CISM
Certified Information Security Manager, an ISACA certification.
Getting Started: CISM Exam Overview
Free knowledge base
Everything from the course in one searchable place: 217 entries. Use it to review before a practice test or look up a word you forgot.
217 results
Certified Information Security Manager, an ISACA certification.
Getting Started: CISM Exam Overview
Information Systems Audit and Control Association, a global professional body.
Getting Started: CISM Exam Overview
Establishing and maintaining a framework for info sec management.
Getting Started: CISM Exam Overview
Identifying, assessing, and mitigating information security risks.
Getting Started: CISM Exam Overview
Designing, implementing, and managing an info sec program.
Getting Started: CISM Exam Overview
Detecting, responding to, and recovering from security incidents.
Getting Started: CISM Exam Overview
Continuing Professional Education credits required to maintain certification.
Getting Started: CISM Exam Overview
To remember the four CISM domains, think 'G-R-P-I': Governance, Risk, Program, Incident. 'Good Robots Protect Information!'
Getting Started: CISM Exam Overview
The exam frequently tests your understanding of the CISM domains. Memorize the four domains and their core focus. Keywords like 'strategic alignment,' 'business objectives,' 'risk appetite,' and 'governance framework' are strong indicators of questions related to Information Security Governance.
Getting Started: CISM Exam Overview
Confusing CISM with technical certifications; CISM is management-focused.
Getting Started: CISM Exam Overview
Underestimating the experience requirements; managerial experience is key.
Getting Started: CISM Exam Overview
Not understanding the interconnectedness of the four CISM domains.
Getting Started: CISM Exam Overview
Adjusted raw score for fairness across exam versions.
Getting Started: CISM Exam Overview
Number of questions answered correctly on the exam.
Getting Started: CISM Exam Overview
Four key areas of knowledge tested by the CISM exam.
Getting Started: CISM Exam Overview
Question format with one correct answer among options.
Getting Started: CISM Exam Overview
Strategic, governance-focused perspective expected on exam.
Getting Started: CISM Exam Overview
Experimental questions not affecting your exam score.
Getting Started: CISM Exam Overview
To remember the passing score: 'Four-Fifty is the CISM key, to unlock your certification, you see!'
Getting Started: CISM Exam Overview
Memorize that the passing score for the CISM exam is 450 on a scale of 200-800. Questions often test your ability to identify the 'most appropriate' or 'first' action from a management perspective, not a technical one.
Getting Started: CISM Exam Overview
Spending too much time on a single difficult question, leading to not finishing the exam.
Getting Started: CISM Exam Overview
Interpreting questions based on your specific workplace practices rather than ISACA's best practices.
Getting Started: CISM Exam Overview
Failing to read all answer choices before selecting one, potentially missing a 'better' answer.
Getting Started: CISM Exam Overview
System for directing and controlling an organization.
Foundations of Information Security Governance
The amount of risk an organization is willing to accept.
Foundations of Information Security Governance
Body responsible for ultimate oversight and strategic direction.
Foundations of Information Security Governance
Ensuring InfoSec initiatives support overall business objectives.
Foundations of Information Security Governance
Responsibility for actions and outcomes, often assigned by governance.
Foundations of Information Security Governance
Think 'BIG PICTURE' for Enterprise Governance: Board sets the direction, InfoSec follows the Plan, Controls are implemented, ultimately leading to Results.
Foundations of Information Security Governance
The CISM exam frequently tests the understanding that Information Security Governance is a *subset* of Enterprise Governance. Keywords to spot include 'strategic alignment,' 'risk appetite,' and 'board oversight.' Remember that the board holds ultimate responsibility.
Foundations of Information Security Governance
Viewing information security as purely a technical problem, separate from business strategy.
Foundations of Information Security Governance
Failing to communicate security risks and initiatives in business terms to senior leadership.
Foundations of Information Security Governance
Not understanding that the Board of Directors has ultimate responsibility for InfoSec oversight, even if they delegate operational tasks.
Foundations of Information Security Governance
Structured approach for managing and overseeing organizational activities.
Foundations of Information Security Governance
Framework for IT governance and management, including information security.
Foundations of Information Security Governance
International standard for Information Security Management Systems (ISMS).
