Click Study Flashcards above to open the flashcard hub — hundreds of CISM cards you can flip, match, type, or quiz yourself on. Every card is drawn from the four official ISACA domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CISM Flashcard Study Modes
Flip mode lets you work through cards one at a time and check yourself. Match turns terms and definitions into a timed pairing game. Type shows the definition and asks you to spell the term back, so a card like Zero trust has to come from memory rather than recognition. Quiz builds multiple choice questions from the same cards.

Why Flashcards Work for the CISM
Information Security Program carries 72 cards and the heaviest official weight at 33%, so it anchors the deck. The cards drill the vocabulary of building and running controls: agreement types such as SLA and OLA, build-and-deploy ideas like Secure SDLC and Shift left, and access language including Need to know. Hardening and Data states show up as short definitional prompts you should be able to restate without hedging.
Incident Management follows closely with 70 cards against a 30% weight. Here the terms cover detection and response structures like SOC, SIEM and CSIRT, the measurement language of MTBF and MTTR, and recovery options where Hot site, Warm site and Cold site have to be told apart by cost and readiness rather than by feel.
Information Security Risk Management holds 53 cards and 20% of the exam. The cards separate metric families, so KRI, KPI and KGI each need their own definition, and they push on core risk vocabulary through Threat, Exploit and Risk capacity. Accountability and calculation both appear, with Risk owner on one side and the ALE formula on the other.
Information Security Governance closes the deck with 49 cards at 17%. These fronts drill frameworks and structures such as COBIT, GRC and RACI, the document hierarchy running through Policy, Standard and Procedure, and duty-of-care language including Due care. ROSI appears as the card that ties security spending back to business justification.
The CISM is dense with management vocabulary — governance roles, risk metrics, control types, and recovery objectives.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CISM Flashcards by Domain
The cards are organized by the four official ISACA domains. The weighting is lopsided toward execution, so lead with the Information Security Program and Incident Management:[1]
| Domain | Exam weight |
|---|---|
| Information Security Program | 33% |
| Incident Management | 30% |
| Information Security Risk Management | 20% |
| Information Security Governance | 17% |
How to Get the Most Out of These Flashcards
- Start with Information Security Program. At 72 cards and 33% of the exam, it is both the largest block in the deck and the heaviest on the blueprint, so early repetitions pay off most.
- Type-drill the formulas and acronyms. Cards like ALE formula and ROSI reward exact recall, and typing them forces you to produce the answer instead of recognizing it in a list.
- Use Match for lookalike sets. Recovery tiers such as Hot site, Warm site and Cold site, and metric pairs like MTBF and MTTR, separate fastest under time pressure.
- Switch to the practice test once Quiz runs clean. When multiple choice on Incident Management and Information Security Risk Management stops surprising you, move to scenario questions and use the study guide for gaps.
- Keep a rotating cadence. Work one domain per session in small batches, then re-Flip the 49 Information Security Governance cards alongside whatever you studied, so framework terms stay fresh.
CISM Flashcards FAQ
Hundreds of free CISM flashcards, organized across all four ISACA domains — Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the CISM's management vocabulary across governance, risk, program, and incident management.
All four ISACA domains: Information Security Governance (strategy, frameworks, roles), Information Security Risk Management (appetite, assessment, treatment, metrics), Information Security Program (controls, classification, vendors), and Incident Management (BIA, BCP/DRP, the incident response lifecycle).
Study by weight: the Information Security Program (33%) and Incident Management (30%) are nearly two-thirds of the exam, so spend the most time there. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISACA exam content outline, covering all four domains in their official proportions — with the program and incident-management content weighted most heavily.
CISM flashcard bank
All 244 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Information Security Governance (49)
- Information security governance
Show answerHide answer
The board/executive responsibilities that set direction, ensure objectives are met, manage risk, and verify resources are used responsibly. Leadership owns security.
