Certified Information Security Manager (CISM) flashcards
180 free flashcards. Tap a card to flip it.
Supply Chain Resilience
Flip cardThe ability of a supply chain to withstand disruptions, recover quickly, and adapt to changing conditions, ensuring continuous operations.
- Crucial for organizations with complex supply dependencies.
- Involves proactive risk management and diversification.
- Focuses on reducing single points of failure.
Memory trick: Don't depend on one chain link; diversify to make it sink-proof.
Modular Incident Response Playbooks
Flip cardIncident response documentation structured into reusable components or modules that can be combined and adapted for various incident types and scenarios.
- Promotes consistency while allowing flexibility.
- Easier to update and maintain than monolithic playbooks.
- Supports automation and orchestration efforts.
Memory trick: Playbooks should be like LEGOs, buildable and adaptable.
Business-Security Alignment
Flip cardThe process of ensuring that information security strategies, controls, and investments support and enable an organization's overall business objectives.
- Requires communication between security and business leaders.
- Involves understanding business risk appetite.
- Ensures security is a business enabler, not just a cost center.
Memory trick: Align security: talk to business, know their goals.
Risk Treatment Options
Flip cardStrategies an organization can employ to address identified risks, including avoidance, mitigation/remediation, transfer, and acceptance.
- Should align with risk appetite.
- Involves cost-benefit analysis.
- Selected based on risk level and business impact.
Memory trick: Treat risks: Avoid, Mitigate, Transfer, Accept.
Information Security Governance
Flip cardInformation security governance is the system by which an organization directs and controls information security activities, ensuring alignment with business objectives, regulatory requirements, and risk tolerance.
- Provides strategic direction.
- Defines roles, responsibilities, and decision-making processes.
- Ensures compliance and manages risk at an organizational level.
Memory trick: Build the house on a strong foundation of rules and purpose.
DRP Communication Plan
Flip cardA component of the Disaster Recovery Plan that outlines how and when to communicate with internal and external stakeholders during and after a disaster.
- Addresses legal, regulatory, and ethical obligations.
- Manages reputation and maintains trust.
- Specifies communication channels, content, and responsible parties.
Memory trick: Speak clearly, or face legal woes.
Risk-adjusted ROI for Security
Flip cardA financial metric that quantifies the return on investment for security initiatives, factoring in the reduction of potential losses (risk mitigation) and the cost of the security controls.
- Demonstrates financial value of security.
- Relevant for executive and board-level reporting.
- Considers both cost of control and averted loss.
Memory trick: Board cares about ROI, especially when risk is involved.
Inter-Application Dependency Mapping
Flip cardThe process of identifying and documenting the relationships and dependencies between different applications, systems, and services within an organization.
- Crucial for effective disaster recovery planning.
- Ensures applications are restored in the correct sequence.
- Helps prevent cascading failures during recovery.
Memory trick: Map the web of apps to avoid recovery gaps.
Cross-training
Flip cardThe process of training employees to perform job functions outside of their primary responsibilities, often related to critical tasks or backup roles.
- Reduces reliance on single individuals for critical tasks.
- Improves organizational resilience and flexibility.
- Enhances employee skill sets and career development.
Memory trick: Don't put all your eggs (skills) in one basket (person).
Mitigating Single Point of Failure (BCP)
Flip cardStrategies employed within a Business Continuity Plan to prevent a single component, system, or vendor from causing a complete disruption of critical business operations.
- Involves redundancy, diversification, and alternative solutions.
- Critical for high-impact dependencies.
- Goes beyond contractual assurances to actual operational resilience.
Memory trick: SPOF mitigation needs 'D.R.A.F.T.': Diversify, Redundancy, Alternate vendors, Failover planning, and Testing alternatives.
Incident Response Policy
Flip cardA formal document that establishes the organization's approach to incident response, outlining objectives, roles, responsibilities, and guiding principles.
- Provides strategic direction for incident management.
- Defines authority and scope for incident responders.
- Ensures consistency and compliance across the organization.
Memory trick: Policy is the bedrock, not the building itself.
Recovery Point Objective (RPO)
Flip cardThe maximum amount of data (measured in time) that an organization can afford to lose during a disaster or incident.
- Determined by business impact analysis.
- Dictates backup frequency and replication strategies.
- Expressed as a time interval (e.g., 1 hour, 24 hours).
Memory trick: RPO is about Point in time (data), RTO is about Time to operate (system).
