🇺🇸 Certified Information Security Manager (CISM) · subject
Certified Information Security Manager (CISM) Information Security Incident Management Syllabus
Every chapter and topic of Information Security Incident Management examined in Certified Information Security Manager (CISM) — 4 chapters, 14 topics and 28 sub-topics, plus 61 flashcards written against it.
Information Security Incident Management syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security Incident Management in Certified Information Security Manager (CISM), not a summary of it.
-
Incident Management Planning
4 topics- Incident Management Concepts
- Events, alerts, and incidents defined
- Incident management vs. incident response
- Incident Response Plan Development
- Plan components and approval
- Roles, responsibilities, and escalation paths
- Incident Classification and Severity
- Categorization schemes and prioritization
- Severity and impact criteria
- Response Team Structure
- CSIRT roles and staffing models
- Internal and external coordination
- Incident Management Concepts
-
Detection, Triage, and Response
4 topics- Detection and Monitoring Capabilities
- SIEM, IDS/IPS, and log management
- Threat hunting and anomaly detection
- Triage and Investigation
- Initial assessment and prioritization
- Root cause and scope determination
- Containment, Eradication, and Recovery
- Short-term and long-term containment
- System restoration and validation
- Digital Forensics and Evidence Handling
- Chain of custody and evidence integrity
- Forensic readiness and legal considerations
- Detection and Monitoring Capabilities
-
Business Continuity and Disaster Recovery
3 topics- Business Impact Analysis
- Recovery time and recovery point objectives
- Critical process and dependency mapping
- Continuity and Recovery Strategies
- Site strategies and redundancy options
- Backup and restoration approaches
- Plan Maintenance and Integration
- Aligning BCP, DRP, and incident response
- Plan review and update cycles
- Business Impact Analysis
-
Post-Incident and Communication
3 topics- Incident Communication and Notification
- Regulatory and breach notification requirements
- Internal, customer, and media communication
- Post-Incident Review
- Lessons learned and after-action reports
- Corrective and preventive actions
- Testing and Exercises
- Tabletop, walkthrough, and simulation tests
- Metrics for response readiness
- Incident Communication and Notification
Information Security Incident Management flashcards for Certified Information Security Manager (CISM)
25 of 61 cards from the Information Security Incident Management deck — real questions with worked answers.
What is the primary objective of incident management in CISM?
To minimize the impact of incidents on the organization by detecting, responding to, and recovering from them effectively, ensuring continuity of business operations and limiting damage.
How does ISACA define a security incident?
An event (or series of events) that has been assessed and found to have caused, or has the potential to cause, harm to the organization's information assets or business operations, typically violating security policy.
What is the difference between an event and an incident?
An event is any observable occurrence in a system or network; an incident is an event (or set of events) that negatively affects, or threatens to affect, the confidentiality, integrity, or availability of information assets.
What are the typical phases of the incident response life cycle (NIST SP 800-61 model)?
1) Preparation, 2) Detection and Analysis, 3) Containment, Eradication, and Recovery, and 4) Post-Incident Activity (lessons learned).
What is the difference between incident response and incident management?
Incident management is the overarching governance program (policy, planning, resourcing, coordination) for handling incidents; incident response is the operational/tactical set of activities executed to detect, contain, and recover from a specific incident.
What is a Computer Security Incident Response Team (CSIRT/CIRT)?
A designated group responsible for receiving, reviewing, and responding to security incident reports and activity, coordinating technical and managerial response across the organization.
Why must incident management capability be aligned with the organization's business objectives?
So response priorities protect the most critical assets and processes, support continuity of essential functions, and ensure resources are allocated to incidents with the greatest business impact rather than treating all incidents equally.
What is the purpose of an Incident Response Plan (IRP)?
To provide a documented, structured, and repeatable set of procedures, roles, and resources for detecting, responding to, and recovering from security incidents in a consistent and effective manner.
What key elements should be included in an incident response plan?
Purpose/scope, definitions and classification criteria, roles and responsibilities, detection and reporting procedures, escalation paths, containment/eradication/recovery steps, communication/notification requirements, and post-incident review processes.
Who should approve the incident response plan and policy?
Senior management (and ideally the board), to ensure organizational authority, adequate resourcing, accountability, and alignment with business and governance objectives.
What is an incident response playbook (runbook)?