- RACI
Show answerHide answer
Responsible (does it), Accountable (answers for it — only one), Consulted (gives input), Informed (kept updated). Assigns ownership for tasks and controls.
- Risk appetite
Show answerHide answer
The amount and type of risk an organization is willing to pursue to meet its objectives — set by the board.
- Due care
Show answerHide answer
Acting on due diligence — implementing and maintaining reasonable controls a prudent organization would (doing the right thing).
- Due diligence
Show answerHide answer
Doing the research and verification — investigating risks and building the plans/policies needed (knowing what's right).
- Security strategy
Show answerHide answer
The long-term plan aligning the information security program to business objectives — the desired future state.
- Business alignment
Show answerHide answer
Ensuring security goals, investments, and metrics map directly to enterprise goals so security delivers value.
- GRC
Show answerHide answer
Governance, Risk, and Compliance — the integrated discipline coordinating how an organization is directed, manages risk, and meets obligations.
- Security steering committee
Show answerHide answer
A cross-functional body that aligns the security strategy with business priorities and directs program investment.
- Policy
Show answerHide answer
A high-level, mandatory statement of management intent and goals for security.
- Standard
Show answerHide answer
Mandatory, specific requirements that support a policy (e.g., 'use AES-256').
- Procedure
Show answerHide answer
Detailed, mandatory step-by-step instructions for carrying out a task securely.
- Guideline
Show answerHide answer
A recommended, discretionary best practice — the only optional item in the governance hierarchy.
- Baseline (security)
Show answerHide answer
A minimum required level of security that systems must meet.
- Governance document hierarchy
Show answerHide answer
Policy → Standard → Procedure → Guideline (guideline is the only optional one).
- Maturity model (CMMI)
Show answerHide answer
A staged scale (e.g., levels 1-5) rating process capability; the target a gap analysis measures against.
- Gap analysis
Show answerHide answer
A comparison of the current security state vs. a desired/target state to identify what's missing and drive the roadmap.
- Business case
Show answerHide answer
The cost/benefit justification (often ROSI) used to win management funding for a security investment.
- ROSI
Show answerHide answer
Return on Security Investment — the financial framing of a control's value used in a business case.
- COBIT
Show answerHide answer
ISACA's framework for the governance and management of enterprise IT.
- ISO/IEC 27001
Show answerHide answer
The international standard for a certifiable Information Security Management System (ISMS).
- ISO/IEC 27002
Show answerHide answer
A catalog of information security controls supporting ISO/IEC 27001.
- NIST Cybersecurity Framework
Show answerHide answer
A voluntary framework (Govern, Identify, Protect, Detect, Respond, Recover) for managing cybersecurity risk.
- Security culture
Show answerHide answer
The shared attitudes and behaviors of staff that enable or undermine security controls.
- Tone at the top
Show answerHide answer
The example and priority senior leadership sets, which shapes the organization's security culture.
- Strategic alignment
Show answerHide answer
Aligning security objectives with business objectives so security supports the mission.
- Value delivery
Show answerHide answer
Ensuring security investments deliver measurable value relative to their cost.
- Legal/regulatory/contractual requirements
Show answerHide answer
Obligations (laws, regulations, contracts) the security program must satisfy as part of governance.
- Organizational structure (security)
Show answerHide answer
How security roles and reporting lines are arranged so accountability is clear.
- CISO role
Show answerHide answer
The senior executive accountable for the information security program and for reporting risk to leadership.
- Data owner
Show answerHide answer
The senior business manager accountable for an asset — sets its classification and protection requirements.
- Data custodian
Show answerHide answer
The party (usually IT) responsible for implementing and maintaining the controls protecting data.
- Accountable vs. responsible
Show answerHide answer
Accountable = answers for the outcome (one party); Responsible = does the work (one or more).
- Information governance
Show answerHide answer
The framework of policies and standards governing how information is created, used, and retained.
- Strategic planning (security)
Show answerHide answer
Planning budgets, resources, and a roadmap to reach the security strategy's target state.
