Click Study Flashcards above to open the flashcard hub — 200 ISSMP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the six official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
ISSMP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
ISSMP Flashcard Study Modes
Flip mode lets you turn cards one at a time when a domain is still new. Type asks you to read a definition and produce the term, so a card like Data remanence has to come from memory, not recognition. Match times you as you pair terms with definitions, and Quiz builds multiple-choice questions from the same 200 cards to check retention.

Why Flashcards Work for the ISSMP
Leadership and Organizational Management is the biggest block at 41 cards, and it drills the governance and management vocabulary an ISSMP candidate is expected to speak fluently. You get the standard-of-conduct pairing of Due care and Due diligence, structural terms such as RACI matrix, and the governance references that sit behind program authority, including ISO/IEC 27014.
Risk Management follows with 40 cards covering the language of identifying, quantifying, and assigning risk. Foundational fronts like Risk and Vulnerability anchor the set, while the FAIR model card pushes you toward quantitative analysis and ISO 31000 gives you the process framework that management-level questions tend to assume.
Security Operations brings 33 cards on the tooling and incident phases you are expected to direct rather than perform. Platform terms such as SIEM and SOAR appear alongside response stages like Containment and Eradication, and MITRE ATT&CK covers the adversary behavior vocabulary that shows up in threat hunting discussions.
Systems Lifecycle Management carries 30 cards on building security into development and retirement. Threat modeling notation gets attention through STRIDE and DREAD, while disposal concepts like Data remanence and process controls such as Change management cover the ends of the lifecycle.
Contingency Management has 28 cards on resilience planning, where recovery site tiers like Hot site and Cold site meet metric pairs such as RTO vs. RPO and backup schemes including the 3-2-1 backup rule. Law, Ethics, and Security Compliance Management adds 28 more, mapping regulations and attestations: GDPR and HIPAA for privacy scope, PCI DSS and SOC 2 for contractual and audit obligations, plus concepts like Liability.
The ISSMP is dense with management terminology — governance, risk formulas, the incident response lifecycle, recovery objectives, and compliance regimes.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
ISSMP Flashcards by Domain
The cards are organized by the six official ISC2 domains. Cover them all, but start with the two largest — Leadership & Organizational Management and Risk Management:[1]
| Domain | Exam weight |
|---|---|
| Leadership & Organizational Management | ~21% |
| Risk Management | ~20% |
| Security Operations | ~18% |
| Systems Lifecycle Management | ~15% |
| Law, Ethics & Security Compliance Management | ~14% |
| Contingency Management | ~12% |
How to Get the Most Out of These Flashcards
- Start with Leadership and Organizational Management. At 41 cards it is the largest domain in the deck, and its governance vocabulary reappears in risk, compliance, and lifecycle questions later.
- Type-drill the pairs that blur under pressure. Due care and Due diligence are the classic trap, and RTO vs. RPO is the contingency equivalent, so produce both definitions from memory rather than recognizing them.
- Use Match for acronym clusters. Terms like SIEM, SOAR, and the regulation shorthand in the compliance domain reward fast recognition, and the timer exposes which abbreviations you only half know.
- Switch to the practice test once Quiz holds steady. When multiple-choice results stay consistent across all six domains, move to scenario questions and use the study guide to fill gaps the cards surfaced.
- Keep a repeatable cadence across 200 cards. Work one domain per sitting in Flip, close with Quiz on that domain, then run Match across two completed domains to keep earlier material warm.
ISSMP Flashcards FAQ
Two hundred free CISSP-ISSMP flashcards, organized across all six ISC2 domains — Leadership & Organizational Management, Systems Lifecycle Management, Risk Management, Security Operations, Contingency Management, and Law, Ethics & Security Compliance Management. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the ISSMP's heavy management terminology across governance, risk, operations, and continuity.
All six ISC2 domains: Leadership & Organizational Management (governance, policy, personnel), Systems Lifecycle Management (SDLC security, certification/accreditation), Risk Management (qualitative/quantitative analysis, treatment), Security Operations (incident response, forensics), Contingency Management (BCP/DRP, RTO/RPO), and Law, Ethics & Security Compliance Management.
Study by weight: lead with Leadership & Organizational Management (~21%) and Risk Management (~20%), the two largest domains. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 CISSP-ISSMP exam outline, covering all six scored domains in their official proportions.
