Free CISM Exam Flashcards
Memorize 50 essential terms and definitions for the ISACA Certified Information Security Manager (CISM). See the term, recall the definition, then flip to check yourself.
The Security Manager Mindset
CISM tests management judgment, not deep technical skill. The best answer usually defines direction, assigns ownership, aligns to business objectives, and produces evidence management can use — not the most technical fix.
Filter by Topic
Jump to Card
About These CISM Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the ISACA Certified Information Security Manager (CISM). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
The Security Manager Mindset
CISM tests management judgment, not deep technical skill. The best answer usually defines direction, assigns ownership, aligns to business objectives, and produces evidence management can use — not the most technical fix.
Scaled Score 450/800
CISM is scored 200–800, with 450 required to pass. The scale normalizes difficulty across forms, so it is not a raw percentage correct. Focus on domain weighting rather than counting questions.
CISM Domain Weighting
Governance 17%, Risk Management 20%, Security Program 33%, Incident Management 30%. Program and Incident Management together are about 63% of the exam — allocate study time accordingly.
One-Best-Answer Elimination
Most CISM options are partially defensible. Eliminate technically-narrow or reactive choices and pick the answer that protects business objectives, assigns accountability, and is sustainable.
Preliminary vs. Official Score
You receive a preliminary pass/fail at the test center; ISACA issues the official score after review. Treat the official result as final and remember certification still requires the experience application.
Information Security Governance
The CISM domain (17%) establishing the structure, strategy, roles, and oversight that direct security in support of business goals. Governance sets direction; management executes within it.
Governance vs. Management
Governance defines direction, risk appetite, and accountability (board/executive); management implements and operates controls. Confusing the two is a classic CISM distractor.
Security Strategy Alignment
The security strategy must support business objectives and be endorsed by senior leadership. A strategy disconnected from business goals fails regardless of technical strength.
Senior Leadership Commitment
The single most important success factor for a security program. Without executive sponsorship and funding, policies and controls lack authority and adoption — secure it first.
Roles & Responsibilities (RACI)
Clear assignment of who is Responsible, Accountable, Consulted, and Informed. Security accountability stays with management/data owners even when execution is delegated or outsourced.
Legal, Regulatory & Contractual Requirements
External obligations (law, regulation, contracts) set mandatory baselines the strategy must meet. Compliance is a minimum floor, not the goal of the program.
Security Governance Frameworks
Reference models (e.g., COBIT, ISO/IEC 27001, NIST CSF) provide structure for governance and controls. Frameworks are adapted to the organization, not adopted unchanged.
Business Case for Security Investment
Justifies spend in business terms: risk reduced, obligations met, value enabled, and cost. Security funding decisions should be framed for executives, not as technical wish lists.
Information Security Risk Management
The CISM domain (20%) covering identifying, analyzing, treating, and monitoring information risk so leadership can make informed, risk-based decisions.
Risk = Threat × Vulnerability × Impact
Risk exists only when a threat can exploit a vulnerability to cause business impact on an asset. Removing any factor reduces the risk; assess all three together.
Inherent vs. Residual Risk
Inherent risk is the exposure before controls; residual risk is what remains after controls. Management accepts residual risk only if it is within risk appetite.
Risk Appetite vs. Risk Tolerance
Appetite is the broad level of risk leadership is willing to pursue; tolerance is the acceptable variation around specific objectives. Both are set by governance, not by the security team alone.
Risk Treatment Options
Mitigate (apply controls), transfer (insure/contract), avoid (stop the activity), or accept (formally retain). The choice is a business decision justified by cost versus risk reduction.
Risk Ownership
Risk is owned by the business/asset owner who accepts it, not by the security manager. Security advises and reports; accountability for accepting residual risk stays with the business.
Qualitative vs. Quantitative Risk Analysis
Qualitative uses ratings (high/medium/low) — fast, subjective; quantitative uses monetary values (e.g., ALE) — data-heavy, comparable. Choose based on data availability and decision need.
Annual Loss Expectancy (ALE)
ALE = Single Loss Expectancy × Annual Rate of Occurrence. It expresses expected yearly loss in money so a control's cost can be compared to the risk it reduces.
Risk Assessment vs. Risk Analysis
Analysis estimates likelihood and impact of identified risks; assessment is the broader process of identifying, analyzing, and evaluating risks against criteria for treatment decisions.
Key Risk Indicator (KRI)
A metric that signals rising risk exposure before it becomes a loss, enabling early action. KRIs feed risk monitoring and reporting to leadership.
Risk Monitoring & Reporting
Continuous tracking of risk levels, controls, and KRIs, reported to the right stakeholders. Risk is dynamic — a one-time assessment is insufficient.
Information Security Program
The CISM domain (33%, the largest) covering building, resourcing, and managing the program that executes the security strategy through people, processes, and technology.
Program vs. Strategy
The strategy defines what to achieve and why; the program is how it is delivered and operated. A program without strategy alignment drifts and cannot justify its value.
