Free knowledge base

Certified Information Security Manager (CISM) — key terms, tricks & tips

Everything from the course in one searchable place: 217 entries. Use it to review before a practice test or look up a word you forgot.

217 results

Key term

CISM

Certified Information Security Manager, an ISACA certification.

Getting Started: CISM Exam Overview

Key term

ISACA

Information Systems Audit and Control Association, a global professional body.

Getting Started: CISM Exam Overview

Key term

Information Security Governance

Establishing and maintaining a framework for info sec management.

Getting Started: CISM Exam Overview

Key term

Risk Management

Identifying, assessing, and mitigating information security risks.

Getting Started: CISM Exam Overview

Key term

Program Development

Designing, implementing, and managing an info sec program.

Getting Started: CISM Exam Overview

Key term

Incident Management

Detecting, responding to, and recovering from security incidents.

Getting Started: CISM Exam Overview

Key term

CPEs

Continuing Professional Education credits required to maintain certification.

Getting Started: CISM Exam Overview

Memory trick

Understanding the CISM Certification and its Value

To remember the four CISM domains, think 'G-R-P-I': Governance, Risk, Program, Incident. 'Good Robots Protect Information!'

Getting Started: CISM Exam Overview

Exam tip

Understanding the CISM Certification and its Value

The exam frequently tests your understanding of the CISM domains. Memorize the four domains and their core focus. Keywords like 'strategic alignment,' 'business objectives,' 'risk appetite,' and 'governance framework' are strong indicators of questions related to Information Security Governance.

Getting Started: CISM Exam Overview

Common mistake

Understanding the CISM Certification and its Value

Confusing CISM with technical certifications; CISM is management-focused.

Getting Started: CISM Exam Overview

Common mistake

Understanding the CISM Certification and its Value

Underestimating the experience requirements; managerial experience is key.

Getting Started: CISM Exam Overview

Common mistake

Understanding the CISM Certification and its Value

Not understanding the interconnectedness of the four CISM domains.

Getting Started: CISM Exam Overview

Key term

Scaled Score

Adjusted raw score for fairness across exam versions.

Getting Started: CISM Exam Overview

Key term

Raw Score

Number of questions answered correctly on the exam.

Getting Started: CISM Exam Overview

Key term

CISM Domains

Four key areas of knowledge tested by the CISM exam.

Getting Started: CISM Exam Overview

Key term

Multiple Choice

Question format with one correct answer among options.

Getting Started: CISM Exam Overview

Key term

ISACA Way

Strategic, governance-focused perspective expected on exam.

Getting Started: CISM Exam Overview

Key term

Unscored Questions

Experimental questions not affecting your exam score.

Getting Started: CISM Exam Overview

Memory trick

Navigating the CISM Exam: Format, Scoring, and Tips

To remember the passing score: 'Four-Fifty is the CISM key, to unlock your certification, you see!'

Getting Started: CISM Exam Overview

Exam tip

Navigating the CISM Exam: Format, Scoring, and Tips

Memorize that the passing score for the CISM exam is 450 on a scale of 200-800. Questions often test your ability to identify the 'most appropriate' or 'first' action from a management perspective, not a technical one.

Getting Started: CISM Exam Overview

Common mistake

Navigating the CISM Exam: Format, Scoring, and Tips

Spending too much time on a single difficult question, leading to not finishing the exam.

Getting Started: CISM Exam Overview

Common mistake

Navigating the CISM Exam: Format, Scoring, and Tips

Interpreting questions based on your specific workplace practices rather than ISACA's best practices.

Getting Started: CISM Exam Overview

Common mistake

Navigating the CISM Exam: Format, Scoring, and Tips

Failing to read all answer choices before selecting one, potentially missing a 'better' answer.

Getting Started: CISM Exam Overview

Key term

Enterprise Governance

System for directing and controlling an organization.

Foundations of Information Security Governance

Key term

Risk Appetite

The amount of risk an organization is willing to accept.

Foundations of Information Security Governance

Key term

Board of Directors

Body responsible for ultimate oversight and strategic direction.

Foundations of Information Security Governance

Key term

Strategic Alignment

Ensuring InfoSec initiatives support overall business objectives.

Foundations of Information Security Governance

Key term

Accountability

Responsibility for actions and outcomes, often assigned by governance.