ISSMP flashcard bank
All 200 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Leadership and Organizational Management (41)
- CISSP-ISSMP
Show answerHide answer
Information Systems Security Management Professional — an ISC2 advanced concentration for CISSPs who build, lead, and govern an enterprise security program; it tests management, not hands-on technical depth.
- Security governance
Show answerHide answer
The system of leadership, structures, and processes by which senior management directs and oversees the security program so it supports — and is accountable to — business objectives.
- Tone at the top
Show answerHide answer
The visible commitment of executives and the board to security; it sets the culture and is the single biggest driver of whether a security program succeeds.
- Strategic alignment
Show answerHide answer
Ensuring the security program's goals, investments, and metrics directly support the organization's mission and business strategy rather than operating as a siloed IT function.
- Security strategic plan
Show answerHide answer
A long-term (3–5 year) plan that defines the security program's vision, goals, and roadmap in alignment with business strategy; tactical and operational plans flow from it.
- Policy vs. standard vs. procedure vs. guideline
Show answerHide answer
Policy = high-level mandatory intent; standard = mandatory specific requirement; procedure = mandatory step-by-step; guideline = recommended, optional best practice.
- Security policy framework
Show answerHide answer
The hierarchy of governance documents (policies → standards → baselines → procedures → guidelines) that translates management intent into enforceable, repeatable controls.
- Security program charter
Show answerHide answer
The authorizing document, signed by senior management, that establishes the security program's mission, authority, scope, and reporting lines.
- RACI matrix
Show answerHide answer
A responsibility-assignment chart marking who is Responsible, Accountable, Consulted, and Informed for each task — clarifying security roles and preventing gaps or overlap.
- Accountable vs. responsible
Show answerHide answer
Accountable = the single owner answerable for the outcome (cannot be delegated); responsible = those who do the work. Management is accountable for security; staff are responsible.
- Security steering committee
Show answerHide answer
A cross-functional group of business and IT leaders that sets security priorities, approves policy, and aligns the program with enterprise objectives.
- Security awareness vs. training vs. education
Show answerHide answer
Awareness changes behavior (the what); training builds a job skill (the how); education builds understanding and reasoning (the why) — increasing depth in that order.
- Security awareness program
Show answerHide answer
An ongoing effort to keep every employee mindful of threats and their security responsibilities; the human layer is the most-exploited and most-trainable control.
- Security metrics (KPIs/KRIs)
Show answerHide answer
Key Performance Indicators measure how well the program runs; Key Risk Indicators give early warning of rising risk. Good metrics are tied to business goals and drive decisions.
- Security balanced scorecard
Show answerHide answer
A management tool that reports security performance across financial, customer, internal-process, and learning-and-growth perspectives to communicate value to executives.
- Return on Security Investment (ROSI)
Show answerHide answer
A metric estimating the financial benefit of a control relative to its cost — typically (reduction in ALE − cost of control) ÷ cost of control.
- Total Cost of Ownership (TCO)
Show answerHide answer
The full lifecycle cost of a security control or system — acquisition plus operation, maintenance, training, and disposal — used to compare investment options.
- Capital expenditure (CapEx) vs. operating expenditure (OpEx)
Show answerHide answer
CapEx = up-front purchases of long-lived assets (appliances); OpEx = recurring run costs (subscriptions, staff). The mix shapes security budgeting and cloud decisions.
- Security budget justification
Show answerHide answer
Translating security needs into business language — risk reduction, compliance, and ROSI — so executives fund the program; a core ISSMP leadership skill.
- Security culture
Show answerHide answer
The shared attitudes and behaviors that make security a normal part of how people work; built through leadership, awareness, accountability, and consistent reinforcement.
- Job rotation
Show answerHide answer
Periodically moving staff between roles to detect fraud, reduce dependence on any one person, and cross-train — a managerial/administrative control.
- Mandatory vacation
Show answerHide answer
Requiring employees to take leave so that someone else performs their duties, which can surface concealed fraud or errors; an administrative detective control.
- Separation of duties (SoD)
Show answerHide answer
Dividing a sensitive task so no single person can complete it alone, reducing fraud and error; collusion would be required to abuse it.
- Least privilege
Show answerHide answer
Granting each user, process, and role only the minimum access needed to perform its function — limiting the damage from compromise or misuse.
