🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject

CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance Syllabus

Every chapter and topic of Business Continuity, Incident Management and Assurance examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 12 topics and 18 sub-topics, plus 61 flashcards written against it.

3Chapters
12Topics
18Sub-topics
~15hEst. first pass
15%Of CISMP (Certificate in Information Security Management Principles)
61Flashcards

Business Continuity, Incident Management and Assurance syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Business Continuity, Incident Management and Assurance in CISMP (Certificate in Information Security Management Principles), not a summary of it.

  1. Incident Management

    4 topics
    • Incident management lifecycle
      • Detection, reporting and triage
      • Containment, eradication and recovery
    • Roles and escalation
      • Incident response team
      • Communications and notification
    • Learning from incidents
      • Post-incident review
      • Feedback into controls
    • Digital forensics and evidence
      • Preserving the chain of custody
  2. Business Continuity and Disaster Recovery

    4 topics
    • Business continuity management
      • Business impact analysis
      • RTO and RPO
    • Disaster recovery planning
      • Recovery strategies and sites
      • Invocation and escalation
    • Testing and maintenance
      • Exercising the plan
      • Keeping plans current
    • Relationship to information security
      • Availability and resilience
  3. Investigations, Assurance and Continual Improvement

    4 topics
    • Security assurance methods
      • Audit, review and assessment
    • Investigations and disciplinary action
      • Conducting internal investigations
    • Metrics and reporting
      • Key performance and risk indicators
    • Continual improvement
      • Corrective and preventive action

Business Continuity, Incident Management and Assurance flashcards for CISMP (Certificate in Information Security Management Principles)

25 of 61 cards from the Business Continuity, Incident Management and Assurance deck — real questions with worked answers.

  1. What are the recognised phases of the incident management lifecycle (as typically taught in CISMP / aligned to ISO/IEC 27035)?

    Plan and prepare; Detection and reporting; Assessment and decision (triage); Response (containment, eradication, recovery); Lessons learned (post-incident review).

  2. In information security, what is the definition of a 'security event' versus a 'security incident'?

    A security event is any observable occurrence in a system or network. A security incident is one or more related, identified security events that compromise (or threaten) confidentiality, integrity or availability and warrant a response.

  3. What is the primary objective of incident management?

    To restore normal service operation as quickly as possible while minimising adverse impact on the business, and to ensure the best possible levels of service quality and availability are maintained.

  4. What is 'triage' in the context of incident handling?

    The initial assessment and prioritisation of a reported incident — categorising it, judging its severity/impact, and deciding the response and who should handle it.

  5. Define 'containment' as a step in incident response.

    Actions taken to limit the scope and magnitude of an incident — stopping it spreading and preventing further damage — before eradication and recovery.

  6. What is the difference between 'eradication' and 'recovery' in incident response?

    Eradication removes the cause of the incident (e.g. malware, compromised accounts, vulnerabilities). Recovery restores affected systems and services to normal, validated operation.

  7. What is a CSIRT (also called CERT)?

    A Computer Security Incident Response Team — a designated group responsible for receiving, reviewing and responding to computer security incident reports and activity.

  8. What is the purpose of an incident response 'playbook' or runbook?

    A predefined, step-by-step set of procedures for responding to a specific type of incident, ensuring a consistent, repeatable and timely response.

  9. Why is escalation important in incident management, and what triggers it?

    Escalation ensures incidents reach staff with the right authority/skill. Triggers include rising severity/impact, breach of SLA timeframes, inability to resolve at the current level, or legal/regulatory implications.

  10. Distinguish 'functional escalation' from 'hierarchical escalation'.

    Functional (horizontal) escalation passes an incident to a team with the needed technical expertise. Hierarchical (vertical) escalation raises it to higher management for awareness, authority or resources.

  11. What is the role of the Incident Manager (incident coordinator)?

    To own and coordinate the end-to-end response: directing the team, controlling communications, making/escalating decisions, and ensuring the incident is documented and resolved.

  12. Why should senior management be involved in significant security incidents?

    They hold accountability and authority to commit resources, make business-risk decisions, authorise external communication, and meet legal/regulatory reporting obligations.

