Certified Information Security Manager (CISM) flashcards
180 free flashcards. Tap a card to flip it.
OT Incident Recovery Priority
Flip cardIn Operational Technology (OT) environments, recovery efforts are primarily prioritized based on ensuring human safety, environmental protection, and then operational continuity.
- Safety of personnel and public is paramount.
- Protection of the environment is a critical concern.
- Operational continuity follows safety and environmental considerations.
Memory trick: In OT, Safety First, then Environment, then Operations.
DR Human Factor Mitigation
Flip cardStrategies to ensure that personnel involved in disaster recovery are adequately trained, familiar, and prepared to execute recovery procedures efficiently under stressful conditions.
- Addresses skill gaps and lack of experience.
- Crucial for effective and timely recovery.
- Goes beyond documentation to practical readiness.
Memory trick: DR humans need 'T.R.A.I.N.': Training, Regular exercises, Awareness, Information sharing, and New role familiarization.
SOAR (Security Orchestration, Automation, and Response)
Flip cardA technology solution that combines incident response, security operations automation, and security orchestration capabilities into a single platform.
- Automates repetitive security tasks.
- Orchestrates disparate security tools.
- Helps standardize and accelerate incident response procedures.
Memory trick: SOAR makes your IR team fly, not just walk faster.
Service Level Agreement (SLA)
Flip cardA contractual agreement that defines the level of service expected from a service provider, including metrics like uptime, response times, and responsibilities.
- Legally binding document.
- Specifies performance metrics and penalties for non-compliance.
- Common in outsourced IT services and cloud computing.
Memory trick: SLAs are the 'Service Law' for incidents.
Incident Classification & Severity Matrix
Flip cardA structured tool used in incident management to categorize incidents based on predefined criteria, determining their severity and the appropriate response level.
- Defines thresholds for incident escalation.
- Ensures consistent incident handling.
- Guides resource allocation and communication.
Memory trick: To know when to 'raise the alarm,' you need a clear 'map' of severity.
DR User Acceptance Testing (UAT)
Flip cardA phase in disaster recovery testing where end-users validate that recovered systems and applications function correctly, meet business requirements, and are usable in the disaster recovery environment.
- Focuses on user experience and business process functionality.
- Identifies gaps between recovery and operational needs.
- Ensures smooth transition for end-users post-recovery.
Memory trick: Users can't use it if they haven't tested it.
Cost of Incident (COI)
Flip cardA metric used to calculate the total financial burden of a security incident, including direct, indirect, and intangible costs.
- Includes lost revenue, mitigation expenses, legal fees.
- Can also account for reputational damage and customer churn.
- Helps organizations justify security investments and prioritize risks.
Memory trick: Metrics 'M.E.A.S.U.R.E.': Mean Time, Efficacy, Alert Rate, Severity, Utilization, Recovery, and Expenses.
Federated IR Coordination
Flip cardEnsuring consistent reporting and threat intelligence sharing across decentralized incident response teams in a federated model, balancing local autonomy with global visibility.
- Maintains local response capability.
- Requires standardized processes for global aggregation.
- Leverages centralized platforms for intelligence sharing.
Memory trick: Many local 'eyes' need a 'central brain' to see the whole picture.
OT Incident Response Priority
Flip cardIn operational technology (OT) environments, the primary concern during a cyber incident is human safety and the prevention of physical damage, even above data confidentiality or system availability.
- OT incidents can lead to physical harm or environmental damage.
- Response priorities differ significantly from IT incidents.
- Requires specialized expertise and safety protocols.
Memory trick: OT incidents demand 'S.A.F.E.T.Y.': Safety first, Assess physical impact, Functionality preservation, Emergency procedures, Technical containment, Yield to physical safety.
Third-Party Risk Assessment
Flip cardThe process of identifying, analyzing, and evaluating risks introduced by external vendors, suppliers, or partners to an organization's information security.
- Crucial for supply chain security.
- Includes contractual and technical reviews.
- Ongoing process, not a one-time event.
Memory trick: Don't just react, reassess with your partner.
Privacy by Design
Flip cardAn approach to system engineering that embeds privacy and data protection into the design and operation of IT systems, networked infrastructure, and business practices, rather than as an afterthought.
- Proactive, not reactive.
- Privacy as the default setting.
- Emphasizes end-to-end security.
Memory trick: Global privacy: build it right from the start with 'Privacy by Design'.
Tailored GRC Framework
Flip cardA customized Governance, Risk, and Compliance (GRC) framework that integrates elements from various industry standards, regulatory requirements, and internal policies to address an organization's unique operational and risk profile.