Foundations of Information Security Governance

Memory trick

Enterprise Governance and its Link to InfoSec

Think 'BIG PICTURE' for Enterprise Governance: Board sets the direction, InfoSec follows the Plan, Controls are implemented, ultimately leading to Results.

Foundations of Information Security Governance

Exam tip

Enterprise Governance and its Link to InfoSec

The CISM exam frequently tests the understanding that Information Security Governance is a *subset* of Enterprise Governance. Keywords to spot include 'strategic alignment,' 'risk appetite,' and 'board oversight.' Remember that the board holds ultimate responsibility.

Foundations of Information Security Governance

Common mistake

Enterprise Governance and its Link to InfoSec

Viewing information security as purely a technical problem, separate from business strategy.

Foundations of Information Security Governance

Common mistake

Enterprise Governance and its Link to InfoSec

Failing to communicate security risks and initiatives in business terms to senior leadership.

Foundations of Information Security Governance

Common mistake

Enterprise Governance and its Link to InfoSec

Not understanding that the Board of Directors has ultimate responsibility for InfoSec oversight, even if they delegate operational tasks.

Foundations of Information Security Governance

Key term

Governance Framework

Structured approach for managing and overseeing organizational activities.

Foundations of Information Security Governance

Key term

COBIT

Framework for IT governance and management, including information security.

Foundations of Information Security Governance

Key term

ISO/IEC 27001

International standard for Information Security Management Systems (ISMS).

Foundations of Information Security Governance

Key term

NIST CSF

Voluntary framework for managing cybersecurity risk, widely adopted.

Foundations of Information Security Governance

Memory trick

Establishing InfoSec Governance Frameworks

To remember the key components, think 'ARRPV': Alignment, Risk, Resources, Performance, Value.

Foundations of Information Security Governance

Exam tip

Establishing InfoSec Governance Frameworks

The CISM exam frequently tests your ability to distinguish between the purpose and scope of different frameworks. Memorize that COBIT is broader IT governance, ISO 27001 is for ISMS certification, and NIST CSF is a risk-based cybersecurity framework.

Foundations of Information Security Governance

Common mistake

Establishing InfoSec Governance Frameworks

Confusing a governance framework with a set of technical controls; frameworks provide the 'what' and 'why', not always the 'how'.

Foundations of Information Security Governance

Common mistake

Establishing InfoSec Governance Frameworks

Believing one framework is universally superior; the best framework depends on the organization's specific context.

Foundations of Information Security Governance

Common mistake

Establishing InfoSec Governance Frameworks

Implementing a framework as a one-time project rather than an ongoing, iterative process.

Foundations of Information Security Governance

Key term

Organizational Culture

Shared values, beliefs, and practices within an organization.

Foundations of Information Security Governance

Key term

Security Culture

How an organization's culture impacts security attitudes and behaviors.

Foundations of Information Security Governance

Key term

Security by Design

Integrating security into system/product development from the outset.

Foundations of Information Security Governance

Key term

DevSecOps

Embedding security practices throughout the software development lifecycle.

Foundations of Information Security Governance

Key term

Security Awareness Training

Educating employees on security risks and best practices.

Foundations of Information Security Governance

Key term

Security Champion

An employee who promotes security within their team/department.

Foundations of Information Security Governance

Key term

Human Firewall

Employees acting as a defense layer against cyber threats.

Foundations of Information Security Governance

Memory trick

Organizational Culture and InfoSec Integration

CULTURE: C-ommunication, U-nderstanding, L-eadership, T-raining, U-sability, R-eporting, E-mbedding.

Foundations of Information Security Governance

Exam tip

Organizational Culture and InfoSec Integration

The CISM exam emphasizes that cultural change is a long-term process requiring continuous effort and leadership buy-in. Look for questions about sustainable strategies, not just one-off initiatives.

Foundations of Information Security Governance

Common mistake

Organizational Culture and InfoSec Integration

Assuming technical controls alone are sufficient without addressing human factors.

Foundations of Information Security Governance

Common mistake

Organizational Culture and InfoSec Integration

Implementing 'one-size-fits-all' security awareness training that isn't relevant to all roles.

Foundations of Information Security Governance

Common mistake

Organizational Culture and InfoSec Integration

Failing to get executive leadership support for security initiatives, leading to apathy.