Mean Time To Detect (MTTD)
Flip cardThe average time it takes an organization to identify a security incident from the moment it began.
- Measures the efficiency of monitoring and alerting systems.
- A lower MTTD indicates better visibility and faster initial response.
- Crucial for minimizing the impact of incidents by enabling early action.
Memory trick: To catch a thief, you first need to 'Detect' they're there.
Business Impact Analysis (BIA)
Flip cardA systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
- Identifies critical business functions and processes.
- Determines recovery time objectives (RTO) and recovery point objectives (RPO).
- Essential for prioritizing security controls and resilience efforts.
Memory trick: BIA builds the security foundation.
Intangible Costs of Incidents
Flip cardNon-monetary losses resulting from a security incident that are difficult to quantify but can significantly impact an organization's long-term viability.
- Includes damage to reputation, customer trust, and brand value.
- Can lead to loss of market share and future revenue.
- Often more substantial in the long run than direct costs.
Memory trick: Reputation is like smoke, hard to catch and put a price on.
Disaster Recovery Failback
Flip cardThe process of restoring business operations from the disaster recovery site back to the primary production site after a disaster has been resolved.
- Often more complex than the initial failover due to data synchronization challenges.
- Requires careful planning to avoid data loss and minimize business disruption.
- A critical, often overlooked, phase of the overall disaster recovery lifecycle.
Memory trick: Returning home without a plan causes more chaos.
Federated Incident Response Model
Flip cardAn incident response model that combines elements of centralized and distributed approaches, allowing local teams to handle incidents independently while a central team provides governance, shared services, and manages major incidents.
- Balances local autonomy with central oversight.
- Promotes consistency while enabling flexibility.
- Effective for large, geographically dispersed organizations.
Memory trick: Federated: United by a core, flexible in the field.
Mean Time To Remediate (MTTR)
Flip cardThe average time it takes for an organization to resolve a detected security vulnerability or incident from the point of discovery to full resolution.
- Measures efficiency of remediation processes.
- High MTTR indicates remediation bottlenecks.
- Influenced by patch management and incident response effectiveness.
Memory trick: MTTR means Must Take Timely Remediation.
Cold Site
Flip cardA disaster recovery site that has basic infrastructure (power, cooling, space) but lacks specific hardware, software, or data. It requires significant time and effort to become operational.
- Lowest cost DR option.
- Longest recovery time (RTO).
- Suitable for non-critical systems or unique hardware requirements with budget constraints.
Memory trick: For old, unique tech on a budget, a cold site is the bold choice.
Scalable Incident Response Structure
Flip cardAn incident response team organization that can dynamically adjust its size, resources, and command structure based on the severity and complexity of an incident.
- Allows for efficient resource allocation.
- Ensures appropriate response for all incident types.
- Prevents teams from being overwhelmed or underutilized.
Memory trick: An IR team should be like a chameleon, changing with the incident.
Risk Treatment Strategies
Flip cardRisk treatment strategies are the approaches an organization takes to manage identified risks, typically categorized as Avoid, Transfer, Mitigate, or Accept.
- Avoid: Eliminate the activity causing the risk.
- Transfer: Shift the risk to a third party (e.g., insurance).
- Mitigate: Reduce the likelihood or impact of the risk.
- Accept: Acknowledge and monitor the risk without further action.
Memory trick: When the old castle can't be rebuilt, you build defenses around it.
Incident Commander
Flip cardThe individual responsible for the overall management of a security incident, including strategic direction, operational planning, and resource allocation.
- Single point of authority during an incident.
- Ensures effective communication and coordination.
- Focuses on achieving incident response objectives.
Memory trick: The Commander's Shield protects the incident.
Lean Incident Response
Flip cardAn incident response methodology that prioritizes efficiency, rapid recovery, and leveraging existing resources, often suitable for organizations with limited budgets or cloud-native environments.
- Focuses on minimum viable response.
- Emphasizes agility and cost-effectiveness.
- Leverages cloud provider security features and SaaS capabilities.
Memory trick: For a lean startup, a lean IR is the smart start.
Forensic Readiness
Flip cardThe organization's ability to collect, preserve, and analyze digital evidence in a legally sound and forensically sound manner during and after a security incident.
- Crucial for legal action, regulatory compliance, and post-incident analysis.
- Requires predefined procedures and trained personnel.
- Evidence must be collected without alteration to maintain its integrity.