- Combines multiple standards and regulations.
- Addresses specific organizational context and risks.
- Provides a holistic approach to governance, risk, and compliance.
Memory trick: Global GRC: Tailor-made for diverse rules and risks.
Privacy by Design (PbD)
Flip cardAn approach to systems engineering that aims to embed privacy into the design and operation of IT systems, networked infrastructure, and business practices from the initial stages.
- Proactive, not reactive; preventative, not remedial.
- Privacy is embedded into design.
- Offers full lifecycle protection.
Memory trick: Privacy by Design: Build it in, don't bolt it on.
Incident Response Lifecycle
Flip cardA structured approach to managing security incidents from preparation through post-incident activities.
- Typically includes Preparation, Identification, Containment, Eradication, Recovery, and Post-Incident Activity.
- Ensures systematic handling of incidents.
- Aims to minimize impact and prevent recurrence.
Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons.
SOAR Platform
Flip cardSecurity Orchestration, Automation, and Response (SOAR) platforms combine incident response, security operations automation, and threat intelligence management capabilities into a single solution.
- Automates repetitive security tasks.
- Orchestrates workflows across security tools.
- Improves incident response speed and consistency.
Memory trick: SOAR: Automate, Orchestrate, Respond Fast.
Risk Analysis
Flip cardThe process of identifying and evaluating potential risks, determining their likelihood and impact, to prioritize and develop appropriate mitigation strategies.
- Involves assessing likelihood and impact.
- Quantitative and qualitative methods can be used.
- Informs risk treatment decisions.
Memory trick: Risk management is like a doctor's visit: first, diagnose the problem, then assess its severity, and finally, prescribe treatment.
Cloud-Native Disaster Recovery
Flip cardDR strategies specifically designed to leverage the inherent capabilities of cloud platforms, such as global distribution, elasticity, and automation.
- Often involves active-active or active-passive multi-region deployments.
- Emphasizes automation, infrastructure-as-code, and resilience built into application design.
- Aims for low RTO/RPO by distributing resources and data.
Memory trick: Cloud-native DR means your app lives everywhere, all the time.
Risk Mitigation
Flip cardThe process of implementing controls or countermeasures to reduce the likelihood or impact of identified risks to an acceptable level.
- Aims to reduce risk likelihood or impact.
- Involves implementing security controls.
- Does not eliminate the risk entirely.
Memory trick: Avoid, Transfer, Mitigate, or Accept the risk.
SIEM Optimization
Flip cardThe process of refining Security Information and Event Management (SIEM) systems to improve their effectiveness, reduce false positives, and enhance threat detection and response.
- Involves rule tuning, baseline establishment, and data source integration.
- Aims to reduce alert fatigue.
- Essential for efficient security operations.
Memory trick: SIEM: Tune the noise, find the signal.
Application Recovery Validation in DR
Flip cardThe process of verifying that applications not only restore successfully in a disaster recovery environment but also function correctly with their dependencies and configurations.
- Goes beyond mere data restoration.
- Identifies environmental and configuration drift.
- Crucial for achieving RTOs and business continuity.
Memory trick: DR apps need 'C.O.N.F.I.G.S.': Configuration testing, Operational validation, Network alignment, Functional checks, Integration testing, Governance, and Scalability.
Shift Left Security
Flip cardThe practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC).
- Aims to find and fix vulnerabilities early, reducing cost.
- Involves developer education, automated testing, and secure design.
- Key principle of DevSecOps.
Memory trick: Shift Left: secure early, save later.
Data Classification
Flip cardThe process of categorizing data based on its sensitivity, value, and regulatory requirements to determine appropriate protection measures.
- Foundation for data security policies.
- Enables compliance with privacy regulations.
- Helps prioritize security efforts.
Memory trick: Classify data first, then protect what you know.
Incident Response Playbook Design
Flip cardGuidelines and best practices for structuring incident response playbooks to ensure effectiveness, clarity, and ease of use by responders.
- Focuses on practical, step-by-step instructions.
- Aims to reduce decision-making time and human error during incidents.
- Should be concise, actionable, and regularly updated.
Memory trick: Keep it clear, concise, and quick to execute.
Rapid BIA for Incident Recovery
Flip cardA focused, expedited business impact analysis performed during or immediately after a major incident to determine the current impact on critical business functions and systems, informing recovery prioritization.
- Differs from a pre-incident BIA by focusing on current, real-time impacts.