- Governance vs. management
Show answerHide answer
Governance sets direction and is accountable (board); management executes within that direction.
- Security balanced scorecard
Show answerHide answer
A tool linking security objectives to business perspectives so leadership can track strategy.
- Prudent person rule
Show answerHide answer
The standard of acting as a reasonable, careful person would — satisfied by due diligence plus due care.
- Steering committee charter
Show answerHide answer
The document defining the steering committee's authority, membership, and responsibilities.
- Security roles and responsibilities
Show answerHide answer
Clearly defined duties (owner, custodian, user, manager) so accountability is unambiguous.
- Compliance vs. security
Show answerHide answer
Compliance meets external requirements; security manages risk — compliance alone does not equal secure.
- Regulatory drivers
Show answerHide answer
Laws and regulations (e.g., GDPR, HIPAA, SOX, PCI DSS) that shape security obligations.
- Acceptable use policy (AUP)
Show answerHide answer
A policy defining how staff may use organizational systems and data.
- ISACA Code of Professional Ethics
Show answerHide answer
The ethical standards CISM holders must follow to keep the certification in good standing.
- Information security governance outcomes
Show answerHide answer
Strategic alignment, risk management, value delivery, resource management, and performance measurement.
- Top-down security approach
Show answerHide answer
Driving security from senior management down, which is more effective than a grassroots/bottom-up effort.
- Security program charter
Show answerHide answer
Senior-management authorization that establishes the program's mandate and authority.
- Stakeholder analysis
Show answerHide answer
Identifying the parties affected by security decisions so their needs inform strategy.
- Resource management (governance)
Show answerHide answer
Ensuring security knowledge, infrastructure, and people are used efficiently.
Information Security Risk Management (53)
- Risk tolerance
Show answerHide answer
The acceptable deviation around the risk appetite for a specific objective or risk.
- Risk capacity
Show answerHide answer
The maximum amount of risk an organization could actually absorb before it fails.
- Inherent risk
Show answerHide answer
The level of risk that exists before any controls are applied — the raw exposure.
- Residual risk
Show answerHide answer
The risk that remains after controls are in place; the risk owner formally accepts it.
- Risk treatment
Show answerHide answer
The chosen response: mitigate (reduce), transfer (insure/outsource), avoid (stop), or accept.
- Risk mitigation
Show answerHide answer
Reducing risk by adding controls that lower likelihood or impact.
- Risk transfer
Show answerHide answer
Shifting the financial impact of a risk to a third party (e.g., insurance, outsourcing).
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk acceptance
Show answerHide answer
A documented, risk-owner-approved decision to tolerate a risk within the appetite.
- Risk assessment
Show answerHide answer
Identifying and analyzing risks (likelihood and impact) to prioritize them.
- Risk analysis
Show answerHide answer
Determining the likelihood and impact of identified risks (qualitative or quantitative).
- Qualitative risk analysis
Show answerHide answer
Subjective risk rating using scales like high/medium/low — fast, not dollar-based.
- Quantitative risk analysis
Show answerHide answer
Objective, dollar-based risk analysis using SLE, ARO, and ALE.
- Threat
Show answerHide answer
Any potential event or actor that could exploit a vulnerability to harm an asset.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Exploit
Show answerHide answer
The act or tool that leverages a vulnerability to cause harm.
- Likelihood x impact
Show answerHide answer
The core risk-rating equation: probability of an event times the harm it would cause.
- Exposure Factor (EF)
Show answerHide answer
The percentage of an asset's value lost if a specific risk event occurs.
- Single Loss Expectancy (SLE)
Show answerHide answer
The expected loss from one event: SLE = Asset Value x Exposure Factor.
- Annualized Rate of Occurrence (ARO)
Show answerHide answer
The expected number of times a risk event occurs in one year.
- Annualized Loss Expectancy (ALE)
Show answerHide answer
The expected yearly cost of a risk: ALE = SLE x ARO. Used to cost-justify controls.