- Need to know
Show answerHide answer
Restricting access to information to those whose duties require it, even among users with the same clearance level; narrower than least privilege.
- Onboarding (security)
Show answerHide answer
Provisioning access, conveying policy, and completing background and awareness steps when a person joins, so access is granted correctly from day one.
- Offboarding (security)
Show answerHide answer
Promptly revoking access, recovering assets, and disabling accounts when a person leaves — a top cause of insider risk when done late or incompletely.
- Background investigation
Show answerHide answer
Pre-employment screening (criminal, credit, references) proportional to the role's sensitivity; a preventive personnel control against insider risk.
- Insider threat program
Show answerHide answer
A coordinated effort (HR, legal, security) to deter, detect, and respond to malicious or negligent insiders using monitoring, analytics, and reporting channels.
- Communication plan (security)
Show answerHide answer
A defined approach for who reports security information to whom, how often, and through what channel — ensuring management visibility and timely escalation.
- Stakeholder management
Show answerHide answer
Identifying parties affected by security decisions (executives, owners, users, regulators) and managing their expectations and engagement throughout the program.
- Change leadership
Show answerHide answer
Guiding people through the human side of security change — communicating the why, addressing resistance, and reinforcing new behaviors so controls stick.
- Security maturity model
Show answerHide answer
A staged framework (e.g., CMMI-style levels) that rates how repeatable, measured, and optimized a security program is, guiding improvement priorities.
- ISO/IEC 27014
Show answerHide answer
The ISO standard on governance of information security, defining how the governing body should direct and evaluate the security program.
- Risk appetite
Show answerHide answer
The broad amount and type of risk an organization is willing to pursue or retain to meet its objectives; set by the board and senior management.
- Performance management (security staff)
Show answerHide answer
Setting objectives, measuring results, and developing security personnel so the team's capabilities match the program's goals.
- Build vs. buy decision
Show answerHide answer
A management choice between developing a security capability in-house or acquiring it; weighed on cost, expertise, time-to-value, and control.
- Security program scope
Show answerHide answer
The defined boundary of what the program protects (systems, data, locations, lines of business); a clear scope prevents gaps and over-reach.
- Due diligence
Show answerHide answer
Doing the research, planning, and ongoing investigation needed to understand and protect the organization — the homework before acting.
- Due care
Show answerHide answer
Acting on due diligence by implementing and maintaining reasonable controls — what a prudent person would do; together they form the prudent-person rule.
- Security organizational structure
Show answerHide answer
How the security function is positioned and staffed (centralized, decentralized, or hybrid; CISO reporting line) to balance authority, independence, and business reach.
Systems Lifecycle Management (30)
- Systems Development Life Cycle (SDLC)
Show answerHide answer
The structured phases through which a system is conceived, built, operated, and retired; security must be integrated into every phase, not bolted on at the end.
- Security in the SDLC
Show answerHide answer
Embedding requirements, design review, secure coding, testing, and accreditation activities throughout the lifecycle so flaws are caught when they are cheapest to fix.
- Requirements phase (security)
Show answerHide answer
Defining security and privacy requirements early — classification, regulatory needs, and control objectives — so they shape design rather than being retrofitted.
- Secure design principles
Show answerHide answer
Foundational rules (defense in depth, least privilege, fail securely, economy of mechanism, complete mediation) applied during architecture to reduce attack surface.
- Threat modeling
Show answerHide answer
Systematically identifying and prioritizing threats to a system during design (e.g., with STRIDE) so the right mitigations are built in.
- STRIDE
Show answerHide answer
A threat-modeling taxonomy: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege.
- DREAD
Show answerHide answer
A risk-rating model for threats: Damage, Reproducibility, Exploitability, Affected users, Discoverability — used to prioritize what to fix first.
- Secure coding standards
Show answerHide answer
Mandated coding practices (input validation, output encoding, parameterized queries) that prevent classes of vulnerabilities such as injection and overflow.
- Static application security testing (SAST)
Show answerHide answer
Analyzing source code or binaries without executing them to find vulnerabilities early in development (white-box testing).
- Dynamic application security testing (DAST)
Show answerHide answer
Testing a running application from the outside to find vulnerabilities at runtime (black-box testing); complements SAST.
- Security testing gate
Show answerHide answer
A checkpoint in the SDLC where a build must pass defined security tests before it advances — enforcing that security is verified, not assumed.
