Information security program development and management concepts, including security architecture and metrics, tested on the CISM exam.
35 cards · basic cards · AI-written, checked twice. Edit anything.
- What is a security program?
- A coordinated set of capabilities, processes, and people designed to protect an organization's information assets and enable business objectives.
- Define security architecture.
- The set of structures, components, and their relationships that define how security controls are integrated into an organization's environment.
- What is defense in depth?
- A security strategy using multiple, layered controls at different levels to protect against various attack vectors and reduce single points of failure.
- What does the zero trust model assume?
- That no user, device, or service should be automatically trusted, regardless of location or network; all access requests must be verified and authenticated.
- What is a security metric?
- A quantifiable measure used to assess the effectiveness, efficiency, and maturity of security controls and the overall security program.
- Define a Key Performance Indicator (KPI) in security.
- A metric that measures whether the security program is achieving its strategic objectives and delivering expected business value.
- Define a Key Risk Indicator (KRI).
- A metric that provides early warning of increasing risk exposure or deteriorating control effectiveness.
- What is a security maturity model?
- A framework that defines levels of capability progression (usually 1-5) showing how an organization's security program evolves from ad hoc to optimized.
- Define security governance.
- The system of roles, responsibilities, policies, and processes that direct and control how an organization manages its security program.
- What are the primary responsibilities of a CISO?
- Developing and implementing the security program strategy, advising executive leadership on security risks, allocating resources, and ensuring regulatory compliance.
- What is a security baseline?
- The minimum set of security controls and configurations required to protect assets and meet organizational and regulatory standards.
- Name three common security frameworks.
- NIST Cybersecurity Framework, ISO 27001, and COBIT are widely used frameworks for organizing and implementing security controls.
- What is a corrective control?
- A security control designed to restore systems and data to normal operations after an attack or unwanted event has been detected.
- What is the goal of a risk assessment?
- To identify threats and vulnerabilities, analyze their potential impact and likelihood, and prioritize risk mitigation efforts.
- What is threat modeling?
- A systematic process to identify potential attackers, their objectives, attack methods, and entry points into an organization's systems.