🇬🇧 Chartered IT Professional (CITP) · subject
Chartered IT Professional (CITP) Information Security, Risk and Resilience Syllabus
Every chapter and topic of Information Security, Risk and Resilience examined in Chartered IT Professional (CITP) — 4 chapters, 12 topics and 30 sub-topics, plus 54 flashcards written against it.
Information Security, Risk and Resilience syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security, Risk and Resilience in Chartered IT Professional (CITP), not a summary of it.
-
Security Principles and Governance
3 topics- Core Security Concepts
- Confidentiality, integrity and availability
- Defence in depth and least privilege
- Zero trust principles
- Security Governance and Standards
- ISO/IEC 27001 information security management
- NCSC guidance and Cyber Essentials
- Security policy and culture
- Identity and Access Management
- Authentication and multi-factor methods
- Authorisation and role-based access
- Privileged access management
- Core Security Concepts
-
Threats, Vulnerabilities and Controls
3 topics- Threat Landscape
- Malware, phishing and social engineering
- Advanced persistent threats and insider risk
- Technical Controls
- Cryptography and key management
- Network and endpoint protection
- Secure configuration and hardening
- Security Testing and Assurance
- Vulnerability assessment and penetration testing
- Secure development and code assurance
- Threat Landscape
-
Risk Management
3 topics- Risk Identification and Assessment
- Qualitative and quantitative methods
- Threat modelling and risk registers
- Risk Treatment and Appetite
- Mitigate, transfer, accept and avoid
- Residual risk and risk appetite
- Third-Party and Supply Chain Risk
- Vendor assessment and due diligence
- Contractual security obligations
- Risk Identification and Assessment
-
Business Continuity and Incident Response
3 topics- Business Continuity and Disaster Recovery
- Business impact analysis
- Recovery time and recovery point objectives
- Continuity testing and exercises
- Incident Management
- Detection, triage and containment
- Forensics and evidence handling
- Post-incident review and lessons learned
- Operational Resilience
- Resilience by design
- Crisis communication and stakeholder management
- Business Continuity and Disaster Recovery
Information Security, Risk and Resilience flashcards for Chartered IT Professional (CITP)
22 of 54 cards from the Information Security, Risk and Resilience deck — real questions with worked answers.
What three properties make up the CIA triad in information security?
Confidentiality (data is accessible only to authorised parties), Integrity (data is accurate and unaltered), and Availability (data and systems are accessible when needed).
What two additional properties are often added to the CIA triad to form an extended security model?
Authenticity (verifying identity/origin is genuine) and Non-repudiation (a party cannot deny having performed an action). Together with CIA these form the basis of the Parkerian/extended models.
Define the difference between a threat, a vulnerability, and a risk.
A threat is a potential cause of an unwanted incident; a vulnerability is a weakness that a threat can exploit; risk is the effect of uncertainty combining the likelihood of a threat exploiting a vulnerability and its impact.
What is the principle of 'defence in depth'?
Layering multiple, independent security controls (physical, technical, administrative) so that if one control fails, others still protect the asset. No single point of failure compromises security.
What does the principle of 'least privilege' require?
Users, processes and systems are granted only the minimum access rights and permissions necessary to perform their function, and no more.
Contrast the security principles of 'fail-secure' (fail-closed) and 'fail-safe' (fail-open).
Fail-secure/fail-closed denies access when a control fails, prioritising confidentiality/security (e.g. a locked door staying locked). Fail-safe/fail-open allows access on failure, prioritising availability/safety (e.g. a fire door unlocking).
In the ISO/IEC 27000 family, what is the purpose of ISO/IEC 27001?
It specifies the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS), and is the standard against which organisations can be certified.
What is the relationship between ISO/IEC 27001 and ISO/IEC 27002?
ISO/IEC 27001 specifies the certifiable ISMS requirements (the 'what'); ISO/IEC 27002 is a code of practice providing implementation guidance and detail on the controls (the 'how').
What model of continual improvement underpins an ISO 27001 ISMS?
The Plan-Do-Check-Act (PDCA) cycle: Plan (establish objectives/controls), Do (implement), Check (monitor and review), Act (maintain and improve).
In information security governance, what is a Statement of Applicability (SoA)?