- ALE formula
Show answerHide answer
ALE = SLE x ARO, where SLE = Asset Value x Exposure Factor.
- Risk register
Show answerHide answer
A documented inventory of risks with ratings, owners, treatments, controls, and status.
- Risk owner
Show answerHide answer
The party accountable for a risk who formally accepts its residual level (usually senior management).
- Control owner
Show answerHide answer
The party responsible for designing, implementing, and operating a specific control.
- KRI
Show answerHide answer
Key Risk Indicator — a forward-looking metric that signals rising risk before an incident.
- KPI
Show answerHide answer
Key Performance Indicator — a metric measuring how well the program or a control performs.
- KGI
Show answerHide answer
Key Goal Indicator — a metric showing whether a defined goal was achieved.
- Control deficiency
Show answerHide answer
A control that is missing or not operating effectively, leaving a gap that increases risk.
- Third-party risk
Show answerHide answer
Risk introduced through vendors and the supply chain; a provider's breach is still your problem.
- Supply-chain risk
Show answerHide answer
Risk arising from the products, services, and dependencies in an organization's supply chain.
- Emerging risk
Show answerHide answer
A new or evolving threat (e.g., AI-enabled attacks) the program must continuously scan for.
- Risk monitoring
Show answerHide answer
Ongoing tracking of risk levels and KRIs so the manager can act and report changes.
- Risk reporting
Show answerHide answer
Communicating risk posture to senior management so they can make informed decisions.
- Cost-benefit (control)
Show answerHide answer
A control is justified only when its annual cost is less than the reduction in ALE it delivers.
- Risk vs. control ownership
Show answerHide answer
Risk owner accepts the residual risk; control owner operates the control.
- Threat landscape
Show answerHide answer
The current set of threats and actors relevant to the organization, which changes over time.
- Vulnerability assessment
Show answerHide answer
Identifying and rating weaknesses in systems and processes (a management input to risk).
- Risk identification
Show answerHide answer
Finding the assets, threats, vulnerabilities, and scenarios that could affect the organization.
- Asset valuation
Show answerHide answer
Determining an asset's worth (tangible and intangible) to prioritize its protection.
- Annualized cost of safeguard (ACS)
Show answerHide answer
The yearly cost of a control; a control is justified when ACS is less than the ALE reduction it gives.
- Risk heat map
Show answerHide answer
A visual matrix plotting risks by likelihood and impact to prioritize them.
- Risk scenario
Show answerHide answer
A plausible description of how a threat could exploit a vulnerability and the resulting impact.
- Risk aggregation
Show answerHide answer
Combining individual risks to understand the organization's overall exposure.
- Risk velocity
Show answerHide answer
How quickly a risk would impact the organization once it materializes.
- Threat modeling (management view)
Show answerHide answer
Identifying likely threats to a system to prioritize controls during design.
- Risk-based approach
Show answerHide answer
Allocating security effort and spending based on the level of risk, not uniformly.
- Risk communication
Show answerHide answer
Conveying risk clearly to decision-makers so they can choose a response.
- Control self-assessment (CSA)
Show answerHide answer
A process where control owners assess their own controls' effectiveness.
- Continuous risk monitoring
Show answerHide answer
Ongoing tracking of risk and control status rather than point-in-time review.
- Risk treatment plan
Show answerHide answer
A documented plan of the chosen responses, owners, and timelines for treating risks.
- Acceptable risk
Show answerHide answer
Residual risk that falls within the organization's defined risk appetite/tolerance.
- Risk reassessment
Show answerHide answer
Re-evaluating risk as assets, threats, and the business environment change.
Information Security Program (72)
- Information security program
Show answerHide answer
The coordinated set of activities, controls, resources, and people that executes the security strategy.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so that if one fails, others still protect the asset.
- Least privilege
Show answerHide answer
Granting users and processes only the minimum access needed to do their job.