Memory trick: No evidence, no justice, no recovery.
Threat Intelligence
Flip cardThreat intelligence is evidence-based knowledge, including context, mechanisms, indicators, implications and actionable advice, about an existing or emerging menace or hazard to assets.
- Proactive, not reactive.
- Informs security decisions and defenses.
- Covers TTPs (Tactics, Techniques, Procedures) of adversaries.
Memory trick: To see the future threats, you need intelligence.
Post-Incident Review (Lessons Learned)
Flip cardA formal process conducted after a security incident to analyze what happened, evaluate the effectiveness of the response, identify root causes, and determine improvements.
- Critical for continuous improvement.
- Identifies root causes.
- Informs policy and control updates.
Memory trick: After the fire, inspect the ashes to prevent the next one.
Compensating Controls
Flip cardAlternative security controls that are implemented to meet the intent of a security requirement when the primary control cannot be implemented or is not fully effective.
- Used when primary control is not feasible.
- Reduces risk to an acceptable level.
- Often temporary until a permanent solution.
Memory trick: Compensating Controls: A temporary fix to bridge the gap.
Incident Command Structure (ICS)
Flip cardA standardized, on-scene, all-hazards incident management concept that allows users to adopt an integrated organizational structure to match the complexities and demands of single or multiple incidents without being hindered by jurisdictional boundaries.
- Scalable and flexible for incidents of any size.
- Establishes clear chain of command and communication.
- Focuses on common terminology and modular organization.
Memory trick: ICS structures chaos into clarity.
OT Security Strategy
Flip cardSpecific security controls and practices designed to protect operational technology (OT) systems, which control physical processes, from cyber and physical threats.
- Prioritizes safety and availability over confidentiality.
- Often involves network segmentation and physical controls.
- Addresses unique protocols and legacy systems.
Memory trick: OT Security: Segment and Protect the Physical.
Data Residency
Flip cardThe requirement for data to be stored and processed within specific geographic boundaries, often due to legal or regulatory mandates.
- Driven by national laws and regulations.
- Impacts cloud computing and global data flows.
- Requires careful architectural planning.
Memory trick: Data residency: data must sleep where the law lives.
STRIDE Threat Modeling
Flip cardA systematic threat modeling methodology used to identify and classify threats to applications and systems based on six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
- Used early in the SDLC.
- Categorizes threats for systematic analysis.
- Helps design security controls proactively.
Memory trick: STRIDE for application threats.
Continuous Monitoring
Flip cardThe ongoing process of collecting, analyzing, and reporting data from security controls and systems to maintain a continuous awareness of an organization's security posture.
- Ensures security controls remain effective.
- Facilitates adaptation to evolving threats.
- Supports real-time risk assessment.
Memory trick: Continuous Monitoring: Always Watching, Always Adapting.
ICS Security Priorities
Flip cardThe distinct security objectives and control priorities for Industrial Control Systems (ICS) compared to traditional IT systems.
- Availability and integrity are often paramount.
- Safety is a critical consideration.
- Utilizes specialized protocols and hardware.
Memory trick: ICS: Availability & Integrity are the keys to keeping the factory running safely.
Annualized Loss Expectancy (ALE)
Flip cardThe expected monetary loss from a risk over a one-year period, calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO).
- Quantifies financial risk.
- Used for cost-benefit analysis of security controls.
- Helps prioritize risk mitigation efforts.
Memory trick: Speak the language of money, and the board will listen.
Incident Response Objectives
Flip cardClear, measurable goals that guide an organization's actions during and after a security incident, ensuring a structured and effective response.
- Crucial for aligning incident response with business goals.
- Help prioritize actions during an incident.
- Vary based on organization's risk profile and regulatory environment.
Memory trick: An incident's objective is to 'C.R.E.A.T.E.' a safe environment: Contain, Recover, Eradicate, Analyze, Train, and Evidence.
Third-Party DR Alignment
Flip cardEnsuring that the disaster recovery capabilities and objectives (e.g., RTOs, RPOs) of third-party vendors and cloud providers are aligned with, and capable of supporting, the organization's own DRP requirements.
- Critical for services hosted externally.
- Typically managed through Service Level Agreements (SLAs).
- Discrepancies can lead to significant recovery gaps.
Memory trick: Align your clocks with your partners, or be late.
