🇺🇸 Certified Information Security Manager (CISM) · subject
Certified Information Security Manager (CISM) Information Security Risk Assessment Syllabus
Every chapter and topic of Information Security Risk Assessment examined in Certified Information Security Manager (CISM) — 3 chapters, 10 topics and 20 sub-topics, plus 51 flashcards written against it.
Information Security Risk Assessment syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security Risk Assessment in Certified Information Security Manager (CISM), not a summary of it.
-
Risk Concepts and the Risk Landscape
4 topics- Core Risk Terminology
- Threats, vulnerabilities, assets, and impact
- Inherent, residual, and aggregate risk
- Risk Appetite and Tolerance
- Establishing acceptable risk levels
- Aligning appetite with business objectives
- Emerging Threats and Vulnerabilities
- Threat intelligence and threat actor profiling
- Supply chain and third-party risk
- Risk Management Frameworks
- NIST SP 800-39 and ISO/IEC 27005
- FAIR quantitative risk modeling
- Core Risk Terminology
-
Asset Identification and Valuation
3 topics- Asset Inventory and Classification
- Asset ownership and stewardship
- Information classification schemes
- Business Impact Considerations
- Determining asset criticality
- Valuation methods for tangible and intangible assets
- Data Lifecycle and Protection Needs
- Data states and handling requirements
- Retention and disposal considerations
- Asset Inventory and Classification
-
Risk Identification and Analysis
3 topics- Risk Identification Methods
- Threat modeling and scenario analysis
- Vulnerability assessment and penetration testing inputs
- Risk Analysis Techniques
- Qualitative vs. quantitative analysis
- Single loss and annualized loss expectancy
- Risk Evaluation and Ranking
- Risk scoring and heat maps
- Prioritization against risk criteria
- Risk Identification Methods
Information Security Risk Assessment flashcards for Certified Information Security Manager (CISM)
21 of 51 cards from the Information Security Risk Assessment deck — real questions with worked answers.
What is the definition of a 'threat' in information security risk terminology?
A threat is any potential cause of an unwanted incident that may result in harm to a system or organization, e.g., a hacker, malware, natural disaster, or insider.
What is a 'vulnerability' in risk terminology?
A vulnerability is a weakness or flaw in an asset or control that can be exploited by a threat to cause harm (e.g., unpatched software, weak passwords).
Define 'risk' as used in information security.
Risk is the potential that a given threat will exploit a vulnerability of an asset, resulting in loss or damage. It is a function of likelihood and impact.
What is an 'asset' in risk management?
An asset is anything of value to the organization—data, hardware, software, people, reputation, or processes—that needs protection.
What is 'exposure' in risk terminology?
Exposure is an instance of being susceptible to loss from a threat; the state of being unprotected against a particular vulnerability.
Define 'inherent risk' versus 'residual risk'.
Inherent risk is the level of risk before any controls are applied; residual risk is the risk that remains after controls/mitigations have been implemented.
What is a 'control' (safeguard/countermeasure)?
A control is a policy, procedure, practice, or technical mechanism that reduces risk by lowering the likelihood or impact of a threat exploiting a vulnerability.
What is the difference between a threat agent (threat actor) and a threat?
A threat is the potential danger; a threat agent/actor is the entity (person, group, or thing) that carries out or triggers the threat.
Define 'likelihood' (probability) in risk assessment.
Likelihood is the chance or frequency that a given threat will successfully exploit a vulnerability within a defined time period.
Define 'impact' in risk assessment.
Impact is the magnitude of harm or loss resulting from a threat exploiting a vulnerability—measured in financial, operational, reputational, or regulatory terms.
What is 'risk appetite'?
Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of its objectives, set at the strategic level by senior management/board.
What is 'risk tolerance'?
Risk tolerance is the acceptable level of variation (deviation) around specific objectives or risk types—a more granular, operational boundary than risk appetite.
How do risk appetite and risk tolerance differ?
Risk appetite is the overall strategic amount of risk an organization will accept; risk tolerance is the acceptable deviation around specific objectives. Tolerance operationalizes appetite.
What is 'risk capacity'?
Risk capacity is the maximum amount of risk an organization can absorb before threatening its viability—an objective limit, unlike appetite which is a chosen preference.
Who is ultimately responsible for setting an organization's risk appetite?
The board of directors and senior management (executive leadership) set risk appetite, aligning it with business strategy and objectives.
Why must risk tolerance levels be documented and communicated?
So that risk treatment decisions are consistent, risk owners know acceptable thresholds, and exceptions can be escalated when tolerance is exceeded.
What is an Advanced Persistent Threat (APT)?
An APT is a stealthy, prolonged, and targeted cyberattack—typically by a well-resourced adversary—that gains and maintains unauthorized access to exfiltrate data over time.
What is a 'zero-day vulnerability'?
A zero-day is a software flaw unknown to the vendor (or with no available patch) that attackers can exploit before a fix is released.
What is a 'supply chain attack' as an emerging threat?
An attack that compromises an organization indirectly by targeting a trusted third-party vendor, software component, or service provider in its supply chain.
What distinguishes a vulnerability from an emerging threat in monitoring?
A vulnerability is an existing weakness to be patched/mitigated; an emerging threat is a new or evolving danger (new malware, attack technique) requiring updated threat intelligence.
Why is threat intelligence important for managing emerging threats?
It provides timely, actionable information about new attack vectors, actors, and indicators of compromise, enabling proactive defense before threats materialize.
Planning Information Security Risk Assessment for Certified Information Security Manager (CISM)
Information Security Risk Assessment is about 15% of the Certified Information Security Manager (CISM) syllabus by topic count — 10 of 68 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.
The heaviest chapters are Risk Concepts and the Risk Landscape (4 topics), Asset Identification and Valuation (3 topics), Risk Identification and Analysis (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Information Security Risk Assessment (Certified Information Security Manager (CISM)) FAQ
What is in the Certified Information Security Manager (CISM) Information Security Risk Assessment syllabus?
Information Security Risk Assessment is split into 3 chapters — Risk Concepts and the Risk Landscape, Asset Identification and Valuation and Risk Identification and Analysis, containing 10 topics and 20 sub-topics in total.
How many chapters are there in Information Security Risk Assessment for Certified Information Security Manager (CISM)?
3 chapters. Information Security Risk Assessment accounts for about 15% of the topics in the whole Certified Information Security Manager (CISM) syllabus (10 of 68).
How long should I spend on Information Security Risk Assessment for Certified Information Security Manager (CISM)?
Budget around 10 hours for a first pass through Information Security Risk Assessment — about 45 minutes per topic plus 12 minutes per sub-topic across its 10 topics. Add revision cycles on top.
Are there flashcards for Certified Information Security Manager (CISM) Information Security Risk Assessment?
Yes — a 51-card Information Security Risk Assessment deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.