Foundations of Information Security Governance

Key term

GDPR

General Data Protection Regulation; EU law on data protection and privacy.

Foundations of Information Security Governance

Key term

HIPAA

Health Insurance Portability and Accountability Act; US law for health data privacy.

Foundations of Information Security Governance

Key term

PCI DSS

Payment Card Industry Data Security Standard; global standard for card data security.

Foundations of Information Security Governance

Key term

Data Processing Agreement (DPA)

Contract specifying terms for processing personal data by a third party.

Foundations of Information Security Governance

Key term

Service Level Agreement (SLA)

Contract defining the level of service expected from a vendor.

Foundations of Information Security Governance

Key term

Non-Disclosure Agreement (NDA)

Legal contract outlining confidential material shared between parties.

Foundations of Information Security Governance

Key term

Compliance Framework

Structured approach to meet legal, regulatory, and contractual obligations.

Foundations of Information Security Governance

Key term

Non-compliance

Failure to adhere to laws, regulations, or contractual terms.

Foundations of Information Security Governance

Memory trick

Legal, Regulatory, and Contractual Compliance

L.R.C. – 'Laws, Regulations, Contracts' – are the three pillars of compliance you must always consider.

Foundations of Information Security Governance

Exam tip

Legal, Regulatory, and Contractual Compliance

The CISM exam frequently tests your knowledge of major global and industry-specific regulations. Be prepared to identify the purpose and key requirements of GDPR, HIPAA, and PCI DSS. Keywords to spot include 'data privacy,' 'healthcare information,' and 'payment card data.'

Foundations of Information Security Governance

Common mistake

Legal, Regulatory, and Contractual Compliance

Treating compliance as a one-time project instead of an ongoing process.

Foundations of Information Security Governance

Common mistake

Legal, Regulatory, and Contractual Compliance

Assuming legal counsel handles all compliance, without integrating it into InfoSec operations.

Foundations of Information Security Governance

Common mistake

Legal, Regulatory, and Contractual Compliance

Failing to review and update contractual agreements as laws and regulations change.

Foundations of Information Security Governance

Key term

Risk Tolerance

Acceptable deviation from the risk appetite for specific objectives.

Strategic Information Security Risk Management

Key term

Risk Capacity

Maximum risk an organization can bear without critical failure.

Strategic Information Security Risk Management

Key term

Risk Treatment

Actions taken to modify risks (e.g., mitigate, accept).

Strategic Information Security Risk Management

Key term

Risk Assessment

Process of identifying, analyzing, and evaluating risks.

Strategic Information Security Risk Management

Key term

Framework

Structure and processes for managing risk consistently.

Strategic Information Security Risk Management

Memory trick

Information Security Risk Management Principles

ART: Appetite is what you're willing to pursue (strategic); Tolerance is how much you can deviate (operational); Capacity is your absolute limit (survival).

Strategic Information Security Risk Management

Exam tip

Information Security Risk Management Principles

The CISM exam frequently tests the distinction between risk appetite, tolerance, and capacity. Memorize that appetite is strategic and high-level, tolerance is operational and specific, and capacity is the absolute limit.

Strategic Information Security Risk Management

Common mistake

Information Security Risk Management Principles

Confusing risk appetite with risk tolerance; they are related but distinct levels of risk acceptance.

Strategic Information Security Risk Management

Common mistake

Information Security Risk Management Principles

Viewing risk management as a one-time project rather than a continuous, iterative process.

Strategic Information Security Risk Management

Common mistake

Information Security Risk Management Principles

Failing to align information security risk management with overall business objectives and enterprise risk management.

Strategic Information Security Risk Management

Key term

Threat

Potential cause of an unwanted incident resulting in harm.

Strategic Information Security Risk Management

Key term

Vulnerability

Weakness exploitable by a threat source.

Strategic Information Security Risk Management

Key term

Impact

Magnitude of harm from a security incident.

Strategic Information Security Risk Management

Key term

Threat Assessment

Identifying and evaluating potential threat sources and methods.

Strategic Information Security Risk Management

Key term

Vulnerability Assessment

Identifying, quantifying, and prioritizing security weaknesses.

Strategic Information Security Risk Management

Key term

Business Impact Analysis (BIA)

Determines criticality of business processes and systems.

Strategic Information Security Risk Management

Key term

Penetration Testing

Simulating attacks to find exploitable vulnerabilities.