- Certification (system)
Show answerHide answer
The technical evaluation of a system's controls against requirements to confirm they are implemented and effective; precedes accreditation.
- Accreditation (system)
Show answerHide answer
Management's formal decision (the authorizing official's) to accept the residual risk and authorize a system to operate.
- Authorization to Operate (ATO)
Show answerHide answer
The formal approval, signed by the authorizing official, that a system may go live with its risk accepted — the outcome of accreditation.
- NIST Risk Management Framework (RMF)
Show answerHide answer
A seven-step process (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for managing system security risk across the lifecycle (NIST SP 800-37).
- Continuous monitoring
Show answerHide answer
Ongoing assessment of controls, configurations, and risk after authorization so security keeps pace with change rather than being a point-in-time check.
- Configuration management
Show answerHide answer
Identifying, controlling, and recording the state of system components so changes are deliberate and the secure baseline is preserved.
- Security baseline
Show answerHide answer
A documented minimum set of security settings for a system or component; deviations must be justified and approved.
- Change management
Show answerHide answer
A controlled process to request, assess, approve, implement, and document changes so they do not introduce unmanaged risk.
- Change Advisory Board (CAB)
Show answerHide answer
The group that reviews and approves significant changes, weighing risk, impact, and rollback before authorizing implementation.
- Patch management
Show answerHide answer
The process of identifying, testing, and deploying software updates to remediate vulnerabilities within risk-based timelines.
- Vulnerability management
Show answerHide answer
The ongoing cycle of discovering, prioritizing, remediating, and verifying vulnerabilities across the environment — distinct from one-off scanning.
- Secure decommissioning
Show answerHide answer
The end-of-life phase that revokes access, sanitizes media, and retires assets so retired systems leave no exploitable data or trust behind.
- Data remanence
Show answerHide answer
Residual data that persists on media after deletion or formatting and may be recoverable; defeated by proper sanitization.
- Media sanitization
Show answerHide answer
Removing data so it cannot be recovered, via clearing (overwrite for reuse), purging (degauss/strong overwrite to release), or destruction (NIST SP 800-88).
- Supply chain risk management (SCRM)
Show answerHide answer
Managing security risk introduced by vendors, components, and software dependencies across acquisition, integration, and maintenance.
- Third-party / vendor risk assessment
Show answerHide answer
Evaluating a supplier's security posture before and during engagement (questionnaires, audits, SOC 2 reports) to manage outsourced risk.
- Software Bill of Materials (SBOM)
Show answerHide answer
A formal inventory of the components and dependencies in a software product, enabling rapid response when a component vulnerability is disclosed.
- Secure acquisition
Show answerHide answer
Building security requirements, evaluation criteria, and contractual obligations into procurement so purchased products and services meet the organization's standards.
- Service Level Agreement (SLA)
Show answerHide answer
A contract clause defining measurable service commitments (availability, response times); for security, it can mandate patch windows and incident notification.
Risk Management (40)
- Risk
Show answerHide answer
The likelihood that a threat exploits a vulnerability, combined with the resulting impact on an asset; the core unit security management measures and treats.
- Threat
Show answerHide answer
Any potential event or actor that could cause harm to an asset by exploiting a vulnerability.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Asset (security)
Show answerHide answer
Anything of value to the organization — data, systems, people, reputation — whose protection drives the risk program.
- Risk management lifecycle
Show answerHide answer
A continuous loop: identify assets and threats, assess risk, choose a treatment, implement controls, and monitor — risk is reduced but never eliminated.
- Risk assessment
Show answerHide answer
The process of identifying risks and estimating their likelihood and impact, producing a prioritized view to guide treatment (NIST SP 800-30).
- Qualitative risk analysis
Show answerHide answer
A subjective approach ranking risks high/medium/low using scales and expert judgment; fast and good for prioritization but not expressed in dollars.
- Quantitative risk analysis
Show answerHide answer
An objective, dollar-based approach using formulas (SLE, ARO, ALE) to express risk financially and cost-justify controls.
- Exposure Factor (EF)
Show answerHide answer
The percentage of an asset's value lost if a specific risk event occurs; expressed as a decimal in the SLE formula.
- Single Loss Expectancy (SLE)
Show answerHide answer
The expected monetary loss from one occurrence of a risk: .
