FlashKeepers

CISM/CISA · CISM

CISM Information Security Program Development

Information security program development and management concepts, including security architecture and metrics, tested on the CISM exam.

35 cards · basic cards · AI-written, checked twice. Edit anything.

Study this set free Look inside first Get FlashKeepers for iPhone
What is a security program?
A coordinated set of capabilities, processes, and people designed to protect an organization's information assets and enable business objectives.
Define security architecture.
The set of structures, components, and their relationships that define how security controls are integrated into an organization's environment.
What is defense in depth?
A security strategy using multiple, layered controls at different levels to protect against various attack vectors and reduce single points of failure.
What does the zero trust model assume?
That no user, device, or service should be automatically trusted, regardless of location or network; all access requests must be verified and authenticated.
What is a security metric?
A quantifiable measure used to assess the effectiveness, efficiency, and maturity of security controls and the overall security program.
Define a Key Performance Indicator (KPI) in security.
A metric that measures whether the security program is achieving its strategic objectives and delivering expected business value.
Define a Key Risk Indicator (KRI).
A metric that provides early warning of increasing risk exposure or deteriorating control effectiveness.
What is a security maturity model?
A framework that defines levels of capability progression (usually 1-5) showing how an organization's security program evolves from ad hoc to optimized.
Define security governance.
The system of roles, responsibilities, policies, and processes that direct and control how an organization manages its security program.
What are the primary responsibilities of a CISO?
Developing and implementing the security program strategy, advising executive leadership on security risks, allocating resources, and ensuring regulatory compliance.
What is a security baseline?
The minimum set of security controls and configurations required to protect assets and meet organizational and regulatory standards.
Name three common security frameworks.
NIST Cybersecurity Framework, ISO 27001, and COBIT are widely used frameworks for organizing and implementing security controls.
What is a corrective control?
A security control designed to restore systems and data to normal operations after an attack or unwanted event has been detected.
What is the goal of a risk assessment?
To identify threats and vulnerabilities, analyze their potential impact and likelihood, and prioritize risk mitigation efforts.
What is threat modeling?
A systematic process to identify potential attackers, their objectives, attack methods, and entry points into an organization's systems.

20 more cards in the app