code of Ethics as related to management issuesValidate compliance in accordance with applicable laws, regulations and industry best practicesCoordinate with auditors and regulators in support of the internal and external audit processesDocument and manage compliance exceptions