- Separation of duties
Show answerHide answer
Splitting a sensitive task so no single person can complete it alone, reducing fraud/error.
- Asset classification
Show answerHide answer
Labeling information assets by sensitivity so the right protection is applied; assigned by the data owner.
- Data classification levels
Show answerHide answer
Sensitivity labels (e.g., public, internal, confidential, restricted) that drive handling and controls.
- Preventive control
Show answerHide answer
A control that stops an incident before it happens (firewall rule, access control, encryption).
- Detective control
Show answerHide answer
A control that identifies an incident in progress or after the fact (IDS, log review, SIEM alert).
- Corrective control
Show answerHide answer
A control that restores systems after an incident (backups, patching, failover).
- Deterrent control
Show answerHide answer
A control that discourages a would-be attacker (warning banners, visible cameras, sanctions).
- Compensating control
Show answerHide answer
An alternative control used when the primary control isn't feasible (extra monitoring for SoD).
- Administrative control
Show answerHide answer
A policy/people control (policies, training, background checks).
- Technical control
Show answerHide answer
A technology-enforced (logical) control (firewalls, encryption, access control).
- Physical control
Show answerHide answer
A control in the physical world (locks, guards, cameras, fences).
- Control design and selection
Show answerHide answer
Choosing controls that meet the risk cost-effectively based on classification and requirements.
- Control implementation
Show answerHide answer
Deploying and integrating chosen controls into business processes and technology.
- Control testing and evaluation
Show answerHide answer
Verifying controls work as intended via assessment, audit, or testing.
- Security awareness training
Show answerHide answer
Ongoing education that reduces human risk by teaching staff to recognize threats and follow policy.
- Awareness vs. training vs. education
Show answerHide answer
Awareness builds recognition; training builds skills; education builds deep understanding.
- Management of external services
Show answerHide answer
Governing vendors/providers to security requirements via contracts, SLAs, and monitoring.
- SLA
Show answerHide answer
Service Level Agreement — a measurable service commitment between the organization and an external provider.
- OLA
Show answerHide answer
Operational Level Agreement — an internal agreement between teams that supports an SLA.
- Vendor risk management
Show answerHide answer
Assessing and monitoring the security risk introduced by third-party vendors.
- Program metrics
Show answerHide answer
Measures (KPIs/KGIs) that make the program's performance and value visible to management.
- Program communications and reporting
Show answerHide answer
Communicating program status, performance, and risk to stakeholders and leadership.
- Secure SDLC
Show answerHide answer
Embedding security into every phase of the system development lifecycle ('shift left').
- Shift left
Show answerHide answer
Addressing security early in development, where flaws are cheaper to fix.
- Policies, procedures, guidelines
Show answerHide answer
The program's documented rules: mandatory policies/procedures and optional guidelines.
- Industry standards and frameworks
Show answerHide answer
Recognized structures (ISO 27001, NIST CSF, COBIT) used to build and benchmark the program.
- Program resources
Show answerHide answer
The budget, people, and tools needed to build and run the security program.
- Information asset identification
Show answerHide answer
Inventorying the information assets the program must protect before classifying them.
- Need to know
Show answerHide answer
Limiting access to only the specific information required for a person's role.
- Access control (program)
Show answerHide answer
Managing who can access what, enforced through models like RBAC, MAC, DAC, and ABAC.
- Role-based access control (RBAC)
Show answerHide answer
Granting access by job role rather than the individual; scales well in enterprises.
- Identity and access management (IAM)
Show answerHide answer
The processes and tools that manage digital identities and their access rights.
- Configuration management
Show answerHide answer
Controlling and documenting system settings to a secure, known baseline.
- Change management
Show answerHide answer
A controlled process for evaluating, approving, and documenting changes to systems.
- Patch management
Show answerHide answer
Systematically applying updates to remediate known vulnerabilities.
- Encryption (program control)
Show answerHide answer
A technical control protecting confidentiality of data at rest and in transit.