- Helps prioritize recovery efforts to minimize business disruption and financial loss.
- Essential when resources are limited and quick decisions are needed.
Memory trick: Impact analysis guides the fastest recovery path.
Supply Chain Diversification
Flip cardThe strategy of sourcing critical components or services from multiple vendors to reduce reliance on a single supplier and mitigate risks associated with vendor failure.
- Reduces single points of failure.
- Enhances resilience against vendor disruptions.
- Requires careful management of multiple vendor relationships.
Memory trick: Don't put all your supply eggs in one vendor basket.
Security Program Metrics
Flip cardQuantifiable measures used to assess the performance, effectiveness, and maturity of an information security program.
- Should align with business objectives.
- Include operational, technical, and management metrics.
- Used for reporting, decision-making, and continuous improvement.
Memory trick: Measure what matters: outcomes over efforts.
Security by Design
Flip cardSecurity by Design is an approach to software and system development that aims to build security into the initial design and architecture, rather than adding it as an afterthought.
- Integrates security from the outset.
- Reduces vulnerabilities and costs in the long run.
- Involves threat modeling, secure coding, and architecture reviews.
Memory trick: Building security in, not bolting it on later.
Dependency Mapping
Flip cardThe process of identifying and documenting the interconnections and relationships between an organization's critical business processes, applications, data, infrastructure, and external services.
- Crucial for understanding impact of component failures.
- Essential for effective incident response and disaster recovery.
- Helps prioritize recovery efforts and identify single points of failure.
Memory trick: Map out your path, or you'll get lost in DR.
DRP User Acceptance Testing (UAT)
Flip cardA critical phase in disaster recovery planning where business users validate the functionality, performance, and data integrity of restored applications and systems.
- Ensures restored systems meet business requirements.
- Identifies issues before full production resumption.
- Requires active participation from business unit representatives.
Memory trick: Restoring systems is like baking a cake; UAT is the taste test to ensure it's actually edible for the business.
Succession Planning (BCP)
Flip cardSuccession planning in Business Continuity Planning (BCP) is the process of identifying and developing internal people with the potential to fill key business leadership positions in the event of unforeseen vacancies.
- Ensures continuity of critical roles.
- Reduces impact of loss of key personnel.
- Essential for human resource resilience in BCP.
Memory trick: Key people's shoes must be fillable, quickly.
Cloud-Native DR Strategy
Flip cardA disaster recovery approach specifically designed for applications built and deployed using cloud computing principles and services.
- Leverages cloud provider's inherent resilience and global infrastructure.
- Utilizes features like multi-region deployment, auto-scaling, and managed services.
- Focuses on automation and infrastructure-as-code for rapid recovery.
Memory trick: Use the cloud's own tools for cloud problems.
Vendor Risk Management (VRM) Foundations
Flip cardThe essential initial components and legal mechanisms required to establish an effective program for managing information security risks posed by third-party vendors.
- Contractual agreements are paramount.
- Establishes legal enforceability of security requirements.
- Provides the basis for audits and monitoring.
Memory trick: Start with the handshake and the fine print; everything else flows from there.
Agile Security Governance
Flip cardAn approach to information security governance that embraces flexibility, adaptability, and integration with business processes to support innovation and agility, rather than imposing rigid, traditional controls that can hinder speed.
- Security as an enabler, not a blocker.
- Prioritizes continuous feedback and improvement.
- Tailored to dynamic organizational cultures.
Memory trick: Security must be the seatbelt, not the brake pedal, for innovation.
Security in Strategic Planning
Flip cardThe proactive embedding of information security considerations, risk management, and objectives into an organization's overarching strategic business planning process.
- Ensures security is a business enabler, not a blocker.
- Identifies security risks and opportunities early.
- Aligns security investments with strategic priorities.
Memory trick: Don't just guard the ship; help design its voyage, considering all storms.
Jurisdictional Legal Assessment
Flip cardThe process of identifying and analyzing all applicable laws, regulations, and contractual obligations relevant to information security within each geographical region an organization operates.
- Crucial for global organizations.
- Ensures compliance with diverse legal landscapes.
- Informs policy development and control implementation.
Memory trick: Know every law, in every land you play.
M&A Security Due Diligence
Flip cardThe process of thoroughly investigating and evaluating the information security posture, risks, and liabilities of a target company during a merger or acquisition.
- Identifies security risks before integration.
- Protects the acquiring company from inheriting vulnerabilities.
- Ensures compliance and data integrity post-acquisition.
Memory trick: Before you buy, identify the crown jewels you're getting and how shiny they are.