Asset Identification & Classification
You cannot protect what you have not identified and valued. Classification by sensitivity/criticality drives proportionate control selection — it is the foundation of the program.
Data Owner vs. Data Custodian
The owner (business) classifies data and approves access and risk; the custodian (IT/security) implements and maintains protective controls. Accountability remains with the owner.
Policy, Standard, Procedure, Guideline
Policy = mandatory intent; standard = mandatory specifics; procedure = step-by-step how-to; guideline = recommended practice. Only policies/standards are enforceable requirements.
Preventive, Detective, Corrective Controls
Preventive stops an incident; detective identifies one in progress; corrective restores after one. A balanced program uses all three — relying only on prevention is fragile.
Administrative, Technical, Physical Controls
Administrative = policies/process; technical = system/logical; physical = facility protection. Defense in depth layers all three so one failure does not collapse security.
Defense in Depth
Layering multiple, independent controls so the failure of one does not cause total compromise. The goal is resilient overlap, not a single perfect control.
Control Testing & Evaluation
Controls must be tested for design and operating effectiveness, not assumed to work. Untested controls give false assurance and are a common audit and exam trap.
Security Awareness & Training
Targets the human risk factor and must be role-relevant and reinforced. Awareness changes behavior; one-time annual training without reinforcement has limited effect.
Third-Party / Supplier Risk
Outsourcing transfers work, not accountability. The organization remains responsible for vendor security through contracts, right-to-audit, and ongoing monitoring.
Security Program Metrics
Metrics must show whether the program reduces risk and supports objectives, communicated to the right audience. Activity counts alone do not demonstrate value to leadership.
Incident Management
The CISM domain (30%) covering preparing for, detecting, responding to, and recovering from security incidents while limiting business impact.
Event vs. Incident
An event is any observable occurrence; an incident is an event that actually or potentially harms confidentiality, integrity, or availability. Classification triggers the response process.
Incident Response Plan (IRP)
The documented, tested process and roles for handling incidents. Plans must be exercised before a real incident; an untested plan typically fails under pressure.
Incident Response Lifecycle
Prepare → detect/analyze → contain → eradicate → recover → post-incident review. Containment usually precedes eradication to stop spread before removing the cause.
Containment Priority
The first operational goal during an active incident is to limit damage and stop spread, balancing speed against preserving evidence and maintaining critical operations.
Business Impact Analysis (BIA)
Identifies critical processes and the impact of disruption over time, producing recovery priorities. BIA outputs drive RTO/RPO and the continuity and recovery plans.
RTO vs. RPO
RTO = maximum tolerable time to restore a process after disruption; RPO = maximum tolerable data loss measured in time. RTO is about downtime; RPO is about data currency.
BCP vs. DRP
Business Continuity Plan keeps critical business functions running during disruption; Disaster Recovery Plan restores IT systems and data. DRP is a technical subset supporting the BCP.
Incident Classification & Severity
Categorizing incidents by type and severity drives escalation, resourcing, and communication. Misclassification causes either over-reaction or dangerous under-response.
Incident Communication & Escalation
Predefined notification paths to management, legal, regulators, and customers. Communication is planned in advance so the team is not improvising during a live incident.
Chain of Custody
Documented handling of evidence to keep it admissible and credible. Improper collection or handling during response can make evidence unusable in legal action.
Eradication & Recovery
Eradication removes the root cause (malware, access, vulnerability); recovery validates and returns systems to normal. Restoring before eradicating risks immediate reinfection.
Post-Incident Review (Lessons Learned)
A structured review after closure to identify root cause and improve controls and the plan. Skipping it guarantees repeat incidents; it is a required, not optional, step.
Incident Testing & Exercises
Tabletop and simulation exercises validate the IRP, BCP, and DRP and build team readiness. Plans degrade over time, so testing must be periodic and documented.
Frequently Asked Questions
What are the four CISM domains?
ISACA's CISM exam covers four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The Program and Incident Management domains together carry roughly 63% of the exam, reflecting CISM's management and execution focus.
What is the CISM passing score?
CISM uses a scaled score from 200 to 800, and a score of 450 or higher is required to pass. The scaled score is not a percentage of correct answers; it normalizes difficulty across exam forms. Candidates receive a preliminary result at the test center and an official score after ISACA review.
How is the CISM exam structured?
The CISM exam has 150 multiple-choice questions with a 4-hour (240-minute) time limit. Items emphasize the security manager's perspective — what to decide, fund, communicate, and improve — rather than deep technical implementation. The exam is delivered at PSI test centers or via remote online proctoring.
What experience is required for CISM certification?
Anyone may sit the CISM exam, but certification requires five years of professional information security management experience. Experience waivers of up to two years are available for certain credentials and education. Candidates must apply for certification within five years of passing the exam.
When does the CISM exam content outline change?
ISACA states the CISM Exam Content Outline updates effective 3 November 2026. Candidates testing before that date should study the current four-domain outline and avoid mixing it with the later blueprint. Maintaining certification requires 120 CPE hours per three-year reporting cycle plus annual maintenance fees.
Explore More ISACA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.