- Data loss prevention (DLP)
Show answerHide answer
Controls that detect and block unauthorized movement of sensitive data.
- Security architecture
Show answerHide answer
The structured design of security capabilities within the enterprise's technology design.
- Enterprise architecture
Show answerHide answer
The overall structure of an enterprise's processes and technology that security must integrate with.
- Security baselines
Show answerHide answer
Standardized minimum security configurations applied across similar systems.
- Control framework
Show answerHide answer
A structured set of controls (e.g., NIST 800-53, ISO 27002) used to build the program.
- Penetration test (management view)
Show answerHide answer
An authorized simulated attack used to evaluate control effectiveness; results inform risk.
- Vulnerability scanning (program)
Show answerHide answer
Automated identification of known weaknesses to feed remediation and risk decisions.
- Logging and monitoring
Show answerHide answer
Recording and reviewing system activity to support detection and accountability.
- Data retention
Show answerHide answer
Policy defining how long data is kept before secure disposal, driven by legal and business needs.
- Secure disposal / sanitization
Show answerHide answer
Removing data from media (clear, purge, destroy) so it cannot be recovered.
- Privacy by design
Show answerHide answer
Building privacy protections into systems and processes from the start.
- Discretionary access control (DAC)
Show answerHide answer
Access decided by the data owner (e.g., file permissions, ACLs).
- Mandatory access control (MAC)
Show answerHide answer
Access enforced by the system from labels and clearances; rigid and high-security.
- Attribute-based access control (ABAC)
Show answerHide answer
Access decided by attributes and policy (user, resource, time, location) — most granular.
- Single sign-on (SSO)
Show answerHide answer
One authentication that grants access to multiple systems (e.g., via SAML or Kerberos).
- Multi-factor authentication (MFA)
Show answerHide answer
Requiring two or more factors from different categories: know, have, are.
- Provisioning and deprovisioning
Show answerHide answer
Granting access when staff join/change roles and promptly removing it when they leave.
- Privileged access management (PAM)
Show answerHide answer
Tightly controlling and monitoring high-privilege accounts.
- Data states
Show answerHide answer
At rest, in transit, and in use — each needs different protective controls.
- Endpoint protection
Show answerHide answer
Controls (EDR, antivirus, hardening) that secure user devices and servers.
- Network segmentation
Show answerHide answer
Dividing a network (VLANs, subnets) so a compromise can't spread freely.
- Zero trust
Show answerHide answer
A model that never implicitly trusts and verifies every access request continuously.
- Hardening
Show answerHide answer
Reducing a system's attack surface by removing unneeded services and applying secure settings.
- Security testing types
Show answerHide answer
Vulnerability scan, penetration test, code review, and audit — used to evaluate controls.
- Static vs. dynamic testing
Show answerHide answer
Static reviews source code; dynamic tests a running application.
- SOC 1 vs. SOC 2
Show answerHide answer
SOC 1 covers financial-reporting controls; SOC 2 covers security/availability controls.
- Audit (security)
Show answerHide answer
An independent evaluation of controls against a standard or policy.
- Continuous monitoring (program)
Show answerHide answer
Ongoing automated assessment of control effectiveness and security posture.
- Cloud shared responsibility
Show answerHide answer
Security duties split between the cloud provider and the customer by service model.
- Data privacy controls
Show answerHide answer
Controls protecting personal data and meeting privacy obligations (consent, minimization).
- Backup strategy (program)
Show answerHide answer
Defining what to back up, how often (RPO-driven), and where copies are stored.
- Control integration
Show answerHide answer
Embedding controls into business processes so security is part of how work is done.
- Security metrics dashboard
Show answerHide answer
A leadership view of KPIs/KGIs that communicates program performance.
Incident Management (70)
- Incident response lifecycle
Show answerHide answer
Prepare → Detect → Triage → Contain → Eradicate → Recover → Post-incident review.