GRC Framework
Flip cardGovernance, Risk, and Compliance (GRC) is a structured approach to aligning IT with business objectives, managing risk, and meeting compliance requirements across an organization.
- Integrates governance, risk, and compliance functions.
- Provides a holistic view of organizational performance.
- Helps manage complex regulatory landscapes efficiently.
Memory trick: GRC, the Global Regulatory Compass.
Static Application Security Testing (SAST)
Flip cardA 'white-box' testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Identifies vulnerabilities early in the SDLC.
- Works on non-running code.
- Often integrated into CI/CD pipelines.
Memory trick: SAST shifts security left, saving time and stress.
Incident Communication Plan
Flip cardA documented strategy outlining how an organization will communicate during and after a security incident, specifying stakeholders, messaging, channels, and timelines.
- Ensures timely and accurate information dissemination.
- Manages expectations and mitigates reputational damage.
- Tailored for different internal and external audiences.
Memory trick: To fix the talk lag, make a communication plan, no sag.
Threat Hunting
Flip cardThreat hunting is a proactive cybersecurity activity that involves iteratively and proactively searching for and detecting threats that are lurking undetected in a network.
- Focuses on finding unknown or advanced threats.
- Goes beyond automated security alerts.
- Requires skilled analysts and specialized tools.
Memory trick: To be proactive, you must hunt the shadows before they strike.
Incident Command Structure (ICS) Initial Response
Flip cardThe immediate actions and priorities of the Incident Commander and team upon declaration of a major incident, focusing on establishing order and control.
- Emphasizes clear leadership and defined roles.
- Crucial for managing complex, multi-faceted incidents.
- Promotes efficient resource allocation and communication.
Memory trick: Initial response needs 'C.L.A.R.I.T.Y.': Command established, Leadership, Action plan, Roles defined, Information flow, Team organization, Yield to expert advice.
IT/OT Convergence Security
Flip cardThe process of integrating information technology (IT) systems with operational technology (OT) systems, requiring specialized security strategies to manage distinct risk profiles, priorities, and capabilities.
- OT prioritizes safety and availability over confidentiality.
- Legacy OT systems are often unpatchable.
- Segmentation (e.g., DMZ, data diodes) is critical for risk reduction.
Memory trick: OT needs One-way Traffic to IT.
Post-Incident Review
Flip cardA formal process after an incident to analyze what happened, how it was handled, and what can be improved.
- Identifies lessons learned.
- Leads to updates in incident response plans and policies.
- Aims for continuous improvement in security posture.
Memory trick: Learn from the past to secure the future.
BCP Workarounds
Flip cardBusiness Continuity Plan (BCP) workarounds are pre-defined alternative manual or temporary processes that allow critical business functions to continue operating when automated systems or primary infrastructure are unavailable.
- Crucial for systems with high RTOs or single points of failure.
- Focus on maintaining business function, not just IT recovery.
- Requires thorough documentation and staff training.
Memory trick: When the bridge is out, find another path.
Security Orchestration, Automation, and Response (SOAR)
Flip cardA collection of software capabilities that enable organizations to collect security threat data, orchestrate tools, and automate responses to low-level security events without human intervention.
- Automates repetitive tasks.
- Streamlines incident response.
- Improves SOC efficiency.
Memory trick: Automate the routine, orchestrate the complex.
Hot Site
Flip cardA fully equipped, offsite data center that can be operational within hours, often with mirrored or real-time replicated data from the primary site.
- Provides the quickest recovery time (lowest RTO).
- Minimizes data loss (lowest RPO) through continuous replication.
- Most expensive recovery option due to ongoing operational costs.
Memory trick: Hot sites are like having a twin data center ready to jump in.
Human Factors in BCP
Flip cardThe consideration of human resource availability, skills, and welfare as integral components of a successful business continuity plan.
- Ensures that qualified personnel are available to perform critical functions.
- Includes plans for communication, transportation, and welfare of employees.
- Often overlooked but vital for effective recovery and resumption of operations.
Memory trick: People are the power behind the plan.
Return on Security Investment (ROSI)
Flip cardROSI is a metric used to quantify the financial benefits of information security investments by comparing the cost of security controls to the financial losses avoided due to those controls.
- Helps justify security spending.
- Calculated as: (Avoided Loss - Cost of Investment) / Cost of Investment.
- Provides a business-centric view of security value.
Memory trick: To show the money, you need to calculate the return.
