CISM Must know cold

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/70

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:58 PM on 3/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

71 Terms

1
New cards

What is Information Security Governance? | The system by which information security strategy is directed and controlled so it aligns with business goals, risk appetite, and accountability.

2
New cards
3
New cards

What is Information Security Risk Management? | The process of identifying, assessing, treating, monitoring, and communicating information security risk.

4
New cards
5
New cards

What is an Information Security Program? | The organized set of policies, processes, controls, resources, and activities used to manage information security.

6
New cards
7
New cards

What is Incident Management? | The structured approach for preparing for, detecting, responding to, recovering from, and learning from security incidents.

8
New cards
9
New cards

What is the main purpose of Governance? | To align security with business objectives, provide oversight, assign accountability, and guide decision-making.

10
New cards
11
New cards

What is the main purpose of Risk Management? | To understand and prioritize risk so the organization can make informed business decisions.

12
New cards
13
New cards

What is the main purpose of the Security Program? | To implement and operate the organization’s security strategy and controls.

14
New cards
15
New cards

What is the main purpose of Incident Management? | To reduce the impact of incidents through preparation, response, recovery, and improvement.

16
New cards
17
New cards

What is risk appetite? | The amount and type of risk an organization is willing to pursue or retain.

18
New cards
19
New cards

What is risk tolerance? | The acceptable variation around specific objectives or risk levels.

20
New cards
21
New cards

What is inherent risk? | The level of risk that exists before controls are applied.

22
New cards
23
New cards

What is residual risk? | The level of risk that remains after controls are applied.

24
New cards
25
New cards

What is a control? | A safeguard or countermeasure used to reduce risk.

26
New cards
27
New cards

What is a policy? | A high-level statement of management intent and direction.

28
New cards
29
New cards

What is a standard? | A mandatory rule or requirement that supports a policy.

30
New cards
31
New cards

What is a procedure? | A detailed step-by-step instruction for performing a task.

32
New cards
33
New cards

What is a guideline? | A recommended but optional approach.

34
New cards
35
New cards

What is due care? | Acting responsibly and prudently to protect assets and reduce risk.

36
New cards
37
New cards

What is due diligence? | The ongoing effort to review, monitor, and verify that security measures are appropriate and effective.

38
New cards
39
New cards

What is business alignment in security? | Ensuring security supports business goals instead of operating in isolation.

40
New cards
41
New cards

What is accountability? | Being answerable for results, decisions, or assigned responsibilities.

42
New cards
43
New cards

What is ownership in risk management? | The responsibility for accepting, managing, or escalating a risk.

44
New cards
45
New cards

What is a security strategy? | A long-term plan for achieving the organization’s security objectives.

46
New cards
47
New cards

What is a security roadmap? | A prioritized sequence of initiatives used to implement the security strategy over time.

48
New cards
49
New cards

What is a metric? | A measurable value used to evaluate performance or effectiveness.

50
New cards
51
New cards

What is a KPI? | A key performance indicator that tracks how well an important objective is being achieved.

52
New cards
53
New cards

What is risk treatment? | Choosing and implementing a response to risk such as mitigate, transfer, avoid, or accept.

54
New cards
55
New cards

What is risk acceptance? | A decision to retain a risk after understanding it and deciding it is within tolerance.

56
New cards
57
New cards

What is risk mitigation? | Reducing likelihood or impact through controls or other actions.

58
New cards
59
New cards

What is risk transfer? | Shifting some risk to another party, such as through insurance or contracts.

60
New cards
61
New cards

What is risk avoidance? | Stopping the activity that creates the risk.

62
New cards
63
New cards

What is an incident? | An event that actually threatens or harms confidentiality, integrity, or availability and requires response.

64
New cards
65
New cards

What is an event? | An observable occurrence that may or may not require action.

66
New cards
67
New cards

What is recovery? | Restoring systems, operations, or services after an incident.

68
New cards
69
New cards

What is lessons learned? | The post-incident review used to improve future response and reduce repeat issues.

70
New cards
71
New cards

What is continuous improvement in security? | The ongoing effort to enhance governance, risk management, controls, and response over time.

Explore top notes

note
Structure  of an atom
Updated 1181d ago
0.0(0)
note
APUSH Chapters 1-4 Notes
Updated 433d ago
0.0(0)
note
English Poetry Unit Test
Updated 1277d ago
0.0(0)
note
Characters for Trojan War
Updated 1203d ago
0.0(0)
note
lokal_at_global_na_demand
Updated 413d ago
0.0(0)
note
Structure  of an atom
Updated 1181d ago
0.0(0)
note
APUSH Chapters 1-4 Notes
Updated 433d ago
0.0(0)
note
English Poetry Unit Test
Updated 1277d ago
0.0(0)
note
Characters for Trojan War
Updated 1203d ago
0.0(0)
note
lokal_at_global_na_demand
Updated 413d ago
0.0(0)

Explore top flashcards

flashcards
The Cell (A2.2)
85
Updated 186d ago
0.0(0)
flashcards
It's just a game
114
Updated 477d ago
0.0(0)
flashcards
Amendments
27
Updated 1294d ago
0.0(0)
flashcards
Civil war vocab
35
Updated 1209d ago
0.0(0)
flashcards
Egzamin Angielski wszystko
565
Updated 1168d ago
0.0(0)
flashcards
mechanical systems study guide
43
Updated 194d ago
0.0(0)
flashcards
The Cell (A2.2)
85
Updated 186d ago
0.0(0)
flashcards
It's just a game
114
Updated 477d ago
0.0(0)
flashcards
Amendments
27
Updated 1294d ago
0.0(0)
flashcards
Civil war vocab
35
Updated 1209d ago
0.0(0)
flashcards
Egzamin Angielski wszystko
565
Updated 1168d ago
0.0(0)
flashcards
mechanical systems study guide
43
Updated 194d ago
0.0(0)