Strategic Information Security Risk Management

Memory trick

Threat, Vulnerability, and Impact Assessment

To remember the order: 'TV I' - Threats lead to Vulnerabilities being exploited, causing Impact. It's like a TV show where the villain (threat) finds a weak spot (vulnerability) and causes a big explosion (impact)!

Strategic Information Security Risk Management

Exam tip

Threat, Vulnerability, and Impact Assessment

The CISM exam frequently tests your ability to distinguish between threats, vulnerabilities, and risks. Remember: a threat exploits a vulnerability, leading to an impact, which collectively defines risk. Keywords to spot: 'potential for harm' (threat), 'weakness' (vulnerability), 'consequence' (impact).

Strategic Information Security Risk Management

Common mistake

Threat, Vulnerability, and Impact Assessment

Confusing a threat with a vulnerability (e.g., 'malware' is a threat, 'unpatched software' is a vulnerability).

Strategic Information Security Risk Management

Common mistake

Threat, Vulnerability, and Impact Assessment

Failing to consider insider threats as seriously as external threats.

Strategic Information Security Risk Management

Common mistake

Threat, Vulnerability, and Impact Assessment

Not linking impact assessment directly to business objectives and financial consequences.

Strategic Information Security Risk Management

Key term

InfoSec Program

Comprehensive, structured approach to protecting information assets.

Strategic Information Security Risk Management

Key term

Security Governance

Framework defining roles, responsibilities, and decision-making for security.

Strategic Information Security Risk Management

Key term

Policy

High-level statement dictating organizational security requirements.

Strategic Information Security Risk Management

Key term

Standard

Mandatory specification for implementing a policy.

Strategic Information Security Risk Management

Key term

Procedure

Detailed step-by-step instructions for performing a task.

Strategic Information Security Risk Management

Key term

CISO

Chief Information Security Officer, leads the InfoSec program.

Strategic Information Security Risk Management

Key term

Program Lifecycle

Continuous phases of development, operation, and improvement.

Strategic Information Security Risk Management

Memory trick

Developing and Managing the InfoSec Program

P.L.A.N. for Security: Policies, Lifecycle, Awareness, and Necessary Roles. Remember these four pillars for a strong InfoSec program!

Strategic Information Security Risk Management

Exam tip

Developing and Managing the InfoSec Program

The exam often tests your understanding of the InfoSec program lifecycle and the interdependencies of its components. Look for questions asking about the 'next step' or 'best action' at a specific stage of the program, or how different program elements (e.g., policies, awareness) contribute to overall effectiveness. Memorize the general flow of the lifecycle.

Strategic Information Security Risk Management

Common mistake

Developing and Managing the InfoSec Program

Treating the InfoSec program as a one-time project rather than a continuous lifecycle.

Strategic Information Security Risk Management

Common mistake

Developing and Managing the InfoSec Program

Developing policies and procedures without aligning them to business objectives or risk assessments.

Strategic Information Security Risk Management

Common mistake

Developing and Managing the InfoSec Program

Failing to secure executive management support and adequate resources for the program.

Strategic Information Security Risk Management

Key term

Preventative Control

A control designed to stop an incident from occurring.

Strategic Information Security Risk Management

Key term

Detective Control

A control designed to identify an incident after it has occurred.

Strategic Information Security Risk Management

Key term

Corrective Control

A control designed to minimize impact and restore systems.

Strategic Information Security Risk Management

Key term

Deterrent Control

A control designed to discourage potential attackers.

Strategic Information Security Risk Management

Key term

Control Effectiveness

The measure of how well a control achieves its intended purpose.

Strategic Information Security Risk Management

Key term

Control Gap

A weakness where a necessary control is missing or inadequate.

Strategic Information Security Risk Management

Key term

Continuous Monitoring

Ongoing oversight to ensure controls operate as intended.

Strategic Information Security Risk Management

Key term

Remediation Plan

A structured approach to fix identified control deficiencies.

Strategic Information Security Risk Management

Memory trick

Implementing and Monitoring Information Security Controls

To remember the control types, think 'P.D.C.D.': Preventative, Detective, Corrective, Deterrent. They help you 'Protect Data, Catch Dangers!'