Annualized Savings
Flip cardThe net financial benefit realized from implementing a security control, calculated by subtracting the annual cost of the control from the reduction in Annualized Loss Expectancy (ALE).
- Measures the financial gain of a security control.
- Calculated as (ALE reduction - control cost).
- Helps justify security investments.
Memory trick: Savings = (ALE reduction) - (Control Cost).
External IR Team Integration
Flip cardThe process of bringing in and managing third-party incident response experts during a major security incident.
- Requires clear legal agreements (NDAs) and defined responsibilities (SOW).
- Focuses on secure and controlled access to organizational systems and data.
- Aims to augment internal capabilities without introducing new risks.
Memory trick: Legal first, then tools and access.
BCP Exercise Outcomes
Flip cardThe identification of gaps, weaknesses, and areas for improvement in business continuity and disaster recovery plans through testing and simulation.
- Primary goal is continuous improvement.
- Requires thorough documentation of findings.
- Leads to remediation plans and plan updates.
Memory trick: Test to learn, not just to pass; fix what breaks fast.
NIST Incident Response Lifecycle (CER Phase)
Flip cardThe 'Containment, Eradication, and Recovery' phase of the NIST Incident Response Lifecycle focuses on limiting the scope and impact of an incident, removing the root cause, and restoring affected systems and services to normal operation.
- Follows Detection and Analysis.
- Aims to stop the attack and prevent further damage.
- Includes activities like isolating systems, removing malware, and restoring from backups.
Memory trick: After finding the fire, put it out and rebuild.
DR Inter-Application Dependency Testing
Flip cardA critical component of disaster recovery testing that validates the proper communication, integration, and functionality of interdependent applications and services after recovery.
- Ensures the entire business ecosystem functions.
- Identifies network, firewall, and configuration issues.
- Goes beyond individual system restoration.
Memory trick: Restoring apps is like putting puzzle pieces back, but dependency testing ensures they 'click' together.
Lessons Learned Process
Flip cardA systematic process of identifying, documenting, and disseminating knowledge gained from incident response activities to improve future performance.
- Occurs during post-incident review.
- Identifies what went well, what went wrong, and what could be improved.
- Drives updates to policies, procedures, and training.
Memory trick: Learn from the past to secure the future.
Risk Appetite
Flip cardRisk appetite is the amount and type of risk that an organization is willing to take in pursuit of its objectives.
- Set by the board/senior management.
- Guides risk management decisions.
- Considers both potential gains and losses.
Memory trick: The CISO is the translator between tech fear and business goals.
Third-Party Risk Management
Flip cardThe process of identifying, assessing, and mitigating risks associated with external vendors, suppliers, and partners.
- Requires due diligence and continuous monitoring.
- Contractual agreements (SLAs) are crucial.
- Risks can include data breaches, service disruptions, and compliance failures.
Memory trick: When working with partners, treat their risks like yours; contractually bind them to your standards.
Global Regulatory Compliance
Flip cardGlobal regulatory compliance refers to an organization's adherence to all applicable laws, regulations, and standards across every jurisdiction in which it operates, particularly concerning data protection and privacy.
- Crucial for multinational operations.
- Includes GDPR, CCPA, HIPAA, local data residency laws.
- Non-compliance can lead to severe penalties and reputational damage.
Memory trick: When data crosses borders, laws are your first and greatest concern.
Quantitative Risk Assessment
Flip cardA risk assessment method that assigns numerical values (typically monetary) to assets, threats, vulnerabilities, and the likelihood and impact of risks, allowing for calculation of potential financial losses.
- Uses numerical values for risk factors.
- Calculates potential financial losses.
- Enables cost-benefit analysis for security controls.
Memory trick: Quantify losses to prioritize wisely.
Maximum Tolerable Downtime (MTD)
Flip cardThe absolute maximum period of time an organization can tolerate for a system or business function to be unavailable after a disaster or incident.
- Determined by Business Impact Analysis (BIA).
- Drives RTO and RPO requirements.
- Critical for selecting appropriate recovery strategies.
Memory trick: Hot, Warm, Cold: Speed costs money. Cold is cheap, Hot is fast.
Federated Incident Response
Flip cardAn incident response model where local or business unit teams handle initial incidents, escalating to a central team for complex or critical events.
- Leverages local expertise and faster initial response.
- Challenges include maintaining consistency and central oversight.
- Requires strong governance and communication frameworks.
Memory trick: Federated is flexible but fragmented.