Free CISM Exam Flashcards

Memorize 50 essential terms and definitions for the ISACA Certified Information Security Manager (CISM). See the term, recall the definition, then flip to check yourself.

50 Flashcards
5 Topics
100% Free
TermClick to flip

The Security Manager Mindset

Tap to reveal definition
Card 1 of 50Exam Foundations

Filter by Topic

Jump to Card

About These CISM Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the ISACA Certified Information Security Manager (CISM). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Exam Foundations5 cards
Information Security Governance8 cards
Information Security Risk Management11 cards
Information Security Program12 cards
Incident Management14 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

The Security Manager Mindset

CISM tests management judgment, not deep technical skill. The best answer usually defines direction, assigns ownership, aligns to business objectives, and produces evidence management can use — not the most technical fix.

Scaled Score 450/800

CISM is scored 200–800, with 450 required to pass. The scale normalizes difficulty across forms, so it is not a raw percentage correct. Focus on domain weighting rather than counting questions.

CISM Domain Weighting

Governance 17%, Risk Management 20%, Security Program 33%, Incident Management 30%. Program and Incident Management together are about 63% of the exam — allocate study time accordingly.

One-Best-Answer Elimination

Most CISM options are partially defensible. Eliminate technically-narrow or reactive choices and pick the answer that protects business objectives, assigns accountability, and is sustainable.

Preliminary vs. Official Score

You receive a preliminary pass/fail at the test center; ISACA issues the official score after review. Treat the official result as final and remember certification still requires the experience application.

Information Security Governance

The CISM domain (17%) establishing the structure, strategy, roles, and oversight that direct security in support of business goals. Governance sets direction; management executes within it.

Governance vs. Management

Governance defines direction, risk appetite, and accountability (board/executive); management implements and operates controls. Confusing the two is a classic CISM distractor.

Security Strategy Alignment

The security strategy must support business objectives and be endorsed by senior leadership. A strategy disconnected from business goals fails regardless of technical strength.

Senior Leadership Commitment

The single most important success factor for a security program. Without executive sponsorship and funding, policies and controls lack authority and adoption — secure it first.

Roles & Responsibilities (RACI)

Clear assignment of who is Responsible, Accountable, Consulted, and Informed. Security accountability stays with management/data owners even when execution is delegated or outsourced.

Legal, Regulatory & Contractual Requirements

External obligations (law, regulation, contracts) set mandatory baselines the strategy must meet. Compliance is a minimum floor, not the goal of the program.

Security Governance Frameworks

Reference models (e.g., COBIT, ISO/IEC 27001, NIST CSF) provide structure for governance and controls. Frameworks are adapted to the organization, not adopted unchanged.

Business Case for Security Investment

Justifies spend in business terms: risk reduced, obligations met, value enabled, and cost. Security funding decisions should be framed for executives, not as technical wish lists.

Information Security Risk Management

The CISM domain (20%) covering identifying, analyzing, treating, and monitoring information risk so leadership can make informed, risk-based decisions.

Risk = Threat × Vulnerability × Impact

Risk exists only when a threat can exploit a vulnerability to cause business impact on an asset. Removing any factor reduces the risk; assess all three together.

Inherent vs. Residual Risk

Inherent risk is the exposure before controls; residual risk is what remains after controls. Management accepts residual risk only if it is within risk appetite.

Risk Appetite vs. Risk Tolerance

Appetite is the broad level of risk leadership is willing to pursue; tolerance is the acceptable variation around specific objectives. Both are set by governance, not by the security team alone.

Risk Treatment Options

Mitigate (apply controls), transfer (insure/contract), avoid (stop the activity), or accept (formally retain). The choice is a business decision justified by cost versus risk reduction.

Risk Ownership

Risk is owned by the business/asset owner who accepts it, not by the security manager. Security advises and reports; accountability for accepting residual risk stays with the business.

Qualitative vs. Quantitative Risk Analysis

Qualitative uses ratings (high/medium/low) — fast, subjective; quantitative uses monetary values (e.g., ALE) — data-heavy, comparable. Choose based on data availability and decision need.

Annual Loss Expectancy (ALE)

ALE = Single Loss Expectancy × Annual Rate of Occurrence. It expresses expected yearly loss in money so a control's cost can be compared to the risk it reduces.

Risk Assessment vs. Risk Analysis

Analysis estimates likelihood and impact of identified risks; assessment is the broader process of identifying, analyzing, and evaluating risks against criteria for treatment decisions.

Key Risk Indicator (KRI)

A metric that signals rising risk exposure before it becomes a loss, enabling early action. KRIs feed risk monitoring and reporting to leadership.

Risk Monitoring & Reporting

Continuous tracking of risk levels, controls, and KRIs, reported to the right stakeholders. Risk is dynamic — a one-time assessment is insufficient.

Information Security Program

The CISM domain (33%, the largest) covering building, resourcing, and managing the program that executes the security strategy through people, processes, and technology.

Program vs. Strategy

The strategy defines what to achieve and why; the program is how it is delivered and operated. A program without strategy alignment drifts and cannot justify its value.

