🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject

CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance Syllabus

Every chapter and topic of Information Security Frameworks, Law and Compliance examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 11 topics and 20 sub-topics, plus 50 flashcards written against it.

3Chapters
11Topics
20Sub-topics
~10hEst. first pass
14%Of CISMP (Certificate in Information Security Management Principles)
50Flashcards

Information Security Frameworks, Law and Compliance syllabus — full chapter and topic list

Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security Frameworks, Law and Compliance in CISMP (Certificate in Information Security Management Principles), not a summary of it.

  1. Organisation and Responsibilities

    3 topics
    • Internal organisation of security
      • Segregation of duties
      • Contact with authorities and special interest groups
    • Third-party and supplier security
      • Supply chain risk
      • Contractual security requirements
    • Security in projects and change
  2. UK and International Law

    4 topics
    • UK GDPR and Data Protection Act 2018
      • Data protection principles
      • Rights of data subjects
      • Role of the ICO
    • Computer Misuse Act 1990
      • Unauthorised access offences
      • Impairing computer operation
    • Intellectual property and copyright
      • Software licensing
      • Copyright, Designs and Patents Act
    • Other relevant legislation
      • Regulation of Investigatory Powers / Investigatory Powers Act
      • Freedom of Information Act
      • Network and Information Systems (NIS) Regulations
  3. Standards, Procedures and Compliance

    4 topics
    • International and UK standards
      • ISO/IEC 27000 family
      • PCI DSS for payment data
    • Codes of practice and good practice guides
      • NCSC guidance and Cyber Essentials
    • Compliance monitoring and audit
      • Internal versus external audit
      • Demonstrating compliance
    • Records management and retention
      • Retention schedules and legal hold

Information Security Frameworks, Law and Compliance flashcards for CISMP (Certificate in Information Security Management Principles)

21 of 50 cards from the Information Security Frameworks, Law and Compliance deck — real questions with worked answers.

  1. What is the purpose of defining an 'internal organisation of security' within an ISMS?

    To establish a management framework that initiates and controls the implementation and operation of information security within the organisation - allocating roles, responsibilities and authorities for security.

  2. In information security governance, what is the difference between 'responsibility' and 'accountability'?

    Accountability is the ultimate ownership/answerability for an outcome and cannot be delegated (typically held by senior management/the board). Responsibility is the duty to carry out specific tasks and can be delegated to others.

  3. What does 'segregation (separation) of duties' achieve as an internal organisational control?

    It divides conflicting tasks among different people so no single individual can both perpetrate and conceal an error or fraud, reducing the risk of misuse, fraud and unauthorised modification of assets.

  4. Who is typically accountable at board level for information security in an organisation?

    A senior responsible owner such as a member of the board or executive (e.g. a CISO reporting upward, or a designated director); the board retains overall accountability for risk and security governance.

  5. What is the role of a Senior Information Risk Owner (SIRO) in a UK public-sector context?

    A board-level executive accountable for managing information risk across the organisation, owning the information risk policy, fostering a risk-aware culture and advising the board on information risk.

  6. What is the function of an 'Information Asset Owner' (IAO)?

    A senior individual accountable for a specific information asset - understanding what information is held, how it is used and protected, and ensuring risks to that asset are identified and managed.

  7. Why should security responsibilities be defined and allocated in job descriptions and contracts?

    To ensure individuals know their security duties, create enforceable obligations, support accountability, and demonstrate due diligence/compliance with policy and standards.

  8. What is the value of maintaining 'contact with special interest groups' and authorities as an organisational control?

    It keeps the organisation informed of threats, vulnerabilities, best practice and legal/regulatory changes, and ensures appropriate liaison with authorities (e.g. police, regulators) during incidents.

  9. Why must information security be addressed in 'project management' regardless of the project type?

    So that security risks are identified and treated early ('security by design'), avoiding costly retrofits; security requirements should be integrated into all projects, not just IT/security projects.

