CISM Information Security Governance Review

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/36

flashcard set

Earn XP

Description and Tags

Comprehensive vocabulary flashcards covering the CISM exam topics including information security governance, the SABSA model, GRC processes, and security strategy development.

Last updated 3:29 PM on 7/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

37 Terms

1
New cards

Information security governance driver

Business strategy

2
New cards

Risk Analysis Driver

The Security Manager

3
New cards

Application Data Access Rights

Security administrators are responsible for enforcing these.

4
New cards

Notifications

The MOST important component of a privacy policy.

5
New cards

Information Security Governance (Definition)

A set of policies and procedures establishing a framework of security strategies and a practice area ensuring efficient utilization of information resources.

6
New cards

Main Purpose of Information Security Governance

To ensure the safety of information including its Confidentiality, Integrity, and Availability.

7
New cards

Six Basic Outcomes of Information Security Governance

Strategic alignment, value delivery, risk management, performance measurement, resource management, and integration.

8
New cards

Security Investment Goal

Optimized so that they support business objectives.

9
New cards

Primary Goals of Resource Management

Keeping a record of security practices, acquiring and making knowledge accessible, and building a security architecture for proper infrastructure resource use.

10
New cards

Corporate Governance

A set of procedures and duties performed by the board of directors and executive management to direct and control the organization.

11
New cards

Steering Committee

Consists of senior representatives of departments affected by security policies and aims to involve all stakeholders influenced by security aspects.

12
New cards

Board of Directors (Information Security Responsibility)

Responsible for identifying information assets that need protection and assigning appropriate priorities and protection levels.

13
New cards

CISO (Chief Information Security Officer)

Responsible for establishing reporting and communication channels to ensure effective information security governance.

14
New cards

GRC

Governance, Risk Management, Compliance.

15
New cards

Governance (GRC process)

The process senior management uses to direct and control an organization, developing methods to ensure employees adhere to policies and standards.

16
New cards

Risk Management (GRC process)

The process for mitigating risks, establishing risk tolerance, recognizing potential impacts, and deciding mitigation priorities based on business goals.

17
New cards

Compliance (GRC process)

The process of supervising controls and methods to ensure adherence to policies, standards, and procedures.

18
New cards

Systems Theory

A network of processes, people, technologies, relationships, events, reactions, and results interacting to achieve one common goal.

19
New cards

Information Security Business Model Elements

Organization design and strategy, people, process, and technology.

20
New cards

Governance Dynamic Interconnection

Links the organization and process elements; involves guiding and controlling an organization.

21
New cards

Culture Dynamic Interconnection

Links the organization and people elements; represents people's beliefs, opinions, and behaviors.

22
New cards

Enablement and Support Dynamic Interconnection

Links the technology and process elements; involves creating security policies, guidelines, and standards.

23
New cards

Emergence Dynamic Interconnection

Links people and process elements; indicates patterns that appear without evident reason and have results difficult to forecast.

24
New cards

Human Factors Dynamic Interconnection

Links the people and technology elements, indicating the relationship and gap between these elements.

25
New cards

Architecture Dynamic Interconnection

Links organization and technology elements; covers the policies, processes, people, and technology composing security practices.

26
New cards

SABSA

Sherwood Applied Business Security Architecture.

27
New cards

SABSA Layers

Business View, Architect's View, Designer's View, Builder's View, Tradesman's View, and Service Manager's View.

28
New cards

Business Case

Contains justifications for a security program, including cost, ROI, benefits, success factors, and Total Cost of Ownership (TCO).

29
New cards

COBIT 5

An information security governance model providing processes and best practices for the control and governance of information technology.

30
New cards

Security Baseline

The current state of security encompassing people, processes, and technologies used to measure progress toward the desired state.

31
New cards

Security Roadmap

A set of actions or steps executed to close the gaps between the current and desired states of security.

32
New cards

Policies

The foundation of a security strategy; high-level statements describing management's intent and expectations.

33
New cards

Procedures

Step-by-step instructions used to carry out a policy.

34
New cards

Standards

Written in conjunction with policies, providing specific configuration setups and protocols required (e.g., wireless protocols).

35
New cards

Guidelines

Suggestions and examples that clarify procedures; often used as a precursor for what may become a policy issue.

36
New cards

Risk Treatment Strategies

Risk mitigation, risk avoidance, risk transference, and risk acceptance.

37
New cards

Balanced Scorecard

An effective tool for evaluating the degree to which information security objectives are met and tracking the effectiveness of strategy execution.