- Annualized Rate of Occurrence (ARO)
Show answerHide answer
The expected number of times a specific risk event will occur in one year; an event every 25 years is an ARO of 0.04.
- Annualized Loss Expectancy (ALE)
Show answerHide answer
The expected yearly cost of a risk: . It is the basis for cost-justifying a control.
- Cost-benefit of a control
Show answerHide answer
A control is justified only when its annual cost is less than the reduction in ALE it provides; spending more than the expected loss is not prudent.
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls that lower likelihood or impact.
- Risk transference
Show answerHide answer
Shifting the financial impact of a risk to a third party, such as through insurance or outsourcing.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk and its potential impact; ignoring a risk is not acceptance.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; senior management must formally accept it.
- Inherent risk
Show answerHide answer
The level of risk that exists before any controls are applied — the starting point for choosing treatments.
- Risk register
Show answerHide answer
A living record of identified risks with their owner, likelihood, impact, treatment, and status — the central artifact of risk management.
- Risk owner
Show answerHide answer
The individual accountable for managing a specific risk and its treatment decisions — typically a business leader, not the security team alone.
- Key Risk Indicator (KRI)
Show answerHide answer
A metric that provides early warning that risk exposure is rising toward an unacceptable level, prompting action before an incident occurs.
- Risk tolerance
Show answerHide answer
The acceptable variation around risk appetite for a specific objective — the practical threshold at which a risk must be treated.
- Risk threshold
Show answerHide answer
The defined point at which a risk's level triggers escalation or a required treatment decision.
- Control types (by function)
Show answerHide answer
Preventive (stop), detective (find), corrective (fix), deterrent (discourage), recovery (restore), and compensating (alternative) controls.
- Control categories
Show answerHide answer
Administrative (policies, training), technical/logical (encryption, access control), and physical (locks, guards) — defense in depth combines all three.
- Compensating control
Show answerHide answer
An alternative control deployed when a required control is impractical, providing equivalent protection and a documented justification.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so that if one fails, others still protect the asset.
- NIST SP 800-30
Show answerHide answer
The NIST guide for conducting risk assessments, defining the process of identifying threats, vulnerabilities, likelihood, and impact.
- NIST SP 800-37
Show answerHide answer
The NIST Risk Management Framework, the seven-step process for authorizing and continuously monitoring system risk.
- NIST SP 800-39
Show answerHide answer
The NIST guide to managing information security risk at the organization, mission, and information-system tiers.
- ISO/IEC 27005
Show answerHide answer
The ISO standard providing guidelines for information security risk management within an ISMS.
- ISO 31000
Show answerHide answer
The ISO standard on enterprise risk management principles and guidelines, applicable beyond information security.
- Enterprise Risk Management (ERM)
Show answerHide answer
An organization-wide approach that treats security risk as one component of total business risk, integrated with strategy and governance.
- Risk heat map
Show answerHide answer
A visual grid plotting risks by likelihood and impact to communicate priorities to executives at a glance.
- FAIR model
Show answerHide answer
Factor Analysis of Information Risk — a quantitative framework that decomposes risk into loss frequency and loss magnitude for financial analysis.
- Risk-based decision making
Show answerHide answer
Prioritizing security effort and spending where they reduce the most risk per dollar, rather than treating all assets equally.
- Threat intelligence
Show answerHide answer
Evidence-based knowledge about adversaries, their tactics, and indicators, used to anticipate and prioritize defenses and inform risk decisions.
- Quantitative vs. qualitative — when to use
Show answerHide answer
Use qualitative for fast, broad prioritization and when data is scarce; use quantitative when financial justification and precise comparison are needed.
- Risk treatment plan
Show answerHide answer
A documented plan recording, for each significant risk, the chosen treatment, owner, controls, timeline, and acceptance — the bridge from assessment to action.
Security Operations (33)
- Security operations (SecOps)
Show answerHide answer
The day-to-day running of security: monitoring, detection, response, vulnerability handling, and control maintenance that keep the program effective over time.
- Security Operations Center (SOC)
Show answerHide answer
The team and facility that continuously monitors, detects, and responds to security events across the enterprise.
- SIEM
Show answerHide answer
Security Information and Event Management — a system that aggregates and correlates logs across sources for detection, alerting, and investigation.
- SOAR
Show answerHide answer
Security Orchestration, Automation, and Response — tooling that automates and coordinates incident workflows to speed and standardize response.