Measuring InfoSec Value
Flip cardQuantifying and communicating the tangible benefits and return on investment (ROI) of information security initiatives to business stakeholders, especially leadership.
- Translates security into business terms.
- Justifies security investments.
- Aligns security with enterprise objectives.
Memory trick: Speak the language of business: money and risk.
Tiered Vendor Risk Management
Flip cardA strategy for managing third-party security risks by categorizing vendors based on their criticality to the business and the sensitivity of data they access or process, then applying proportionate security controls and oversight.
- Optimizes resource allocation.
- Ensures focus on highest-risk vendors.
- Scalable for diverse vendor ecosystems.
Memory trick: Don't treat all partners the same; some need more security.
Business Alignment of Security
Flip cardThe process of ensuring that information security strategies, objectives, and investments directly support and enable the overarching business goals and objectives of an organization.
- Translates security benefits into business value.
- Crucial for gaining executive buy-in and resource allocation.
- Focuses on enabling growth, protecting assets, and maintaining trust.
Memory trick: Speak the board's language: money, growth, and reputation.
Security in System Lifecycle (SLC)
Flip cardThe practice of embedding security considerations and activities into every phase of a system's acquisition, development, and operational lifecycle, from planning to disposal.
- Ensures security is 'built-in', not 'bolted-on'.
- More cost-effective to address security early.
- Crucial for effective information security governance over new systems.
Memory trick: Build security in, from the start, for the system's heart.
Communicating Security Business Value
Flip cardArticulating the benefits of information security initiatives in terms that resonate with business leadership, focusing on how security enables business objectives, reduces risk, and contributes to strategic goals and financial performance.
- Translates technical security to business language.
- Focuses on enablement, not just prevention.
- Quantifies impact on revenue, risk, and reputation.
Memory trick: Show them the money, not just the locks.
Executive Security Reporting (Strategic Focus)
Flip cardPresenting information security risks and posture to executive leadership and the board in a strategic, business-oriented manner, emphasizing impacts on profitability, reputation, compliance, and legal liability rather than just technical details.
- Translate technical risks to business impact.
- Focus on regulatory, legal, and reputational risks.
- Align with executive decision-making priorities.
- Avoid excessive technical jargon.
Memory trick: Report business consequences, not just tech details.
Strategic Alignment (InfoSec)
Flip cardThe principle of ensuring that information security strategies, investments, and activities are directly linked to and support the organization's overall business objectives, mission, and strategic plan.
- Essential for gaining executive support and resource allocation.
- Ensures security efforts deliver business value.
- Involves understanding business goals, risk appetite, and regulatory landscape.
Memory trick: Before you build security, know the business's heart and its risk start.
InfoSec Steering Committee Composition
Flip cardThe selection of members for an information security steering committee, emphasizing diverse representation from business units, executive leadership, and relevant departments to ensure strategic alignment and enterprise-wide support.
- Crucial for strategic alignment.
- Ensures broad organizational buy-in.
- Facilitates resource allocation and prioritization.
- Avoids security operating in a silo.
Memory trick: Diverse voices steer the security ship.
Security Champion Program
Flip cardA program that designates and trains employees from various departments to act as security advocates and liaisons within their teams, fostering a peer-driven security culture and embedding security awareness more deeply into daily operations.
- Empowers internal advocates.
- Fosters peer-driven security culture.
- Integrates security into daily work.
Memory trick: To change the tide, empower the people.
Cultural Reinforcement (Security)
Flip cardThe process of strengthening and embedding desired information security behaviors and values within an organization's culture through communication, education, leadership example, and positive reinforcement.
- Focuses on understanding the 'why' behind policies.
- Builds a sense of shared responsibility.
- More effective for long-term change than purely punitive measures.
Memory trick: To change behavior, illuminate the 'why' and its real-world impact.
InfoSec Governance Framework
Flip cardA structured system of processes, roles, and responsibilities that directs and controls an organization's information security activities to align with business objectives and manage risks.
- Ensures strategic alignment and risk management.
- Defines accountability and decision-making authority.
- Comprises policies, organizational structures, and processes.
Memory trick: To build governance, first define who does what, and who reports where.
Strategic Alignment in InfoSec Governance
Flip cardEnsuring that information security objectives and activities are directly supportive of and integrated with the organization's overall business strategy and goals.
- Foundation for effective security governance.
- Ensures security investments provide business value.
- Prevents security from being a siloed function.
Memory trick: Build security on business goals, not just tech.