- Business Impact Analysis (BIA)
Show answerHide answer
Identifies critical processes and the impact of disruption; produces MTD, RTO, and RPO.
- Recovery Time Objective (RTO)
Show answerHide answer
The target time to restore a system after a disruption; must fit within the MTD.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable data loss measured backward in time; drives backup frequency.
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The absolute outer limit a process can be down before unacceptable harm; MTD = RTO + WRT.
- Work Recovery Time (WRT)
Show answerHide answer
The time to verify data and resume normal operations after systems are restored.
- Business Continuity Plan (BCP)
Show answerHide answer
A plan to keep critical business functions operating during/after a disruption (business-focused).
- Disaster Recovery Plan (DRP)
Show answerHide answer
The IT-focused plan to restore technology systems and data; it supports the BCP.
- BCP vs. DRP
Show answerHide answer
BCP keeps the business running; DRP restores the IT the business depends on.
- Incident response plan (IRP)
Show answerHide answer
The documented procedures, roles, and communications for handling a security incident.
- Containment
Show answerHide answer
Limiting the spread/damage of an incident before eradication and recovery — stop the bleeding first.
- Eradication
Show answerHide answer
Removing the root cause of an incident — malware, compromised accounts, the exploited weakness.
- Recovery (incident)
Show answerHide answer
Restoring affected systems to normal operation and validating they're clean.
- Post-incident review
Show answerHide answer
Lessons learned and root-cause analysis after an incident that improve the program.
- Lessons learned
Show answerHide answer
The documented improvements identified after an incident to prevent recurrence.
- Root cause analysis (RCA)
Show answerHide answer
Identifying the underlying cause of an incident so it can be permanently fixed.
- Event vs. incident vs. breach
Show answerHide answer
Event = observable occurrence; incident = harms CIA; breach = confirmed data exposure.
- Security event
Show answerHide answer
Any observable occurrence in a system or network; most are benign.
- Security incident
Show answerHide answer
An adverse event that harms or threatens the confidentiality, integrity, or availability of information.
- Data breach
Show answerHide answer
A confirmed incident in which protected data was accessed or exposed, often triggering notification.
- CSIRT
Show answerHide answer
Computer Security Incident Response Team — the group that detects, responds to, and recovers from incidents.
- SOC
Show answerHide answer
Security Operations Center — the function that monitors, detects, and responds to security events.
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs for detection and analysis.
- Incident classification
Show answerHide answer
Categorizing an incident by type and severity to prioritize the response and escalation.
- Incident triage
Show answerHide answer
The initial assessment that decides which events are incidents and how severe they are.
- Escalation
Show answerHide answer
Routing an incident to the right level of authority based on its severity and impact.
- Chain of custody
Show answerHide answer
The documented, tamper-evident record of who handled evidence and when, preserving admissibility.
- Digital forensics
Show answerHide answer
The disciplined collection, analysis, and preservation of digital evidence.
- Evidence preservation
Show answerHide answer
Imaging, hashing, and securely storing evidence so it remains intact and admissible.
- Incident response communications
Show answerHide answer
Coordinated internal and external messaging during an incident, including legal/PR/regulators.
- Notification obligations
Show answerHide answer
Legal/regulatory duties to inform affected parties or regulators after a breach.
- Tabletop exercise
Show answerHide answer
A discussion-based test of the incident/continuity plan against a scenario.
- Simulation exercise
Show answerHide answer
A hands-on test that exercises the response team and tools against a realistic scenario.
- Hot site
Show answerHide answer
A fully equipped alternate site with near-real-time failover — fastest recovery, most expensive.
- Warm site
Show answerHide answer
An alternate site with hardware/connectivity but data restored on demand — moderate cost/speed.
- Cold site
Show answerHide answer
An alternate site with power/cooling only — cheapest, slowest to bring online.
- Full backup
Show answerHide answer
A backup of all selected data; fastest to restore from a single set.
- Incremental backup
Show answerHide answer
Backs up changes since the last backup of any type — fast backup, slow restore.
