🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject

CISMP (Certificate in Information Security Management Principles) Information Risk Management Syllabus

Every chapter and topic of Information Risk Management examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 12 topics and 18 sub-topics, plus 51 flashcards written against it.

3Chapters
12Topics
18Sub-topics
~15hEst. first pass
15%Of CISMP (Certificate in Information Security Management Principles)
51Flashcards

Information Risk Management syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Risk Management in CISMP (Certificate in Information Security Management Principles), not a summary of it.

  1. Risk Management Concepts

    4 topics
    • Risk terminology
      • Inherent versus residual risk
      • Risk appetite and tolerance
    • Threats and vulnerabilities
      • Categories of threat
      • Sources of vulnerability
    • Likelihood and impact assessment
      • Qualitative scales
      • Quantitative estimation
    • Risk owners and stakeholders
  2. The Risk Management Process

    4 topics
    • Risk identification
      • Asset identification and valuation
      • Building a risk register
    • Risk analysis and evaluation
      • Qualitative methods
      • Quantitative methods and ALE
    • Risk treatment options
      • Treat, tolerate, transfer, terminate
      • Selecting proportionate controls
    • Risk monitoring and review
      • Reassessing changing risk
      • Reporting to management
  3. Risk Methodologies and Standards

    4 topics
    • ISO/IEC 27005 risk management
    • Recognised risk frameworks
      • NIST and ISO approaches
      • UK government risk guidance
    • Cost-benefit and proportionality
      • Balancing control cost against benefit
    • Accreditation and risk acceptance
      • Formal sign-off of residual risk

Information Risk Management flashcards for CISMP (Certificate in Information Security Management Principles)

19 of 51 cards from the Information Risk Management deck — real questions with worked answers.

  1. Define a 'risk' in the context of information security management.

    The potential that a given threat will exploit a vulnerability of an asset (or group of assets) and thereby cause harm to the organisation. It combines the likelihood of an event with the magnitude of its impact.

  2. In risk terminology, what is an 'asset'?

    Anything that has value to the organisation and therefore requires protection. Examples include information, hardware, software, services, people, and reputation.

  3. Define 'threat' as used in information risk management.

    A potential cause of an unwanted incident that may result in harm to a system or organisation. Threats can be deliberate (e.g. hacking), accidental (e.g. human error), or environmental (e.g. fire, flood).

  4. Define 'vulnerability' in information risk terms.

    A weakness in an asset or control that can be exploited by one or more threats. A vulnerability on its own causes no harm; it requires a threat to act upon it.

  5. What is the difference between a threat and a vulnerability?

    A threat is the potential agent or cause of harm (external to the asset); a vulnerability is an internal weakness the threat exploits. Risk only arises when a threat coincides with a matching vulnerability.

  6. Define 'impact' (consequence) in risk assessment.

    The result or outcome of a risk being realised — the harm or loss to the organisation, such as financial loss, reputational damage, legal/regulatory penalties, or loss of confidentiality, integrity or availability.

  7. Define 'likelihood' (probability) in risk assessment.

    The chance or frequency that a particular threat will successfully exploit a vulnerability and the risk will be realised within a given timeframe.

  8. State the conceptual formula relating risk, likelihood and impact.

    $$\text{Risk} = \text{Likelihood} \times \text{Impact}$$ Risk is a function of how probable an event is and how severe its consequences would be.

  9. What is 'residual risk'?

    The risk that remains after risk treatment / security controls have been applied. It is the difference between inherent risk and the risk reduced by controls, and must be formally accepted by management.

  10. What is 'inherent risk'?

    The level of risk that exists before any controls or mitigations are applied — the raw, untreated risk.

  11. Define 'risk appetite'.

    The amount and type of risk an organisation is willing to pursue, accept or retain in order to achieve its objectives, set by senior management/the board.

  12. What is 'risk tolerance'?

    The acceptable level of variation (boundaries) around the risk appetite that an organisation is prepared to withstand for a specific risk before action is required.

  13. Define 'exposure' in risk terms.

    The extent to which an organisation or asset is subject to a particular threat, often expressed as the potential loss if the risk is realised.

  14. What is a 'control' (countermeasure/safeguard)?

    A measure that modifies risk — it can be a policy, procedure, practice, technical mechanism or organisational structure that reduces likelihood, reduces impact, or aids detection/recovery.

  15. Name the four broad categories of controls by function.

    Preventive (stop incidents), Detective (identify incidents), Corrective (limit/recover from impact), and Deterrent (discourage threat actors). (Directive/compensating are sometimes added.)

  16. Give the three main types of control by nature.

    Physical (locks, fences, CCTV), Technical/Logical (firewalls, encryption, access control), and Administrative/Procedural (policies, training, processes).

  17. List the typical stages of the risk management process.

    1) Establish context, 2) Risk identification, 3) Risk analysis, 4) Risk evaluation, 5) Risk treatment, followed by ongoing 6) Monitoring & review and continuous Communication & consultation.

  18. In risk management, what does 'risk assessment' encompass?

    It is the overall process of risk identification, risk analysis and risk evaluation — the part of risk management that determines and prioritises risks before treatment decisions are made.

  19. What is the purpose of 'risk identification'?

    To find, recognise and describe the risks that could affect the achievement of objectives — identifying assets, threats, existing controls, vulnerabilities and potential consequences.

See more Information Risk Management flashcards →

Planning Information Risk Management for CISMP (Certificate in Information Security Management Principles)

Information Risk Management is about 15% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 12 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.

The heaviest chapters are Risk Management Concepts (4 topics), The Risk Management Process (4 topics), Risk Methodologies and Standards (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Information Risk Management (CISMP (Certificate in Information Security Management Principles)) FAQ

What is in the CISMP (Certificate in Information Security Management Principles) Information Risk Management syllabus?

Information Risk Management is split into 3 chapters — Risk Management Concepts, The Risk Management Process and Risk Methodologies and Standards, containing 12 topics and 18 sub-topics in total.

How many chapters are there in Information Risk Management for CISMP (Certificate in Information Security Management Principles)?

3 chapters. Information Risk Management accounts for about 15% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (12 of 81).

How long should I spend on Information Risk Management for CISMP (Certificate in Information Security Management Principles)?

Budget around 15 hours for a first pass through Information Risk Management — about 45 minutes per topic plus 12 minutes per sub-topic across its 12 topics. Add revision cycles on top.

Are there flashcards for CISMP (Certificate in Information Security Management Principles) Information Risk Management?

Yes — a 51-card Information Risk Management deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.