- Continuous monitoring (operations)
Show answerHide answer
Ongoing collection and analysis of security data so threats and control failures are detected as they happen, not at the next audit.
- Logging and log management
Show answerHide answer
Capturing, protecting, and retaining event records so activity can be detected, investigated, and proven; logs must be tamper-resistant and time-synced.
- Incident
Show answerHide answer
An event that actually or potentially harms confidentiality, integrity, or availability and warrants a response; distinct from a routine event.
- Event vs. incident
Show answerHide answer
An event is any observable occurrence; an incident is an event with adverse security consequences that triggers the response process.
- Incident response lifecycle (NIST)
Show answerHide answer
Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity (NIST SP 800-61).
- Preparation (IR)
Show answerHide answer
Building the capability before an incident — plans, tools, training, and communications — so response is fast and coordinated when it counts.
- Detection and analysis (IR)
Show answerHide answer
Identifying that an incident has occurred and determining its scope, type, and severity so response can be prioritized correctly.
- Containment
Show answerHide answer
Limiting the spread and damage of an incident (short-term and long-term) before eradication — stop the bleeding first.
- Eradication
Show answerHide answer
Removing the cause of the incident — malware, compromised accounts, and the exploited weakness — from the environment.
- Recovery (IR)
Show answerHide answer
Restoring affected systems to normal operation and verifying they are clean and monitored before returning them to production.
- Post-incident activity (lessons learned)
Show answerHide answer
Reviewing the incident and the response to improve plans, controls, and training; the step teams most often skip.
- Computer Security Incident Response Team (CSIRT)
Show answerHide answer
The designated, trained team responsible for handling security incidents end to end and coordinating across the organization.
- Incident severity classification
Show answerHide answer
Rating incidents by impact and urgency so response effort, escalation, and notification match the seriousness.
- Escalation procedures
Show answerHide answer
Defined criteria and paths for raising an incident to higher authority or specialized teams when thresholds are met.
- Chain of custody
Show answerHide answer
Documentation showing who handled evidence, when, and how — preserving its integrity and admissibility for legal use.
- Digital forensics
Show answerHide answer
The disciplined collection, preservation, examination, and analysis of digital evidence in a defensible manner.
- Order of volatility
Show answerHide answer
Collecting evidence from most-volatile to least (CPU/registers and cache → RAM → network state → disk → archives) to avoid losing transient data.
- Evidence preservation
Show answerHide answer
Protecting original evidence (write-blocking, hashing, imaging) so analysis is done on copies and integrity can be proven.
- Breach notification
Show answerHide answer
The legal and contractual obligation to inform affected parties and regulators within required timeframes after a data breach.
- Threat hunting
Show answerHide answer
Proactively searching the environment for adversary activity that evaded automated detection, guided by hypotheses and intelligence.
- Indicators of Compromise (IoC)
Show answerHide answer
Forensic artifacts (hashes, IPs, domains, behaviors) that signal a system may be breached and feed detection and hunting.
- MITRE ATT&CK
Show answerHide answer
A knowledge base of real-world adversary tactics and techniques used to map detections, assess coverage, and guide response.
- Cyber Kill Chain
Show answerHide answer
Lockheed Martin's model of attack stages (recon → weaponization → delivery → exploitation → installation → C2 → actions) used to disrupt attacks early.
- Vulnerability scan vs. penetration test
Show answerHide answer
A scan finds known weaknesses automatically without exploiting them; a pen test authorizedly exploits weaknesses to prove real impact.
- Penetration testing oversight
Show answerHide answer
Managing scope, rules of engagement, authorization, and reporting for tests so they are safe, legal, and produce actionable results.
- Security audit
Show answerHide answer
An independent, systematic evaluation of controls against a standard or policy, producing findings and recommendations.
- Continuous improvement (operations)
Show answerHide answer
Using metrics, audits, and lessons learned to refine operations over time so detection and response capability keeps maturing.
- Security monitoring metrics
Show answerHide answer
Operational measures such as mean time to detect (MTTD) and mean time to respond (MTTR) that gauge and drive SOC performance.
- Managed Security Service Provider (MSSP)
Show answerHide answer
A third party that delivers security operations (monitoring, detection, response) under contract; managed via SLAs and oversight.