Strategic Information Security Risk Management

Exam tip

Implementing and Monitoring Information Security Controls

The CISM exam frequently tests your understanding of the different types of controls (preventative, detective, corrective, deterrent) and their application in various scenarios. Be prepared to identify which type of control is most appropriate for a given risk or situation.

Strategic Information Security Risk Management

Common mistake

Implementing and Monitoring Information Security Controls

Failing to regularly test controls, assuming they remain effective.

Strategic Information Security Risk Management

Common mistake

Implementing and Monitoring Information Security Controls

Implementing controls without a clear understanding of the risks they are meant to mitigate.

Strategic Information Security Risk Management

Common mistake

Implementing and Monitoring Information Security Controls

Not involving business stakeholders in control selection and design, leading to operational friction.

Strategic Information Security Risk Management

Key term

Risk Metric

Quantifiable measure to assess and track information security risk.

Strategic Information Security Risk Management

Key term

Qualitative Metric

Descriptive risk measure (e.g., high/medium/low), less precise.

Strategic Information Security Risk Management

Key term

Quantitative Metric

Numerical risk measure (e.g., financial impact, percentages), precise.

Strategic Information Security Risk Management

Key term

Risk Monitoring

Continuous observation of risk environment and control effectiveness.

Strategic Information Security Risk Management

Key term

Risk Reporting

Communicating risk information to various stakeholders.

Strategic Information Security Risk Management

Key term

Annualized Loss Expectancy (ALE)

Expected monetary loss from a risk event over a year.

Strategic Information Security Risk Management

Key term

Mean Time To Detect (MTTD)

Average time to identify a security incident.

Strategic Information Security Risk Management

Memory trick

Metrics, Monitoring, and Reporting for Risk

RMAT: Risk metrics should be Relevant, Measurable, Actionable, and Timely. Remember a 'mat' for your 'RMAT' metrics to land on!

Strategic Information Security Risk Management

Exam tip

Metrics, Monitoring, and Reporting for Risk

The CISM exam frequently asks about tailoring risk reports to specific audiences. Remember that executives need high-level, business-focused information, often financial, while technical teams need granular, actionable data. Look for keywords like 'board of directors,' 'senior management,' or 'technical team' to guide your answer.

Strategic Information Security Risk Management

Common mistake

Metrics, Monitoring, and Reporting for Risk

Using overly technical jargon in reports for non-technical audiences, leading to misunderstanding or disengagement.

Strategic Information Security Risk Management

Common mistake

Metrics, Monitoring, and Reporting for Risk

Collecting too many metrics without a clear purpose, resulting in 'data overload' and lack of actionable insights.

Strategic Information Security Risk Management

Common mistake

Metrics, Monitoring, and Reporting for Risk

Failing to establish baselines or trends, making it impossible to assess if risk posture is improving or worsening.

Strategic Information Security Risk Management

Key term

Security Architecture

The design of security controls and services to protect information assets.

Building and Managing the Information Security Program

Key term

Continuous Improvement

Ongoing effort to enhance processes, products, and services over time.

Building and Managing the Information Security Program

Key term

Key Risk Indicator (KRI)

A metric used to provide an early signal of increasing risk exposure.

Building and Managing the Information Security Program

Key term

Executive Sponsorship

High-level management support and advocacy crucial for program success.

Building and Managing the Information Security Program

Memory trick

Information Security Program Development Lifecycle

P.D.I.M.O. - **P**lan, **D**esign, **I**mplement, **M**onitor, **O**ptimize. Remember, it's like building a house: you plan it, design it, build it, inspect it, and then continuously improve it!

Building and Managing the Information Security Program

Exam tip

Information Security Program Development Lifecycle

The CISM exam frequently tests your understanding of the *order* of these phases and the *primary activities* within each. Look for keywords like 'strategic alignment' (Initiate), 'policy development' (Design), 'control deployment' (Implement), 'performance metrics' (Monitor), and 'lessons learned' (Optimize).

Building and Managing the Information Security Program

Common mistake

Information Security Program Development Lifecycle

Treating security program development as a one-time project instead of an ongoing, iterative process.

Building and Managing the Information Security Program

Common mistake

Information Security Program Development Lifecycle

Skipping or rushing the 'Initiate & Plan' phase, leading to a security program misaligned with business objectives.

Building and Managing the Information Security Program

Common mistake

Information Security Program Development Lifecycle

Failing to continuously monitor and evaluate the program's effectiveness, resulting in outdated or ineffective controls.