  10. What are the main security risks introduced by third-party suppliers accessing organisational information?

    Loss of direct control, increased attack surface, data leakage, weaker supplier security, breach of confidentiality, supply-chain compromise and inadequate incident handling.

  11. What should be agreed before granting a supplier access to organisational information assets?

    The security requirements - documented in contracts/agreements - covering access rights, data handling, confidentiality, applicable controls, audit rights, incident reporting and return/destruction of data.

  12. What is a 'supply chain attack' in information security?

    An attack that compromises an organisation indirectly by targeting a less-secure element in its supplier or product supply chain (e.g. malicious software updates or a compromised vendor).

  13. What contractual clauses help manage third-party/supplier information security risk?

    Confidentiality/NDA clauses, defined security requirements, right-to-audit, incident notification timeframes, sub-contractor (fourth-party) controls, data return/destruction, and liability/indemnity terms.

  14. What is the purpose of a 'right to audit' clause in a supplier contract?

    It gives the organisation the contractual ability to verify (directly or via a third party) that the supplier is meeting agreed security obligations and controls.

  15. Why should information security be considered during 'change management'?

    Uncontrolled changes can introduce vulnerabilities, break controls or cause outages; change management ensures changes are assessed for security impact, tested, approved and reversible (rollback).

  16. What is the difference between 'change management' and 'configuration management'?

    Change management is the controlled process for requesting, assessing, approving and implementing changes. Configuration management maintains an accurate record of assets/configurations (CMDB) and their relationships.

  17. Within the UK, what two main pieces of legislation together govern data protection since 2018?

    The UK GDPR (UK General Data Protection Regulation) and the Data Protection Act 2018 (DPA 2018), which supplements and tailors the UK GDPR.

  18. Define 'personal data' under the UK GDPR.

    Any information relating to an identified or identifiable living natural person (data subject) who can be identified directly or indirectly, e.g. by name, ID number, location data or online identifier.

  19. What are the 'special categories' of personal data under UK GDPR that require extra protection?

    Data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, and data on sex life or sexual orientation.

  20. List the seven data protection principles under the UK GDPR (Article 5).

    1) Lawfulness, fairness and transparency; 2) Purpose limitation; 3) Data minimisation; 4) Accuracy; 5) Storage limitation; 6) Integrity and confidentiality (security); 7) Accountability.

  21. What does the 'accountability' principle in UK GDPR require of organisations?

    The controller must not only comply with the principles but be able to demonstrate compliance (through policies, records of processing, DPIAs, training and documentation).

See more Information Security Frameworks, Law and Compliance flashcards →

Planning Information Security Frameworks, Law and Compliance for CISMP (Certificate in Information Security Management Principles)

Information Security Frameworks, Law and Compliance is about 14% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 11 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 10 hours.

The heaviest chapters are UK and International Law (4 topics), Standards, Procedures and Compliance (4 topics), Organisation and Responsibilities (3 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.

Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.

Information Security Frameworks, Law and Compliance (CISMP (Certificate in Information Security Management Principles)) FAQ

What is in the CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance syllabus?

Information Security Frameworks, Law and Compliance is split into 3 chapters — Organisation and Responsibilities, UK and International Law and Standards, Procedures and Compliance, containing 11 topics and 20 sub-topics in total.

How many chapters are there in Information Security Frameworks, Law and Compliance for CISMP (Certificate in Information Security Management Principles)?

3 chapters. Information Security Frameworks, Law and Compliance accounts for about 14% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (11 of 81).

How long should I spend on Information Security Frameworks, Law and Compliance for CISMP (Certificate in Information Security Management Principles)?

Budget around 10 hours for a first pass through Information Security Frameworks, Law and Compliance — about 45 minutes per topic plus 12 minutes per sub-topic across its 11 topics. Add revision cycles on top.

Are there flashcards for CISMP (Certificate in Information Security Management Principles) Information Security Frameworks, Law and Compliance?

Yes — a 50-card Information Security Frameworks, Law and Compliance deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.