A documented statement (required by ISO 27001) listing the Annex A controls, whether each is applicable, the justification for inclusion or exclusion, and its implementation status.
What is the distinction between security governance and security management?
Governance is the direction, oversight and accountability set by senior leadership (strategy, policy, risk appetite); management is the operational implementation of those directions through processes and controls.
Name the five core functions of the NIST Cybersecurity Framework (CSF).
Identify, Protect, Detect, Respond, and Recover. (CSF 2.0 adds a sixth overarching function: Govern.)
In Identity and Access Management, distinguish authentication from authorisation.
Authentication verifies who a subject is (proving identity); authorisation determines what an authenticated subject is permitted to do (granting access rights to resources).
What are the three classic factors of authentication?
Something you know (password/PIN), something you have (token/smart card/phone), and something you are (biometric). Multi-factor authentication combines two or more different factors.
Compare Role-Based Access Control (RBAC) with Attribute-Based Access Control (ABAC).
RBAC grants permissions based on a user's assigned role(s). ABAC grants access dynamically by evaluating policies over attributes of the subject, resource, action and environment, giving finer-grained, context-aware control.
What is Single Sign-On (SSO) and what is one key risk it introduces?
SSO lets a user authenticate once to gain access to multiple systems/applications. Its key risk is that compromise of the single credential or identity provider gives an attacker access to all linked systems.
Differentiate biometric False Acceptance Rate (FAR) from False Rejection Rate (FRR), and name the balance point.
FAR is the rate at which an imposter is wrongly accepted; FRR is the rate at which a legitimate user is wrongly rejected. The point where they are equal is the Crossover/Equal Error Rate (CER/EER); a lower EER indicates a more accurate system.
What is privileged access management (PAM) primarily concerned with?
Securing, controlling and monitoring elevated/administrative accounts — e.g. via credential vaulting, just-in-time access, session recording and least-privilege enforcement — because these accounts carry the highest risk if compromised.
In the threat landscape, what does an Advanced Persistent Threat (APT) refer to?
A sophisticated, well-resourced (often state-sponsored) adversary that gains and maintains long-term, stealthy access to a target network to exfiltrate data or cause disruption over an extended period.
List the typical ordered stages of the Cyber Kill Chain.
Reconnaissance, Weaponisation, Delivery, Exploitation, Installation, Command and Control (C2), and Actions on Objectives.
Distinguish a virus, a worm, and a Trojan.
A virus attaches to a host file and needs user action to spread; a worm self-replicates and spreads across networks without a host or user action; a Trojan masquerades as legitimate software to trick a user into running it.
What distinguishes a zero-day vulnerability?
It is a vulnerability unknown to the vendor (or for which no patch yet exists), so defenders have had 'zero days' to fix it; a zero-day exploit attacks such a flaw before mitigation is available.
See more Information Security, Risk and Resilience flashcards →
Planning Information Security, Risk and Resilience for Chartered IT Professional (CITP)
Information Security, Risk and Resilience is about 14% of the Chartered IT Professional (CITP) syllabus by topic count — 12 of 83 topics, spread over 4 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.
The heaviest chapters are Security Principles and Governance (3 topics), Threats, Vulnerabilities and Controls (3 topics), Risk Management (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Information Security, Risk and Resilience (Chartered IT Professional (CITP)) FAQ
What is in the Chartered IT Professional (CITP) Information Security, Risk and Resilience syllabus?
Information Security, Risk and Resilience is split into 4 chapters — Security Principles and Governance, Threats, Vulnerabilities and Controls, Risk Management and Business Continuity and Incident Response, containing 12 topics and 30 sub-topics in total.
How many chapters are there in Information Security, Risk and Resilience for Chartered IT Professional (CITP)?
4 chapters. Information Security, Risk and Resilience accounts for about 14% of the topics in the whole Chartered IT Professional (CITP) syllabus (12 of 83).
How long should I spend on Information Security, Risk and Resilience for Chartered IT Professional (CITP)?
Budget around 15 hours for a first pass through Information Security, Risk and Resilience — about 45 minutes per topic plus 12 minutes per sub-topic across its 12 topics. Add revision cycles on top.
Are there flashcards for Chartered IT Professional (CITP) Information Security, Risk and Resilience?
Yes — a 54-card Information Security, Risk and Resilience deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.