Building and Managing the Information Security Program

Key term

Vulnerability Management

Identifying, evaluating, treating, and reporting security vulnerabilities.

Building and Managing the Information Security Program

Key term

Incident Response

Organized approach to addressing and managing security incidents.

Building and Managing the Information Security Program

Key term

Disaster Recovery

Process of restoring operations after a disruptive event.

Building and Managing the Information Security Program

Key term

Key Performance Indicator (KPI)

Quantifiable measure of performance over time for specific objectives.

Building and Managing the Information Security Program

Memory trick

Managing and Maintaining the InfoSec Program

To remember the continuous cycle: 'P-I-M-R-I' - Plan, Implement, Monitor, Respond, Improve. Keep the 'I's flowing!

Building and Managing the Information Security Program

Exam tip

Managing and Maintaining the InfoSec Program

The exam often tests your understanding of the continuous nature of information security. Look for keywords like 'ongoing,' 'periodic review,' 'lessons learned,' and 'adaptive' when considering answers related to program maintenance. Remember that security is a cycle, not a one-time project.

Building and Managing the Information Security Program

Common mistake

Managing and Maintaining the InfoSec Program

Treating information security as a project with a defined end, rather than an ongoing process.

Building and Managing the Information Security Program

Common mistake

Managing and Maintaining the InfoSec Program

Neglecting to update policies and procedures in response to changes in technology or regulations.

Building and Managing the Information Security Program

Common mistake

Managing and Maintaining the InfoSec Program

Failing to regularly test incident response and disaster recovery plans.

Building and Managing the Information Security Program

Common mistake

Managing and Maintaining the InfoSec Program

Ignoring feedback from security incidents or audits, missing opportunities for improvement.

Building and Managing the Information Security Program

Key term

Security Design

Detailed specifications for implementing security controls.

Building and Managing the Information Security Program

Key term

Least Privilege

Granting minimum necessary access to users or processes.

Building and Managing the Information Security Program

Key term

Defense in Depth

Layering multiple security controls for comprehensive protection.

Building and Managing the Information Security Program

Key term

Threat Modeling

Systematic process of identifying and mitigating potential threats.

Building and Managing the Information Security Program

Key term

Shift Left

Integrating security early in the development lifecycle.

Building and Managing the Information Security Program

Key term

Fail-Safe Defaults

System defaults to a secure state upon failure.

Building and Managing the Information Security Program

Memory trick

Information Security Architecture and Design

A CISM designs a secure 'ARC' (Architecture, Requirements, Controls). Architecture is the big picture, Requirements define what's needed, and Controls are the specific tools.

Building and Managing the Information Security Program

Exam tip

Information Security Architecture and Design

The CISM exam emphasizes that security architecture is strategic and enterprise-wide, while security design is tactical and system-specific. Look for keywords like 'overall strategy' for architecture and 'specific controls' for design.

Building and Managing the Information Security Program

Common mistake

Information Security Architecture and Design

Confusing security architecture with security design; remember, architecture is the 'what and why,' design is the 'how.'

Building and Managing the Information Security Program

Common mistake

Information Security Architecture and Design

Treating security as an afterthought rather than integrating it early in the development lifecycle.

Building and Managing the Information Security Program

Common mistake

Information Security Architecture and Design

Failing to apply fundamental security principles like least privilege and defense in depth in design.

Building and Managing the Information Security Program

Key term

Security Awareness

Informing all personnel about general security principles and policies.

Building and Managing the Information Security Program

Key term

Security Training

Teaching specific groups skills for secure job performance.

Building and Managing the Information Security Program

Key term

Phishing Simulation

Testing employee susceptibility to phishing attacks.

Building and Managing the Information Security Program

Key term

Communication Plan

Strategy for disseminating security information to stakeholders.

Building and Managing the Information Security Program

Key term

Security Fatigue

Apathy or disengagement due to excessive security messages.

Building and Managing the Information Security Program

Memory trick

Awareness, Training, and Communication Strategies

To remember the difference: AWARENESS is for ALL, TRAINING is for TASKS.

Building and Managing the Information Security Program

Exam tip

Awareness, Training, and Communication Strategies

The CISM exam often distinguishes between 'awareness' (general knowledge, culture) and 'training' (specific skills, role-based tasks). Look for keywords like 'all employees' for awareness and 'specific job function' for training.