Contingency Management (28)
- Contingency management
Show answerHide answer
The discipline of preparing for, responding to, and recovering from disruptions through business continuity and disaster recovery planning.
- Business Continuity Plan (BCP)
Show answerHide answer
A plan to keep critical business functions operating during and after a disruption; broader than DR, which focuses on IT.
- Disaster Recovery Plan (DRP)
Show answerHide answer
The procedures to restore IT systems, data, and infrastructure after a disruptive event; a subset of the overall BCP.
- BCP vs. DRP
Show answerHide answer
BCP keeps the whole business running (people, processes, facilities); DRP restores the IT systems that support it. DRP serves the BCP.
- Business Impact Analysis (BIA)
Show answerHide answer
The analysis that identifies critical functions and sets recovery objectives (MTD, RTO, RPO); it is the heart of continuity planning.
- Critical business function
Show answerHide answer
A process whose loss would cause unacceptable harm; identifying these in the BIA prioritizes recovery effort and resources.
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The longest a function can be unavailable before the organization suffers unacceptable harm; it bounds the RTO.
- Recovery Time Objective (RTO)
Show answerHide answer
The target time to restore a system or function after a disruption; it must be shorter than the MTD.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable amount of data loss measured backward in time; it drives how often you back up.
- RTO vs. RPO
Show answerHide answer
RTO is about TIME to recover; RPO is about DATA you can afford to lose. A 4-hour RTO means restore within 4 hours; a 1-hour RPO means back up at least hourly.
- Work Recovery Time (WRT)
Show answerHide answer
The time needed after systems are restored to validate data and resume normal business operations; RTO + WRT must fit within the MTD.
- Mean Time Between Failures (MTBF)
Show answerHide answer
The average operational time between failures of a component; used in availability planning to predict reliability.
- Mean Time To Repair (MTTR)
Show answerHide answer
The average time to restore a failed component to service; lower MTTR supports tighter RTOs.
- Hot site
Show answerHide answer
A fully equipped, staffed alternate site offering near-real-time failover — the fastest recovery and the most expensive option.
- Warm site
Show answerHide answer
An alternate site with hardware and connectivity in place but data restored on demand — moderate cost and recovery speed.
- Cold site
Show answerHide answer
An alternate site with power, cooling, and space only — the cheapest option but the slowest to bring online.
- Mirror / redundant site
Show answerHide answer
A fully redundant copy of the production environment with real-time data replication for immediate failover; the costliest, fastest option.
- Reciprocal agreement
Show answerHide answer
A mutual-aid arrangement where two organizations agree to host each other's operations after a disaster; low cost but hard to enforce and capacity-limited.
- Full backup
Show answerHide answer
A backup of all selected data; fastest to restore from (one set) but slowest and largest to create.
- Incremental backup
Show answerHide answer
Backs up only data changed since the last backup of any type; fast to create but slow to restore (full plus every increment).
- Differential backup
Show answerHide answer
Backs up data changed since the last full backup; slower to create than incremental but faster to restore (full plus one differential).
- 3-2-1 backup rule
Show answerHide answer
Keep three copies of data, on two different media types, with one copy offsite — a resilient backup strategy against most failure modes.
- Backup vs. archive
Show answerHide answer
A backup is a recoverable copy for restoration; an archive is long-term retention of data no longer in active use, often for compliance.
- Plan testing — checklist
Show answerHide answer
The least disruptive BCP test: reviewers verify the plan's contents and contacts on paper without activating anything.
- Plan testing — tabletop / structured walk-through
Show answerHide answer
Team members talk through their roles in a simulated scenario to find gaps without touching production systems.
- Plan testing — simulation
Show answerHide answer
A more realistic test that exercises response steps in a controlled scenario without affecting live operations.
- Plan testing — parallel
Show answerHide answer
Recovery systems are brought up and run alongside production to confirm they work, without taking production offline.
- Plan testing — full interruption
Show answerHide answer
Production is actually failed over to recovery systems — the most thorough and most risky test; requires management approval.
Law, Ethics, and Security Compliance Management (28)
- ISC2 Code of Ethics
Show answerHide answer
Four canons every member must follow, applied in order: protect society and the infrastructure; act honorably; provide diligent service to principals; advance and protect the profession.
- Canon precedence (ISC2 ethics)
Show answerHide answer
When canons conflict, the earlier canon outranks the later — protecting society and the public good comes before all others.