Foundations of Information Security Governance
Voluntary framework for managing cybersecurity risk, widely adopted.
Foundations of Information Security Governance
To remember the key components, think 'ARRPV': Alignment, Risk, Resources, Performance, Value.
Foundations of Information Security Governance
The CISM exam frequently tests your ability to distinguish between the purpose and scope of different frameworks. Memorize that COBIT is broader IT governance, ISO 27001 is for ISMS certification, and NIST CSF is a risk-based cybersecurity framework.
Foundations of Information Security Governance
Confusing a governance framework with a set of technical controls; frameworks provide the 'what' and 'why', not always the 'how'.
Foundations of Information Security Governance
Believing one framework is universally superior; the best framework depends on the organization's specific context.
Foundations of Information Security Governance
Implementing a framework as a one-time project rather than an ongoing, iterative process.
Foundations of Information Security Governance
Shared values, beliefs, and practices within an organization.
Foundations of Information Security Governance
How an organization's culture impacts security attitudes and behaviors.
Foundations of Information Security Governance
Integrating security into system/product development from the outset.
Foundations of Information Security Governance
Embedding security practices throughout the software development lifecycle.
Foundations of Information Security Governance
Educating employees on security risks and best practices.
Foundations of Information Security Governance
An employee who promotes security within their team/department.
Foundations of Information Security Governance
Employees acting as a defense layer against cyber threats.
Foundations of Information Security Governance
CULTURE: C-ommunication, U-nderstanding, L-eadership, T-raining, U-sability, R-eporting, E-mbedding.
Foundations of Information Security Governance
The CISM exam emphasizes that cultural change is a long-term process requiring continuous effort and leadership buy-in. Look for questions about sustainable strategies, not just one-off initiatives.
Foundations of Information Security Governance
Assuming technical controls alone are sufficient without addressing human factors.
Foundations of Information Security Governance
Implementing 'one-size-fits-all' security awareness training that isn't relevant to all roles.
Foundations of Information Security Governance
Failing to get executive leadership support for security initiatives, leading to apathy.
Foundations of Information Security Governance
General Data Protection Regulation; EU law on data protection and privacy.
Foundations of Information Security Governance
Health Insurance Portability and Accountability Act; US law for health data privacy.
Foundations of Information Security Governance
Payment Card Industry Data Security Standard; global standard for card data security.
Foundations of Information Security Governance
Contract specifying terms for processing personal data by a third party.
Foundations of Information Security Governance
Contract defining the level of service expected from a vendor.
Foundations of Information Security Governance
Legal contract outlining confidential material shared between parties.
Foundations of Information Security Governance
Structured approach to meet legal, regulatory, and contractual obligations.
Foundations of Information Security Governance
Failure to adhere to laws, regulations, or contractual terms.
Foundations of Information Security Governance
L.R.C. – 'Laws, Regulations, Contracts' – are the three pillars of compliance you must always consider.
Foundations of Information Security Governance
The CISM exam frequently tests your knowledge of major global and industry-specific regulations. Be prepared to identify the purpose and key requirements of GDPR, HIPAA, and PCI DSS. Keywords to spot include 'data privacy,' 'healthcare information,' and 'payment card data.'
Foundations of Information Security Governance
Treating compliance as a one-time project instead of an ongoing process.
Foundations of Information Security Governance
Assuming legal counsel handles all compliance, without integrating it into InfoSec operations.
Foundations of Information Security Governance
Failing to review and update contractual agreements as laws and regulations change.
Foundations of Information Security Governance
Acceptable deviation from the risk appetite for specific objectives.
Strategic Information Security Risk Management
Maximum risk an organization can bear without critical failure.
Strategic Information Security Risk Management
Actions taken to modify risks (e.g., mitigate, accept).
Strategic Information Security Risk Management
Process of identifying, analyzing, and evaluating risks.
Strategic Information Security Risk Management
Structure and processes for managing risk consistently.
Strategic Information Security Risk Management
ART: Appetite is what you're willing to pursue (strategic); Tolerance is how much you can deviate (operational); Capacity is your absolute limit (survival).