Building and Managing the Information Security Program

Common mistake

Awareness, Training, and Communication Strategies

Treating awareness and training as the same thing.

Building and Managing the Information Security Program

Common mistake

Awareness, Training, and Communication Strategies

Using a 'one-size-fits-all' approach for all employees.

Building and Managing the Information Security Program

Common mistake

Awareness, Training, and Communication Strategies

Failing to measure program effectiveness and report results.

Building and Managing the Information Security Program

Key term

KPI (Key Performance Indicator)

Quantifiable measure of success towards objectives.

Building and Managing the Information Security Program

Key term

Metric

Specific data point used to calculate KPIs.

Building and Managing the Information Security Program

Key term

Measurement Framework

Structured approach for collecting, analyzing, reporting metrics.

Building and Managing the Information Security Program

Key term

Risk Posture

Overall level of risk an organization faces.

Building and Managing the Information Security Program

Key term

Return on Investment (ROI)

Financial benefit compared to cost of investment.

Building and Managing the Information Security Program

Key term

Baseline

Starting point for comparison of future performance.

Building and Managing the Information Security Program

Memory trick

Measuring and Reporting Program Effectiveness

To remember the key steps: 'MEASURE': M-Metrics, E-Establish, A-Analyze, S-Stakeholders, U-Understand, R-Report, E-Enhance.

Building and Managing the Information Security Program

Exam tip

Measuring and Reporting Program Effectiveness

The CISM exam frequently tests your ability to differentiate between operational, tactical, and strategic metrics, and how to present information appropriately to different stakeholders (e.g., board vs. technical team). Focus on the 'why' behind the numbers for management.

Building and Managing the Information Security Program

Common mistake

Measuring and Reporting Program Effectiveness

Using too many technical metrics that don't translate to business risk for executive reporting.

Building and Managing the Information Security Program

Common mistake

Measuring and Reporting Program Effectiveness

Failing to establish a baseline before implementing new controls, making it hard to show improvement.

Building and Managing the Information Security Program

Common mistake

Measuring and Reporting Program Effectiveness

Collecting data but not acting on the insights to drive program improvements.

Building and Managing the Information Security Program

Key term

Incident Response Plan

Documented procedures for reacting to security incidents.

Incident Management and Business Resilience

Key term

Incident

An event that violates security policy or standard practice.

Incident Management and Business Resilience

Key term

Problem

Underlying cause of one or more incidents.

Incident Management and Business Resilience

Key term

Containment

Limiting the scope and impact of an incident.

Incident Management and Business Resilience

Key term

Eradication

Removing the root cause of an incident.

Incident Management and Business Resilience

Key term

Recovery

Restoring affected systems to normal operations.

Incident Management and Business Resilience

Memory trick

Incident Management Lifecycle and Planning

P.I.C.E.R.P. helps remember the lifecycle: Prepare, Identify, Contain, Eradicate, Recover, Post-Incident.

Incident Management and Business Resilience

Exam tip

Incident Management Lifecycle and Planning

The CISM exam frequently tests your understanding of the incident management lifecycle phases. Memorize the order and key activities of each phase: Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity. Look for questions asking about the 'next step' or 'first step' in a given scenario.

Incident Management and Business Resilience

Common mistake

Incident Management Lifecycle and Planning

Confusing an incident with a problem: An incident is the event; a problem is its root cause.

Incident Management and Business Resilience

Common mistake

Incident Management Lifecycle and Planning

Skipping the 'Post-Incident Activity' phase, which is crucial for learning and improvement.

Incident Management and Business Resilience

Common mistake

Incident Management Lifecycle and Planning

Failing to adequately 'Prepare' by not having a tested plan or trained team.

Incident Management and Business Resilience

Key term

Incident Response Procedure

Detailed, step-by-step instructions for handling security incidents.

Incident Management and Business Resilience

Key term

Post-Incident Review

Analysis of an incident to identify lessons learned and improve processes.

Incident Management and Business Resilience

Key term

Tabletop Exercise

A discussion-based simulation of an incident to test plans.

Incident Management and Business Resilience

Key term

Escalation Path

Defined route for reporting incidents to higher authority or specialized teams.