  13. What is the purpose of the 'lessons learned' / post-incident review phase?

    To analyse how the incident was handled, identify root causes and weaknesses, and feed improvements back into controls, processes and the incident plan to prevent recurrence.

  14. What is a root cause analysis (RCA), and name a common technique.

    RCA is a structured method to identify the underlying cause of an incident rather than just its symptoms. A common technique is the '5 Whys' (repeatedly asking 'why'); others include fishbone/Ishikawa diagrams.

  15. What is a 'post-incident report' expected to contain?

    A timeline of events, what happened and its impact, the root cause, how it was detected and handled, decisions taken, and recommendations/actions for improvement.

  16. What is the goal of digital forensics?

    To identify, collect, preserve, analyse and present digital evidence in a manner that is legally sound and admissible, while maintaining its integrity.

  17. What does ACPO guidance (UK) state as Principle 1 of computer-based electronic evidence?

    No action taken should change data held on a computer or storage media which may subsequently be relied upon in court.

  18. List the four ACPO principles of digital evidence (UK).

    1) No action should change data that may be relied on in court. 2) If access to original data is necessary, the person must be competent and able to explain their actions. 3) An audit trail of all processes should be created and preserved. 4) The person in charge of the investigation is responsible for ensuring the law and principles are adhered to.

  19. What is the 'chain of custody' and why is it critical to forensic evidence?

    A documented, unbroken record of who collected, handled, transferred and stored evidence, and when. It is critical to prove the evidence has not been tampered with and to ensure admissibility in court.

  20. Why are cryptographic hashes (e.g. of a disk image) used in digital forensics?

    A hash provides a unique fingerprint of the data; recomputing it later and matching the original value proves the evidence has not been altered, demonstrating integrity.

  21. What is a 'write blocker' and why is it used in forensics?

    A hardware or software device that allows read-only access to storage media so the original evidence cannot be modified during acquisition (supporting ACPO Principle 1).

  22. What is the difference between 'volatile' and 'non-volatile' data in forensic acquisition, and which is collected first?

    Volatile data (e.g. RAM contents, running processes, network connections) is lost on power-off; non-volatile data (e.g. disk) persists. Volatile data is collected first, following the 'order of volatility'.

  23. Define Business Continuity Management (BCM).

    A holistic management process that identifies potential threats to an organisation and the impacts to operations, and provides a framework for building resilience and the capability to respond effectively to safeguard interests, reputation, brand and value-creating activities.

  24. Which ISO standard specifies requirements for Business Continuity Management Systems (BCMS)?

    ISO 22301.

  25. What is a Business Impact Analysis (BIA) and what does it determine?

    A process that identifies critical business functions and the impact over time of their disruption. It determines recovery priorities and the key recovery objectives (RTO, RPO, MTPD/MAO).

See more Business Continuity, Incident Management and Assurance flashcards →

Planning Business Continuity, Incident Management and Assurance for CISMP (Certificate in Information Security Management Principles)

Business Continuity, Incident Management and Assurance is about 15% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 12 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.

The heaviest chapters are Incident Management (4 topics), Business Continuity and Disaster Recovery (4 topics), Investigations, Assurance and Continual Improvement (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Business Continuity, Incident Management and Assurance (CISMP (Certificate in Information Security Management Principles)) FAQ

What is in the CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance syllabus?

Business Continuity, Incident Management and Assurance is split into 3 chapters — Incident Management, Business Continuity and Disaster Recovery and Investigations, Assurance and Continual Improvement, containing 12 topics and 18 sub-topics in total.

How many chapters are there in Business Continuity, Incident Management and Assurance for CISMP (Certificate in Information Security Management Principles)?

3 chapters. Business Continuity, Incident Management and Assurance accounts for about 15% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (12 of 81).

How long should I spend on Business Continuity, Incident Management and Assurance for CISMP (Certificate in Information Security Management Principles)?

Budget around 15 hours for a first pass through Business Continuity, Incident Management and Assurance — about 45 minutes per topic plus 12 minutes per sub-topic across its 12 topics. Add revision cycles on top.

Are there flashcards for CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance?

Yes — a 61-card Business Continuity, Incident Management and Assurance deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.