Strategic Information Security Risk Management
The CISM exam frequently tests the distinction between risk appetite, tolerance, and capacity. Memorize that appetite is strategic and high-level, tolerance is operational and specific, and capacity is the absolute limit.
Strategic Information Security Risk Management
Confusing risk appetite with risk tolerance; they are related but distinct levels of risk acceptance.
Strategic Information Security Risk Management
Viewing risk management as a one-time project rather than a continuous, iterative process.
Strategic Information Security Risk Management
Failing to align information security risk management with overall business objectives and enterprise risk management.
Strategic Information Security Risk Management
Potential cause of an unwanted incident resulting in harm.
Strategic Information Security Risk Management
Weakness exploitable by a threat source.
Strategic Information Security Risk Management
Magnitude of harm from a security incident.
Strategic Information Security Risk Management
Identifying and evaluating potential threat sources and methods.
Strategic Information Security Risk Management
Identifying, quantifying, and prioritizing security weaknesses.
Strategic Information Security Risk Management
Determines criticality of business processes and systems.
Strategic Information Security Risk Management
Simulating attacks to find exploitable vulnerabilities.
Strategic Information Security Risk Management
To remember the order: 'TV I' - Threats lead to Vulnerabilities being exploited, causing Impact. It's like a TV show where the villain (threat) finds a weak spot (vulnerability) and causes a big explosion (impact)!
Strategic Information Security Risk Management
The CISM exam frequently tests your ability to distinguish between threats, vulnerabilities, and risks. Remember: a threat exploits a vulnerability, leading to an impact, which collectively defines risk. Keywords to spot: 'potential for harm' (threat), 'weakness' (vulnerability), 'consequence' (impact).
Strategic Information Security Risk Management
Confusing a threat with a vulnerability (e.g., 'malware' is a threat, 'unpatched software' is a vulnerability).
Strategic Information Security Risk Management
Failing to consider insider threats as seriously as external threats.
Strategic Information Security Risk Management
Not linking impact assessment directly to business objectives and financial consequences.
Strategic Information Security Risk Management
Comprehensive, structured approach to protecting information assets.
Strategic Information Security Risk Management
Framework defining roles, responsibilities, and decision-making for security.
Strategic Information Security Risk Management
High-level statement dictating organizational security requirements.
Strategic Information Security Risk Management
Mandatory specification for implementing a policy.
Strategic Information Security Risk Management
Detailed step-by-step instructions for performing a task.
Strategic Information Security Risk Management
Chief Information Security Officer, leads the InfoSec program.
Strategic Information Security Risk Management
Continuous phases of development, operation, and improvement.
Strategic Information Security Risk Management
P.L.A.N. for Security: Policies, Lifecycle, Awareness, and Necessary Roles. Remember these four pillars for a strong InfoSec program!
Strategic Information Security Risk Management
The exam often tests your understanding of the InfoSec program lifecycle and the interdependencies of its components. Look for questions asking about the 'next step' or 'best action' at a specific stage of the program, or how different program elements (e.g., policies, awareness) contribute to overall effectiveness. Memorize the general flow of the lifecycle.
Strategic Information Security Risk Management
Treating the InfoSec program as a one-time project rather than a continuous lifecycle.
Strategic Information Security Risk Management
Developing policies and procedures without aligning them to business objectives or risk assessments.
Strategic Information Security Risk Management
Failing to secure executive management support and adequate resources for the program.
Strategic Information Security Risk Management
A control designed to stop an incident from occurring.
Strategic Information Security Risk Management
A control designed to identify an incident after it has occurred.
Strategic Information Security Risk Management
A control designed to minimize impact and restore systems.
Strategic Information Security Risk Management
A control designed to discourage potential attackers.
Strategic Information Security Risk Management
The measure of how well a control achieves its intended purpose.
Strategic Information Security Risk Management
A weakness where a necessary control is missing or inadequate.
Strategic Information Security Risk Management
Ongoing oversight to ensure controls operate as intended.
Strategic Information Security Risk Management
A structured approach to fix identified control deficiencies.
Strategic Information Security Risk Management
To remember the control types, think 'P.D.C.D.': Preventative, Detective, Corrective, Deterrent. They help you 'Protect Data, Catch Dangers!'