Incident Management and Business Resilience

Memory trick

Effective Incident Response Procedures

P-D-C-E-R-L: **P**repare, **D**etect, **C**ontain, **E**radicate, **R**ecover, **L**essons Learned. Remember the incident lifecycle!

Incident Management and Business Resilience

Exam tip

Effective Incident Response Procedures

The CISM exam often tests your understanding of the *practical application* of incident response. Look for scenarios where you need to choose the most appropriate action based on the incident type and organizational context, emphasizing communication and documentation.

Incident Management and Business Resilience

Common mistake

Effective Incident Response Procedures

Failing to regularly test and update incident response procedures, making them obsolete.

Incident Management and Business Resilience

Common mistake

Effective Incident Response Procedures

Lack of clear communication channels and defined roles during an incident, leading to chaos.

Incident Management and Business Resilience

Common mistake

Effective Incident Response Procedures

Focusing only on technical recovery without addressing legal, PR, or business impact.

Incident Management and Business Resilience

Key term

Recovery Time Objective (RTO)

Maximum tolerable downtime for a system/service.

Incident Management and Business Resilience

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss measured in time.

Incident Management and Business Resilience

Key term

Root Cause Analysis

Process of identifying the fundamental cause of an incident.

Incident Management and Business Resilience

Key term

Mean Time To Recover (MTTR)

Average time to restore services after an incident.

Incident Management and Business Resilience

Key term

Lessons Learned

Insights gained from an incident to improve processes.

Incident Management and Business Resilience

Memory trick

Incident Recovery and Post-Incident Activities

RPO and RTO: 'RPO is Point, RTO is Time.' Point for how much data you can lose, Time for how long you can be down.

Incident Management and Business Resilience

Exam tip

Incident Recovery and Post-Incident Activities

The CISM exam frequently tests your understanding of the entire incident lifecycle. For this lesson, remember that recovery is not the end; post-incident activities like 'lessons learned' and 'continuous improvement' are vital. Look for keywords like 'post-mortem,' 'root cause analysis,' and 'metrics' when discussing post-incident phases.

Incident Management and Business Resilience

Common mistake

Incident Recovery and Post-Incident Activities

Skipping the post-incident review due to time constraints or 'moving on'. This loses valuable learning opportunities.

Incident Management and Business Resilience

Common mistake

Incident Recovery and Post-Incident Activities

Focusing on blame during post-incident reviews instead of process improvement. This creates a culture of fear.

Incident Management and Business Resilience

Common mistake

Incident Recovery and Post-Incident Activities

Failing to implement and track action items from lessons learned, making the review process ineffective.

Incident Management and Business Resilience

Key term

Business Continuity Plan (BCP)

Holistic plan for maintaining critical business functions during and after disruption.

Incident Management and Business Resilience

Key term

Disaster Recovery Plan (DRP)

Subset of BCP focusing on IT system and data recovery after a disaster.

Incident Management and Business Resilience

Key term

Hot Site

Fully equipped alternative facility ready for immediate use.

Incident Management and Business Resilience

Key term

Warm Site

Partially equipped alternative facility requiring setup time.

Incident Management and Business Resilience

Key term

Cold Site

Basic facility with infrastructure, requiring significant setup time.

Incident Management and Business Resilience

Memory trick

Business Continuity and Disaster Recovery Planning

BCP is 'Big Picture Continuity,' DRP is 'Data Recovery Plan.' Think of BCP as the whole house, DRP as just the server room.

Incident Management and Business Resilience

Exam tip

Business Continuity and Disaster Recovery Planning

The CISM exam frequently tests the distinction between BCP and DRP. Remember that BCP is the overarching strategy for business resilience, while DRP is specifically for IT recovery. Keywords like 'overall business operations' point to BCP, while 'IT systems, data, applications' point to DRP.

Incident Management and Business Resilience

Common mistake

Business Continuity and Disaster Recovery Planning

Confusing BCP and DRP as interchangeable terms or thinking DRP encompasses BCP.

Incident Management and Business Resilience

Common mistake

Business Continuity and Disaster Recovery Planning

Failing to regularly test and update BCP/DRP, rendering them obsolete.

Incident Management and Business Resilience

Common mistake

Business Continuity and Disaster Recovery Planning

Not involving key stakeholders (business units, senior management) in BCP/DRP development and testing.

Incident Management and Business Resilience