- Regulatory compliance
Show answerHide answer
Conforming to laws and regulations (e.g., HIPAA, GDPR, SOX, PCI DSS) that apply to the organization's data and industry; non-compliance carries legal and financial penalties.
- GDPR
Show answerHide answer
The EU General Data Protection Regulation governing personal-data processing of EU residents; defines controller/processor duties, breach notice, and large fines.
- HIPAA
Show answerHide answer
The U.S. law protecting the privacy and security of protected health information (PHI), with administrative, physical, and technical safeguard requirements.
- PCI DSS
Show answerHide answer
The Payment Card Industry Data Security Standard — a contractual framework of controls for organizations handling cardholder data.
- Sarbanes-Oxley (SOX)
Show answerHide answer
U.S. law requiring internal controls over financial reporting for public companies, with IT general controls implications for security.
- Nondisclosure agreement (NDA)
Show answerHide answer
A contract binding an employee or partner to protect confidential information; a legal/administrative control supporting confidentiality.
- Acceptable Use Policy (AUP)
Show answerHide answer
A policy defining how employees may use organizational systems and data; sets expectations and the basis for disciplinary action.
- Conflict of interest
Show answerHide answer
A situation where a person's private interest could improperly influence their duties; managed through disclosure, separation of duties, and ethics policy.
- Compliance program
Show answerHide answer
An organized framework of policies, controls, monitoring, and reporting that demonstrates the organization meets its legal, regulatory, and contractual security obligations.
- Due diligence vs. due care (legal)
Show answerHide answer
Due diligence is investigating and planning to meet obligations; due care is the prudent action taken. Courts use both to judge whether an organization was negligent.
- Negligence (security)
Show answerHide answer
Failing to exercise the due care a reasonable organization would, which can create legal liability after a breach.
- Liability
Show answerHide answer
Legal responsibility for harm; security management limits liability by demonstrating due care and meeting the standard of a prudent person.
- Standard of care
Show answerHide answer
The level of caution a reasonable organization in the same industry would exercise; falling below it can establish negligence.
- Intellectual property — types
Show answerHide answer
Protections for creations: copyright (works), trademark (brand marks), patent (inventions), and trade secret (confidential business value).
- Trade secret
Show answerHide answer
Confidential business information that derives value from secrecy; protected by reasonable safeguards (NDAs, access control) rather than registration.
- Privacy vs. security
Show answerHide answer
Security protects data from unauthorized access; privacy governs the appropriate collection, use, and sharing of personal data. They overlap but are not the same.
- Personally Identifiable Information (PII)
Show answerHide answer
Data that can identify an individual; its handling is governed by privacy laws and requires protection commensurate with sensitivity.
- Data controller vs. data processor
Show answerHide answer
Under privacy law, the controller decides why and how personal data is processed; the processor acts only on the controller's documented instructions.
- CCPA
Show answerHide answer
The California Consumer Privacy Act granting California residents rights over their personal data, including access, deletion, and opt-out of sale.
- GLBA
Show answerHide answer
The Gramm-Leach-Bliley Act requiring U.S. financial institutions to protect customer financial information and explain their data-sharing practices.
- FISMA
Show answerHide answer
The U.S. Federal Information Security Modernization Act requiring federal agencies to implement risk-based security programs, often using the NIST RMF.
- SOC 2
Show answerHide answer
An AICPA audit report on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy (Trust Services Criteria).
- ISO/IEC 27001
Show answerHide answer
The international standard specifying requirements for an Information Security Management System (ISMS) and the basis for ISMS certification.
- Regulatory vs. contractual compliance
Show answerHide answer
Regulatory compliance is mandated by law (HIPAA, GDPR); contractual compliance is required by agreements (PCI DSS, SLAs). Both must be managed.
- Legal hold
Show answerHide answer
A directive to preserve all potentially relevant data when litigation is anticipated, suspending normal deletion; violating it risks sanctions.
- eDiscovery
Show answerHide answer
The legal process of identifying, preserving, and producing electronically stored information for litigation or investigation.
References
- 1.ISC2. “CISSP-ISSMP Certification Exam Outline.” isc2.org. ↑
- 2.ISC2. “CISSP-ISSMP — Information Systems Security Management Professional.” isc2.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-30 Rev. 1: Guide for Conducting Risk Assessments.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