Strategic Information Security Risk Management
The CISM exam frequently tests your understanding of the different types of controls (preventative, detective, corrective, deterrent) and their application in various scenarios. Be prepared to identify which type of control is most appropriate for a given risk or situation.
Strategic Information Security Risk Management
Failing to regularly test controls, assuming they remain effective.
Strategic Information Security Risk Management
Implementing controls without a clear understanding of the risks they are meant to mitigate.
Strategic Information Security Risk Management
Not involving business stakeholders in control selection and design, leading to operational friction.
Strategic Information Security Risk Management
Quantifiable measure to assess and track information security risk.
Strategic Information Security Risk Management
Descriptive risk measure (e.g., high/medium/low), less precise.
Strategic Information Security Risk Management
Numerical risk measure (e.g., financial impact, percentages), precise.
Strategic Information Security Risk Management
Continuous observation of risk environment and control effectiveness.
Strategic Information Security Risk Management
Communicating risk information to various stakeholders.
Strategic Information Security Risk Management
Expected monetary loss from a risk event over a year.
Strategic Information Security Risk Management
Average time to identify a security incident.
Strategic Information Security Risk Management
RMAT: Risk metrics should be Relevant, Measurable, Actionable, and Timely. Remember a 'mat' for your 'RMAT' metrics to land on!
Strategic Information Security Risk Management
The CISM exam frequently asks about tailoring risk reports to specific audiences. Remember that executives need high-level, business-focused information, often financial, while technical teams need granular, actionable data. Look for keywords like 'board of directors,' 'senior management,' or 'technical team' to guide your answer.
Strategic Information Security Risk Management
Using overly technical jargon in reports for non-technical audiences, leading to misunderstanding or disengagement.
Strategic Information Security Risk Management
Collecting too many metrics without a clear purpose, resulting in 'data overload' and lack of actionable insights.
Strategic Information Security Risk Management
Failing to establish baselines or trends, making it impossible to assess if risk posture is improving or worsening.
Strategic Information Security Risk Management
The design of security controls and services to protect information assets.
Building and Managing the Information Security Program
Ongoing effort to enhance processes, products, and services over time.
Building and Managing the Information Security Program
A metric used to provide an early signal of increasing risk exposure.
Building and Managing the Information Security Program
High-level management support and advocacy crucial for program success.
Building and Managing the Information Security Program
P.D.I.M.O. - **P**lan, **D**esign, **I**mplement, **M**onitor, **O**ptimize. Remember, it's like building a house: you plan it, design it, build it, inspect it, and then continuously improve it!
Building and Managing the Information Security Program
The CISM exam frequently tests your understanding of the *order* of these phases and the *primary activities* within each. Look for keywords like 'strategic alignment' (Initiate), 'policy development' (Design), 'control deployment' (Implement), 'performance metrics' (Monitor), and 'lessons learned' (Optimize).
Building and Managing the Information Security Program
Treating security program development as a one-time project instead of an ongoing, iterative process.
Building and Managing the Information Security Program
Skipping or rushing the 'Initiate & Plan' phase, leading to a security program misaligned with business objectives.
Building and Managing the Information Security Program
Failing to continuously monitor and evaluate the program's effectiveness, resulting in outdated or ineffective controls.
Building and Managing the Information Security Program
Identifying, evaluating, treating, and reporting security vulnerabilities.
Building and Managing the Information Security Program
Organized approach to addressing and managing security incidents.
Building and Managing the Information Security Program
Process of restoring operations after a disruptive event.
Building and Managing the Information Security Program
Quantifiable measure of performance over time for specific objectives.
Building and Managing the Information Security Program
To remember the continuous cycle: 'P-I-M-R-I' - Plan, Implement, Monitor, Respond, Improve. Keep the 'I's flowing!
Building and Managing the Information Security Program
The exam often tests your understanding of the continuous nature of information security. Look for keywords like 'ongoing,' 'periodic review,' 'lessons learned,' and 'adaptive' when considering answers related to program maintenance. Remember that security is a cycle, not a one-time project.
Building and Managing the Information Security Program
Treating information security as a project with a defined end, rather than an ongoing process.