M&A Security Due Diligence (Governance Focus)
Flip cardDuring mergers and acquisitions, assessing the target company's information security governance structure, risk management processes, and security culture to identify integration risks, liabilities, and alignment challenges.
- Goes beyond technical vulnerabilities.
- Reveals cultural fit and operational compatibility.
- Critical for long-term integration success.
- Assesses how security is managed at a strategic level.
Memory trick: Don't just check the locks, check the security mindset.
Principles-Based Policy Framework
Flip cardAn information security policy framework that focuses on high-level principles and objectives rather than detailed, prescriptive rules, allowing for greater flexibility and adaptability in implementation.
- Promotes agility and innovation.
- Requires strong security culture for effective interpretation.
- Adapts well to evolving threats and business needs.
Memory trick: Principles give freedom, rules tie you down.
Measuring InfoSec ROI
Flip cardThe process of quantifying the financial benefits derived from information security investments, demonstrating their value to the organization's profitability and risk reduction.
- Requires translating security outcomes into monetary terms.
- Often involves calculating avoided losses or improved operational efficiency.
- Crucial for justifying security budgets and strategic investments.
Memory trick: Show the board how many coins security keeps in the company's vault.
Strategic Alignment of InfoSec Governance
Flip cardEnsuring that information security objectives, strategies, and practices support and are integrated with the organization's overall business strategy and risk management framework.
- Security initiatives must support business goals.
- Requires understanding organizational risk appetite.
- Foundation for effective security governance.
Memory trick: Link security to the business's core.
Strategic Security Metrics
Flip cardMeasurements that demonstrate how information security initiatives support and contribute to the achievement of an organization's overall strategic objectives.
- Focus on business outcomes, not just technical details.
- Translate security performance into terms relevant to senior leadership.
- Help justify security investments and demonstrate ROI.
Memory trick: Show the board how security helps the business bank, not just block hacks.
Security in Digital Transformation
Flip cardEmbedding information security practices and considerations directly into modern software development and operational processes, such as Agile and DevOps, to achieve continuous security assurance and responsiveness.
- Enables 'security by design'.
- Supports rapid development cycles.
- Crucial for agile and cloud-native environments.
Memory trick: Agile dev means agile sec.
Cultural Adaptation in Security Awareness
Flip cardTailoring information security awareness programs to fit the specific cultural norms, values, and communication styles of different regions or employee groups.
- Culture impacts perception of risk and privacy.
- Effective programs require local relevance.
- Engaging local experts is key for adaptation.
Memory trick: Speak their language, literally and culturally.
Regulatory-Driven Security Investment Justification
Flip cardPresenting a business case for information security investments by emphasizing the financial and reputational impacts of regulatory non-compliance, particularly to executive leadership in highly regulated industries.
- Connects security to financial and brand risk.
- Motivates executive action.
- Highlights legal and regulatory penalties.
Memory trick: To get executive buy-in, show them the fines and the fame.
InfoSec Enterprise Governance Integration
Flip cardThe formal embedding of information security objectives, strategies, and oversight mechanisms within the organization's overarching enterprise governance framework and processes.
- Ensures security is a business enabler, not just a technical function.
- Involves regular reporting to top leadership (e.g., board).
- Links security risk management to enterprise risk management.
Memory trick: Security isn't a separate room; it's a pillar of the whole building.
Agility in InfoSec Governance
Flip cardThe principle that an information security governance framework and program should be flexible and responsive, capable of rapidly adapting to changes in the threat landscape, technology, business objectives, and regulatory requirements.
- Enables continuous relevance and effectiveness of security.
- Crucial in dynamic environments with evolving cyber threats.
- Supports proactive risk management and compliance.
Memory trick: For evolving threats, your security must be swift and agile.
Due Care & Due Diligence
Flip cardDue care refers to exercising the care that a reasonable and prudent person would exercise under the circumstances. Due diligence is the act of investigating and understanding the risks and requirements before taking action.
- Crucial for legal and ethical compliance.
- Due diligence precedes due care (investigate then act).
- Demonstrates responsible and systematic risk management.
Memory trick: When non-compliance hits, first analyze the gaps, then act with care.
Measuring InfoSec ROI (Business Value)
Flip cardQuantifying the financial benefits and strategic advantages gained from information security investments, often presented in terms of cost savings, revenue protection, or competitive differentiation.
- Translate technical metrics to business impact.
- Focus on financial terms for board communication.
- Examples: cost avoidance, revenue protection, compliance savings.
Memory trick: Show them the money saved or gained.