1/9
Flashcards covering key concepts in Information Risk Management, focusing on definitions and explanations relevant to CISM certification.
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
Information Risk Management
The process of handling risks to information assets to ensure they are at an acceptable level as defined by their owners.
Risk Assessment
A structured process that identifies, evaluates, and determines the severity of risks to an organization.
Risk Response
Actions taken to manage risks, which may include avoiding, mitigating, transferring, or accepting the risk.
Stakeholders
Individuals or groups who have an interest or concern in an organization, including management, clients, and regulators.
Continuous Monitoring
Ongoing process of regularly reviewing risks and the effectiveness of risk management efforts.
Asset Valuation
The process of determining the value of an organization's assets to drive security efforts.
Risk Treatment Types
Different strategies for managing risk, including avoidance, mitigation, transfer, and acceptance.
Communication of Risks
The practice of reporting risks and sharing information about risk management activities with relevant stakeholders.
CISM Certification
Certified Information Security Manager certification focused on managing information security aligned with organizational goals.
Effective Control Measures
Strategies and actions implemented to reduce risks to an acceptable level.