Building and Managing the Information Security Program
Neglecting to update policies and procedures in response to changes in technology or regulations.
Building and Managing the Information Security Program
Failing to regularly test incident response and disaster recovery plans.
Building and Managing the Information Security Program
Ignoring feedback from security incidents or audits, missing opportunities for improvement.
Building and Managing the Information Security Program
Detailed specifications for implementing security controls.
Building and Managing the Information Security Program
Granting minimum necessary access to users or processes.
Building and Managing the Information Security Program
Layering multiple security controls for comprehensive protection.
Building and Managing the Information Security Program
Systematic process of identifying and mitigating potential threats.
Building and Managing the Information Security Program
Integrating security early in the development lifecycle.
Building and Managing the Information Security Program
System defaults to a secure state upon failure.
Building and Managing the Information Security Program
A CISM designs a secure 'ARC' (Architecture, Requirements, Controls). Architecture is the big picture, Requirements define what's needed, and Controls are the specific tools.
Building and Managing the Information Security Program
The CISM exam emphasizes that security architecture is strategic and enterprise-wide, while security design is tactical and system-specific. Look for keywords like 'overall strategy' for architecture and 'specific controls' for design.
Building and Managing the Information Security Program
Confusing security architecture with security design; remember, architecture is the 'what and why,' design is the 'how.'
Building and Managing the Information Security Program
Treating security as an afterthought rather than integrating it early in the development lifecycle.
Building and Managing the Information Security Program
Failing to apply fundamental security principles like least privilege and defense in depth in design.
Building and Managing the Information Security Program
Informing all personnel about general security principles and policies.
Building and Managing the Information Security Program
Teaching specific groups skills for secure job performance.
Building and Managing the Information Security Program
Testing employee susceptibility to phishing attacks.
Building and Managing the Information Security Program
Strategy for disseminating security information to stakeholders.
Building and Managing the Information Security Program
Apathy or disengagement due to excessive security messages.
Building and Managing the Information Security Program
To remember the difference: AWARENESS is for ALL, TRAINING is for TASKS.
Building and Managing the Information Security Program
The CISM exam often distinguishes between 'awareness' (general knowledge, culture) and 'training' (specific skills, role-based tasks). Look for keywords like 'all employees' for awareness and 'specific job function' for training.
Building and Managing the Information Security Program
Treating awareness and training as the same thing.
Building and Managing the Information Security Program
Using a 'one-size-fits-all' approach for all employees.
Building and Managing the Information Security Program
Failing to measure program effectiveness and report results.
Building and Managing the Information Security Program
Quantifiable measure of success towards objectives.
Building and Managing the Information Security Program
Specific data point used to calculate KPIs.
Building and Managing the Information Security Program
Structured approach for collecting, analyzing, reporting metrics.
Building and Managing the Information Security Program
Overall level of risk an organization faces.
Building and Managing the Information Security Program
Financial benefit compared to cost of investment.
Building and Managing the Information Security Program
Starting point for comparison of future performance.
Building and Managing the Information Security Program
To remember the key steps: 'MEASURE': M-Metrics, E-Establish, A-Analyze, S-Stakeholders, U-Understand, R-Report, E-Enhance.
Building and Managing the Information Security Program
The CISM exam frequently tests your ability to differentiate between operational, tactical, and strategic metrics, and how to present information appropriately to different stakeholders (e.g., board vs. technical team). Focus on the 'why' behind the numbers for management.
Building and Managing the Information Security Program
Using too many technical metrics that don't translate to business risk for executive reporting.
Building and Managing the Information Security Program
Failing to establish a baseline before implementing new controls, making it hard to show improvement.
Building and Managing the Information Security Program
Collecting data but not acting on the insights to drive program improvements.
Building and Managing the Information Security Program
Documented procedures for reacting to security incidents.
Incident Management and Business Resilience
An event that violates security policy or standard practice.
Incident Management and Business Resilience
Underlying cause of one or more incidents.
Incident Management and Business Resilience
Limiting the scope and impact of an incident.
Incident Management and Business Resilience
Removing the root cause of an incident.
Incident Management and Business Resilience
Restoring affected systems to normal operations.
