Certified Information Security Manager Flashcards
Browse all 30 cards
What are the four CISM job practice domains?
Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
Which CISM domain carries the largest exam weight, and what is it?
Domain 3, Information Security Program, at 33% of the exam — the heaviest of the four domains.
How many questions are on the CISM exam and how long is the testing window?
150 multiple-choice questions administered over 240 minutes (4 hours).
What passing score must a CISM candidate achieve?
A scaled score of 450 or higher on ISACA's common scale of 200 to 800.
Why does ISACA report CISM results as scaled scores instead of raw or percentage scores?
Scaled scoring normalizes results across different exam forms of varying difficulty so that a given scaled score reflects the same level of competency regardless of which version a candidate took.
What is the primary objective of information security governance?
To align information security strategy with business objectives and ensure risks are managed appropriately, so security investments support organizational goals rather than operating in isolation from them.
Define 'risk appetite' as used in information security risk management.
The amount and type of risk an organization is willing to accept in pursuit of its business objectives, set by senior leadership before controls are designed.
What distinguishes inherent risk from residual risk?
Inherent risk is the level of risk that exists before any controls are applied; residual risk is what remains after controls have been implemented and are operating.
What is a Business Impact Analysis (BIA) used for?
To identify critical business processes and determine the impact of their disruption over time, driving recovery time and recovery point objectives for continuity planning.
Differentiate Recovery Time Objective (RTO) from Recovery Point Objective (RPO).
RTO is the maximum acceptable time to restore a process or system after disruption; RPO is the maximum acceptable amount of data loss measured in time, i.e., how far back the last usable backup must be.
What is the purpose of an information security steering committee?
To provide senior-level oversight and cross-functional decision-making that aligns security initiatives with business priorities and secures organizational buy-in.
What does 'due diligence' mean in an information security governance context?
The ongoing process of verifying that reasonable care is being exercised to protect assets, as opposed to 'due care,' which is the actual execution of reasonable protective measures.
What is the role of a RACI chart in security program management?
It clarifies accountability by defining who is Responsible, Accountable, Consulted, and Informed for a given task or decision, reducing ambiguity in security roles.
What is the difference between a policy, a standard, and a procedure?
A policy states management's intent and high-level requirements; a standard specifies mandatory, measurable criteria supporting the policy; a procedure gives step-by-step instructions for carrying out the standard.
What is a key risk indicator (KRI)?
A metric that provides early warning of increasing risk exposure, allowing management to take action before a risk event materializes.
What is the goal of security awareness training within a security program?
To reduce human-factor risk by ensuring personnel understand their security responsibilities and can recognize and respond appropriately to threats such as phishing or social engineering.
What is the difference between a security incident and a security event?
An event is any observable occurrence in a system or network; an incident is an event (or series of events) that violates security policy or threatens the confidentiality, integrity, or availability of an asset.
What are the typical phases of the incident response lifecycle?
Preparation, detection and analysis, containment, eradication, recovery, and post-incident review (lessons learned).
Why is a post-incident review important?
It captures lessons learned to improve detection, response procedures, and controls, reducing the likelihood and impact of similar future incidents.
What is the purpose of a disaster recovery plan (DRP) versus a business continuity plan (BCP)?
The DRP focuses narrowly on restoring IT systems and infrastructure after a disruptive event; the BCP is the broader plan for keeping essential business functions operating during and after a disruption.
What is 'defense in depth'?
A layered security strategy that uses multiple, overlapping controls so that if one control fails, others still protect the asset.
What does the CIA triad stand for in information security?
Confidentiality, Integrity, and Availability — the three core properties that security controls aim to protect.
What is the difference between a threat, a vulnerability, and a risk?
A threat is a potential cause of harm; a vulnerability is a weakness that could be exploited; risk is the likelihood and impact of a threat exploiting a vulnerability.
What is the purpose of a risk register?
A centralized log documenting identified risks, their likelihood and impact, owners, and treatment plans, used to track and manage risk over time.
Name the four common risk treatment options.
Avoid, mitigate (reduce), transfer (share), and accept.
What is chain of custody in incident evidence handling?
The documented, unbroken record of who collected, handled, and stored evidence, ensuring it remains admissible and untampered for investigative or legal purposes.
What is the purpose of a security metrics/dashboard program?
To translate technical security data into business-relevant indicators that demonstrate program effectiveness and support informed decision-making by management.
What is the role of senior management sponsorship in a security program's success?
It provides the authority, funding, and organizational priority needed to enforce policy, allocate resources, and drive cultural adoption of security practices.
What is a tabletop exercise?
A discussion-based simulation where stakeholders walk through an incident or disaster scenario to validate and improve response and recovery plans without disrupting live operations.
Why must security strategy be tied to business objectives rather than technology alone?
Because security exists to enable and protect business value; a strategy disconnected from business goals risks misallocating resources and failing to gain executive support.