What Is the CISM? Glossary & Key Terms

CISM
Certified Information Security Manager — an ISACA certification for professionals who manage, design, and oversee an enterprise's information security program.
Information Security Governance
The domain covering the framework of policies, roles, and oversight structures that align an organization's security strategy with its business objectives.
Information Security Risk Management
The domain covering the identification, analysis, evaluation, and treatment of risks to information assets.
Information Security Program
The domain covering the design, implementation, and management of the people, processes, and technology that carry out an organization's security strategy.
Incident Management
The domain covering the planning, detection, response, and recovery activities used to handle security incidents and minimize their business impact.
Scaled Score
A statistically adjusted score, reported on a fixed range such as ISACA's 200-800 scale, that accounts for variation in difficulty across different exam forms.
Risk Appetite
The level and type of risk an organization is willing to accept in pursuit of its objectives, established by senior leadership.
Risk Tolerance
The acceptable variation around risk appetite for a specific objective or metric, defining how much deviation is permissible.
Residual Risk
The risk that remains after controls have been implemented to address inherent risk.
Business Impact Analysis (BIA)
A structured process to identify critical business functions and quantify the operational and financial impact of their disruption over time.
RTO (Recovery Time Objective)
The maximum tolerable duration within which a business process or system must be restored after a disruption.
RPO (Recovery Point Objective)
The maximum acceptable amount of data loss, measured as a point in time to which data must be recoverable.
Due Care
The execution of reasonable, prudent actions to protect an organization's assets and reduce risk.
Due Diligence
The ongoing process of investigating and verifying that appropriate controls and precautions are actually in place and functioning.
Key Risk Indicator (KRI)
A measurable metric that signals rising risk exposure before it results in an adverse event.
Defense in Depth
A security architecture principle that layers multiple independent controls so no single point of failure compromises the entire system.
CIA Triad
The foundational security model of Confidentiality, Integrity, and Availability that controls are designed to preserve.
Chain of Custody
The documented chronological record of evidence handling that preserves its integrity and admissibility during an investigation.
Tabletop Exercise
A facilitated, discussion-based walkthrough of a hypothetical incident used to test and refine response plans.
Disaster Recovery Plan (DRP)
A documented plan focused on restoring IT systems, applications, and data after a disruptive event.
Business Continuity Plan (BCP)
A documented plan for sustaining essential business operations during and after a disruptive event, encompassing more than just IT recovery.
Risk Register
A structured record listing identified risks along with their likelihood, impact, owner, and planned treatment.
Security Steering Committee
A cross-functional, senior-level governance body that oversees and prioritizes an organization's information security initiatives.
PSI
The third-party testing vendor ISACA uses to deliver the CISM exam at test centers and via online remote proctoring.