Incident Management and Business Resilience
P.I.C.E.R.P. helps remember the lifecycle: Prepare, Identify, Contain, Eradicate, Recover, Post-Incident.
Incident Management and Business Resilience
The CISM exam frequently tests your understanding of the incident management lifecycle phases. Memorize the order and key activities of each phase: Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity. Look for questions asking about the 'next step' or 'first step' in a given scenario.
Incident Management and Business Resilience
Confusing an incident with a problem: An incident is the event; a problem is its root cause.
Incident Management and Business Resilience
Skipping the 'Post-Incident Activity' phase, which is crucial for learning and improvement.
Incident Management and Business Resilience
Failing to adequately 'Prepare' by not having a tested plan or trained team.
Incident Management and Business Resilience
Detailed, step-by-step instructions for handling security incidents.
Incident Management and Business Resilience
Analysis of an incident to identify lessons learned and improve processes.
Incident Management and Business Resilience
A discussion-based simulation of an incident to test plans.
Incident Management and Business Resilience
Defined route for reporting incidents to higher authority or specialized teams.
Incident Management and Business Resilience
P-D-C-E-R-L: **P**repare, **D**etect, **C**ontain, **E**radicate, **R**ecover, **L**essons Learned. Remember the incident lifecycle!
Incident Management and Business Resilience
The CISM exam often tests your understanding of the *practical application* of incident response. Look for scenarios where you need to choose the most appropriate action based on the incident type and organizational context, emphasizing communication and documentation.
Incident Management and Business Resilience
Failing to regularly test and update incident response procedures, making them obsolete.
Incident Management and Business Resilience
Lack of clear communication channels and defined roles during an incident, leading to chaos.
Incident Management and Business Resilience
Focusing only on technical recovery without addressing legal, PR, or business impact.
Incident Management and Business Resilience
Maximum tolerable downtime for a system/service.
Incident Management and Business Resilience
Maximum acceptable data loss measured in time.
Incident Management and Business Resilience
Process of identifying the fundamental cause of an incident.
Incident Management and Business Resilience
Average time to restore services after an incident.
Incident Management and Business Resilience
Insights gained from an incident to improve processes.
Incident Management and Business Resilience
RPO and RTO: 'RPO is Point, RTO is Time.' Point for how much data you can lose, Time for how long you can be down.
Incident Management and Business Resilience
The CISM exam frequently tests your understanding of the entire incident lifecycle. For this lesson, remember that recovery is not the end; post-incident activities like 'lessons learned' and 'continuous improvement' are vital. Look for keywords like 'post-mortem,' 'root cause analysis,' and 'metrics' when discussing post-incident phases.
Incident Management and Business Resilience
Skipping the post-incident review due to time constraints or 'moving on'. This loses valuable learning opportunities.
Incident Management and Business Resilience
Focusing on blame during post-incident reviews instead of process improvement. This creates a culture of fear.
Incident Management and Business Resilience
Failing to implement and track action items from lessons learned, making the review process ineffective.
Incident Management and Business Resilience
Holistic plan for maintaining critical business functions during and after disruption.
Incident Management and Business Resilience
Subset of BCP focusing on IT system and data recovery after a disaster.
Incident Management and Business Resilience
Fully equipped alternative facility ready for immediate use.
Incident Management and Business Resilience
Partially equipped alternative facility requiring setup time.
Incident Management and Business Resilience
Basic facility with infrastructure, requiring significant setup time.
Incident Management and Business Resilience
BCP is 'Big Picture Continuity,' DRP is 'Data Recovery Plan.' Think of BCP as the whole house, DRP as just the server room.
Incident Management and Business Resilience
The CISM exam frequently tests the distinction between BCP and DRP. Remember that BCP is the overarching strategy for business resilience, while DRP is specifically for IT recovery. Keywords like 'overall business operations' point to BCP, while 'IT systems, data, applications' point to DRP.
Incident Management and Business Resilience
Confusing BCP and DRP as interchangeable terms or thinking DRP encompasses BCP.
Incident Management and Business Resilience
Failing to regularly test and update BCP/DRP, rendering them obsolete.
Incident Management and Business Resilience
Not involving key stakeholders (business units, senior management) in BCP/DRP development and testing.
Incident Management and Business Resilience