- Differential backup
Show answerHide answer
Backs up changes since the last full backup — slower backup, faster restore.
- MTBF
Show answerHide answer
Mean Time Between Failures — a reliability metric for how often a system fails.
- MTTR
Show answerHide answer
Mean Time To Repair — the average time to restore a failed component to service.
- Incident readiness
Show answerHide answer
The advance planning — IRP, BIA, BCP/DRP, training, testing — that prepares for incidents.
- Incident management training
Show answerHide answer
Preparing the response team and staff so they can execute the plan under pressure.
- Detection and analysis
Show answerHide answer
The NIST phase of identifying and confirming an incident from events and alerts.
- Crisis management
Show answerHide answer
Senior-leadership coordination of major incidents affecting the whole organization.
- Playbook (incident)
Show answerHide answer
A predefined set of response steps for a specific incident type.
- Indicators of compromise (IoC)
Show answerHide answer
Artifacts (e.g., malicious IPs, file hashes) that signal a possible intrusion.
- Containment strategy
Show answerHide answer
The plan for isolating affected systems while preserving evidence and operations.
- Incident severity levels
Show answerHide answer
Tiers (e.g., low/medium/high/critical) that determine response priority and escalation.
- Declaration of an incident
Show answerHide answer
The formal point at which an event is confirmed an incident, activating the IRP.
- First responder
Show answerHide answer
The initial responder who assesses, contains, and escalates an incident.
- Forensic readiness
Show answerHide answer
Preparing in advance to collect and preserve evidence so it's usable later.
- Containment: short vs. long term
Show answerHide answer
Quick isolation to stop spread, then a durable fix while operations continue.
- Parallel test (DR)
Show answerHide answer
Testing recovery systems alongside production without disrupting it.
- Full interruption test
Show answerHide answer
The most thorough (and risky) DR test that actually fails over to the recovery site.
- Checklist test
Show answerHide answer
The simplest DR test: reviewing the plan's contents for completeness.
- Recovery strategy
Show answerHide answer
The chosen approach (sites, backups, redundancy) to meet the RTO/RPO from the BIA.
- Alternate processing site
Show answerHide answer
A standby location (hot/warm/cold) used to resume operations after a disaster.
- Reciprocal agreement
Show answerHide answer
A mutual-aid arrangement to use another organization's facilities in a disaster.
- Incident metrics
Show answerHide answer
Measures like detection time, containment time, and MTTR used to improve response.
- Mean time to detect (MTTD)
Show answerHide answer
The average time from an incident's start to its detection.
- Mean time to contain (MTTC)
Show answerHide answer
The average time from detection to containment of an incident.
- Communication plan (incident)
Show answerHide answer
Predefined who-tells-whom-what during an incident, including spokespersons and regulators.
- Regulatory breach timelines
Show answerHide answer
Legally mandated windows to notify regulators/individuals after a breach (e.g., 72 hours under GDPR).
- Eradication vs. recovery
Show answerHide answer
Eradication removes the cause; recovery restores systems to normal, validated operation.
- Evidence handling
Show answerHide answer
Collecting, labeling, and storing evidence to preserve integrity and chain of custody.
- Order of volatility
Show answerHide answer
Collecting the most ephemeral evidence first (memory, then disk) during forensics.
- Tabletop vs. simulation vs. full
Show answerHide answer
A spectrum of plan tests from discussion-based to a real failover.
- Disaster recovery as a service (DRaaS)
Show answerHide answer
A cloud service providing recovery infrastructure to meet RTO/RPO.
- Crisis communication
Show answerHide answer
Coordinated external messaging to protect reputation and meet obligations during a major incident.
References
- 1.ISACA. “CISM Exam Content Outline.” isaca.org. ↑
- 2.ISACA. “CISM — Certified Information Security Manager.” isaca.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-30 Rev. 1: Guide for Conducting Risk Assessments.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