A predefined, step-by-step procedural guide for handling a specific type of incident (e.g., ransomware, phishing, DDoS), enabling consistent, fast, and repeatable response.
What is the purpose of incident classification?
To categorize incidents by type, source, and impact so the appropriate response priority, resources, escalation, and procedures can be applied consistently.
What two primary factors typically determine an incident's severity/priority?
The functional/business impact (extent of harm to operations and assets) and the urgency (how quickly it must be addressed), often combined with scope and information/data sensitivity affected.
What is the difference between incident category and incident severity?
Category describes the type or nature of the incident (e.g., malware, unauthorized access, DoS); severity describes the magnitude of its impact and the priority of response.
What is escalation in incident management?
The process of involving higher levels of authority, additional resources, or specialized teams when an incident exceeds defined severity thresholds or cannot be resolved at the current response level.
Why are predefined severity thresholds and triggers important?
They remove ambiguity and delay during a crisis by predetermining when to escalate, notify management, activate the CSIRT, or invoke continuity plans, ensuring timely and consistent decisions.
What are the typical core roles within an incident response team?
Incident response manager/coordinator, technical analysts/investigators, plus liaisons from legal, HR, communications/PR, IT operations, and management; supported by an executive sponsor.
What is the role of the incident response coordinator/manager?
To lead and coordinate the overall response effort, manage communication and escalation, make or facilitate key decisions, track activities, and ensure the plan is followed.
What are the three common CSIRT organizational/staffing models?
Centralized (single team for the whole organization), distributed/decentralized (multiple teams by location or business unit, coordinated centrally), and coordinating/outsourced (using external or hybrid providers).
Why should legal, HR, and public relations be part of incident response planning?
Legal advises on regulatory/breach obligations and evidence; HR handles insider/employee issues; PR/communications manages internal and external messaging to protect reputation and ensure consistent, accurate disclosure.
What is the value of retainer agreements with external incident response providers?
They guarantee rapid access to specialized forensic and response expertise and surge capacity during major incidents, with pre-negotiated terms reducing delay when an incident occurs.
What is the purpose of detection and monitoring capabilities in incident management?
To identify potential security incidents as early as possible through continuous observation of systems, networks, and logs, enabling timely response and reducing impact.
What does a SIEM (Security Information and Event Management) system do?
It aggregates, correlates, and analyzes log and event data from multiple sources in near real time to detect anomalies, generate alerts, and support investigation and reporting.
What is the difference between an IDS and an IPS?
An Intrusion Detection System (IDS) detects and alerts on suspicious activity but does not block it; an Intrusion Prevention System (IPS) detects and actively blocks or prevents the malicious traffic inline.
What is the difference between signature-based and anomaly-based (behavioral) detection?
Signature-based detection matches activity against known patterns of malicious behavior (effective for known threats); anomaly-based detection flags deviations from a baseline of normal behavior (can catch novel/zero-day threats but more false positives).
See more Information Security Incident Management flashcards →
Planning Information Security Incident Management for Certified Information Security Manager (CISM)
Information Security Incident Management is about 21% of the Certified Information Security Manager (CISM) syllabus by topic count — 14 of 68 topics, spread over 4 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.
The heaviest chapters are Incident Management Planning (4 topics), Detection, Triage, and Response (4 topics), Business Continuity and Disaster Recovery (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Information Security Incident Management (Certified Information Security Manager (CISM)) FAQ
What is in the Certified Information Security Manager (CISM) Information Security Incident Management syllabus?
Information Security Incident Management is split into 4 chapters — Incident Management Planning, Detection, Triage, and Response, Business Continuity and Disaster Recovery and Post-Incident and Communication, containing 14 topics and 28 sub-topics in total.
How many chapters are there in Information Security Incident Management for Certified Information Security Manager (CISM)?
4 chapters. Information Security Incident Management accounts for about 21% of the topics in the whole Certified Information Security Manager (CISM) syllabus (14 of 68).
How long should I spend on Information Security Incident Management for Certified Information Security Manager (CISM)?
Budget around 15 hours for a first pass through Information Security Incident Management — about 45 minutes per topic plus 12 minutes per sub-topic across its 14 topics. Add revision cycles on top.
Are there flashcards for Certified Information Security Manager (CISM) Information Security Incident Management?
Yes — a 61-card Information Security Incident Management deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.