Information security governance, strategy, and alignment with business objectives tested on the CISM exam, distinct from CISSP.
40 cards · basic cards · AI-written, checked twice. Edit anything.
- What does CISM stand for?
- Certified Information Security Manager
- What is the primary focus of CISM compared to technical certifications?
- Governance, management, and strategic alignment of information security
- Name the four domains of the CISM certification.
- Information Security Governance, Risk Management, Incident Management, and Program Management
- What is information security governance?
- The set of policies, procedures, and processes that direct and control how an organization manages information security
- What is a key objective of aligning information security strategy with business strategy?
- To ensure security investments protect business assets and enable business objectives, not hinder them
- What framework is commonly used for information security governance?
- COBIT (Control Objectives for Information and Related Technology)
- What is the ISO 27000 series primarily focused on?
- Information security management systems (ISMS) and controls
- What is ISO 27001?
- The auditable standard for establishing, implementing, and maintaining an information security management system (ISMS)
- What does an information security policy typically include?
- Objectives, scope, responsibilities, and requirements for managing security within an organization
- What is the purpose of a risk assessment in governance?
- To identify, analyze, and evaluate security risks so the organization can make informed decisions about risk treatment
- What is risk appetite?
- The level and type of risk that an organization is willing to accept in pursuit of its business objectives
- What is the difference between risk tolerance and risk appetite?
- Risk appetite is the overall strategy-level willingness to accept risk; risk tolerance is the specific acceptable variance around objectives
- What is incident management in the context of CISM?
- The process of detecting, analyzing, responding to, and recovering from security incidents to minimize impact and restore normal operations
- What should an incident response plan include?
- Definition of incidents, roles and responsibilities, communication procedures, containment steps, recovery procedures, and post-incident review processes
- What is the goal of an incident response team?
- To respond to security incidents effectively, minimize damage, preserve evidence, and restore normal business operations quickly