Qualified experience for CICA™ certification
General characterization for eligible experience:
- Developing an Information Security Management System program
- Project managing a successful ISO 27001 internal controls implementation
- Core ISO 27001 and 27002 best practices relating to:
- Information security policy and scope
- Risk assessment and Statement of Applicability
- External party controls
- Asset management
- Human Resources security
- Physical and environmental security
- Equipment security
- Communications and operations management
- Malicious software controls
- Network security management and media handling
- Monitoring of information security and incident management
- Business continuity management
- Compliance Exchange of information
- Electronic commerce, e-mail and internet security
- General, network, operating system, and application access control
- Systems acquisition, development and maintenance
- Cryptographic controls
- Development and support process security
- Monitoring of information security and incident management
- Business continuity management
- Compliance


