- CISM
- Certified Information Security Manager — an ISACA certification for professionals who manage, design, and oversee an enterprise's information security program.
- Information Security Governance
- The domain covering the framework of policies, roles, and oversight structures that align an organization's security strategy with its business objectives.
- Information Security Risk Management
- The domain covering the identification, analysis, evaluation, and treatment of risks to information assets.
- Information Security Program
- The domain covering the design, implementation, and management of the people, processes, and technology that carry out an organization's security strategy.
- Incident Management
- The domain covering the planning, detection, response, and recovery activities used to handle security incidents and minimize their business impact.
- Scaled Score
- A statistically adjusted score, reported on a fixed range such as ISACA's 200-800 scale, that accounts for variation in difficulty across different exam forms.
- Risk Appetite
- The level and type of risk an organization is willing to accept in pursuit of its objectives, established by senior leadership.
- Risk Tolerance
- The acceptable variation around risk appetite for a specific objective or metric, defining how much deviation is permissible.
- Residual Risk
- The risk that remains after controls have been implemented to address inherent risk.
- Business Impact Analysis (BIA)
- A structured process to identify critical business functions and quantify the operational and financial impact of their disruption over time.
- Due Care
- The execution of reasonable, prudent actions to protect an organization's assets and reduce risk.
- Due Diligence
- The ongoing process of investigating and verifying that appropriate controls and precautions are actually in place and functioning.
- Key Risk Indicator (KRI)
- A measurable metric that signals rising risk exposure before it results in an adverse event.
- Defense in Depth
- A security architecture principle that layers multiple independent controls so no single point of failure compromises the entire system.
- CIA Triad
- The foundational security model of Confidentiality, Integrity, and Availability that controls are designed to preserve.
- Chain of Custody
- The documented chronological record of evidence handling that preserves its integrity and admissibility during an investigation.
- Tabletop Exercise
- A facilitated, discussion-based walkthrough of a hypothetical incident used to test and refine response plans.
- Business Continuity Plan (BCP)
- A documented plan for sustaining essential business operations during and after a disruptive event, encompassing more than just IT recovery.
- Risk Register
- A structured record listing identified risks along with their likelihood, impact, owner, and planned treatment.
- Security Steering Committee
- A cross-functional, senior-level governance body that oversees and prioritizes an organization's information security initiatives.
- PSI
- The third-party testing vendor ISACA uses to deliver the CISM exam at test centers and via online remote proctoring.