Asset Identification & Classification

You cannot protect what you have not identified and valued. Classification by sensitivity/criticality drives proportionate control selection — it is the foundation of the program.

Data Owner vs. Data Custodian

The owner (business) classifies data and approves access and risk; the custodian (IT/security) implements and maintains protective controls. Accountability remains with the owner.

Policy, Standard, Procedure, Guideline

Policy = mandatory intent; standard = mandatory specifics; procedure = step-by-step how-to; guideline = recommended practice. Only policies/standards are enforceable requirements.

Preventive, Detective, Corrective Controls

Preventive stops an incident; detective identifies one in progress; corrective restores after one. A balanced program uses all three — relying only on prevention is fragile.

Administrative, Technical, Physical Controls

Administrative = policies/process; technical = system/logical; physical = facility protection. Defense in depth layers all three so one failure does not collapse security.

Defense in Depth

Layering multiple, independent controls so the failure of one does not cause total compromise. The goal is resilient overlap, not a single perfect control.

Control Testing & Evaluation

Controls must be tested for design and operating effectiveness, not assumed to work. Untested controls give false assurance and are a common audit and exam trap.

Security Awareness & Training

Targets the human risk factor and must be role-relevant and reinforced. Awareness changes behavior; one-time annual training without reinforcement has limited effect.

Third-Party / Supplier Risk

Outsourcing transfers work, not accountability. The organization remains responsible for vendor security through contracts, right-to-audit, and ongoing monitoring.

Security Program Metrics

Metrics must show whether the program reduces risk and supports objectives, communicated to the right audience. Activity counts alone do not demonstrate value to leadership.

Incident Management

The CISM domain (30%) covering preparing for, detecting, responding to, and recovering from security incidents while limiting business impact.

Event vs. Incident

An event is any observable occurrence; an incident is an event that actually or potentially harms confidentiality, integrity, or availability. Classification triggers the response process.

Incident Response Plan (IRP)

The documented, tested process and roles for handling incidents. Plans must be exercised before a real incident; an untested plan typically fails under pressure.

Incident Response Lifecycle

Prepare → detect/analyze → contain → eradicate → recover → post-incident review. Containment usually precedes eradication to stop spread before removing the cause.

Containment Priority

The first operational goal during an active incident is to limit damage and stop spread, balancing speed against preserving evidence and maintaining critical operations.

Business Impact Analysis (BIA)

Identifies critical processes and the impact of disruption over time, producing recovery priorities. BIA outputs drive RTO/RPO and the continuity and recovery plans.

RTO vs. RPO

RTO = maximum tolerable time to restore a process after disruption; RPO = maximum tolerable data loss measured in time. RTO is about downtime; RPO is about data currency.

BCP vs. DRP

Business Continuity Plan keeps critical business functions running during disruption; Disaster Recovery Plan restores IT systems and data. DRP is a technical subset supporting the BCP.

Incident Classification & Severity

Categorizing incidents by type and severity drives escalation, resourcing, and communication. Misclassification causes either over-reaction or dangerous under-response.

Incident Communication & Escalation

Predefined notification paths to management, legal, regulators, and customers. Communication is planned in advance so the team is not improvising during a live incident.

Chain of Custody

Documented handling of evidence to keep it admissible and credible. Improper collection or handling during response can make evidence unusable in legal action.

Eradication & Recovery

Eradication removes the root cause (malware, access, vulnerability); recovery validates and returns systems to normal. Restoring before eradicating risks immediate reinfection.

Post-Incident Review (Lessons Learned)

A structured review after closure to identify root cause and improve controls and the plan. Skipping it guarantees repeat incidents; it is a required, not optional, step.

Incident Testing & Exercises

Tabletop and simulation exercises validate the IRP, BCP, and DRP and build team readiness. Plans degrade over time, so testing must be periodic and documented.

Frequently Asked Questions

What are the four CISM domains?

ISACA's CISM exam covers four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The Program and Incident Management domains together carry roughly 63% of the exam, reflecting CISM's management and execution focus.

What is the CISM passing score?

CISM uses a scaled score from 200 to 800, and a score of 450 or higher is required to pass. The scaled score is not a percentage of correct answers; it normalizes difficulty across exam forms. Candidates receive a preliminary result at the test center and an official score after ISACA review.

How is the CISM exam structured?

The CISM exam has 150 multiple-choice questions with a 4-hour (240-minute) time limit. Items emphasize the security manager's perspective — what to decide, fund, communicate, and improve — rather than deep technical implementation. The exam is delivered at PSI test centers or via remote online proctoring.

What experience is required for CISM certification?

Anyone may sit the CISM exam, but certification requires five years of professional information security management experience. Experience waivers of up to two years are available for certain credentials and education. Candidates must apply for certification within five years of passing the exam.

When does the CISM exam content outline change?

ISACA states the CISM Exam Content Outline updates effective 3 November 2026. Candidates testing before that date should study the current four-domain outline and avoid mixing it with the later blueprint. Maintaining certification requires 120 CPE hours per three-year reporting cycle plus annual maintenance fees.

Same family resources

Explore More ISACA Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.