🇬🇧 CISMP (Certificate in Information Security Management Principles) · subject
CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts Syllabus
Every chapter and topic of Information Security Management Principles and Concepts examined in CISMP (Certificate in Information Security Management Principles) — 3 chapters, 12 topics and 27 sub-topics, plus 50 flashcards written against it.
Information Security Management Principles and Concepts syllabus — full chapter and topic list
Expand any chapter to see its topics and sub-topics. This is the whole examinable outline for Information Security Management Principles and Concepts in CISMP (Certificate in Information Security Management Principles), not a summary of it.
-
Core Security Concepts and Terminology
4 topics- The CIA Triad
- Confidentiality and need-to-know
- Integrity and data accuracy
- Availability and business continuity
- Extended security attributes
- Authenticity and non-repudiation
- Accountability and auditability
- Reliability and resilience
- Assets, threats, vulnerabilities and risk
- Distinguishing assets from controls
- Threat agents and threat sources
- Impact and likelihood
- The need for and benefits of information security
- Protecting business value and reputation
- Enabling secure operations
- The CIA Triad
-
The Information Security Lifecycle and Governance
4 topics- Plan-Do-Check-Act and continual improvement
- The PDCA cycle in an ISMS
- Measuring effectiveness
- Information security governance
- Board and senior management responsibility
- Direct, monitor and report
- Roles and responsibilities
- CISO, information owners and custodians
- Users and third parties
- Security culture and behaviour
- Embedding security into the organisation
- Influencing user behaviour
- Plan-Do-Check-Act and continual improvement
-
Information Security Management Systems (ISMS)
4 topics- Purpose and scope of an ISMS
- Defining scope and boundaries
- Context of the organisation
- ISO/IEC 27001 and 27002 overview
- Requirements versus guidance
- Statement of Applicability
- Certification and accreditation
- The certification process
- Surveillance and recertification audits
- Policy, standards, procedures and guidelines
- Document hierarchy
- Maintaining the policy framework
- Purpose and scope of an ISMS
Information Security Management Principles and Concepts flashcards for CISMP (Certificate in Information Security Management Principles)
20 of 50 cards from the Information Security Management Principles and Concepts deck — real questions with worked answers.
What three core attributes make up the CIA Triad in information security?
Confidentiality, Integrity and Availability.
Define Confidentiality as used in the CIA Triad.
Ensuring that information is accessible only to those authorised to have access; preventing unauthorised disclosure.
Define Integrity as used in the CIA Triad.
Safeguarding the accuracy and completeness of information and processing methods; preventing unauthorised or accidental modification.
Define Availability as used in the CIA Triad.
Ensuring that authorised users have access to information and associated assets when required.
Name the commonly cited extended (additional) security attributes beyond the CIA Triad.
Authenticity, Accountability, Non-repudiation, and Reliability.
What does the security attribute 'non-repudiation' guarantee?
That a party cannot deny having performed an action, such as sending a message or authorising a transaction; proof of origin and delivery.
What does the security attribute 'authenticity' mean?
That an entity (user, process or data) is genuine and is what it claims to be; the property of being verified and trusted.
What does 'accountability' mean as a security attribute?
The ability to trace actions uniquely to a responsible entity, supporting non-repudiation, detection and prevention.
In information security terms, what is an asset?
Anything that has value to the organisation and therefore requires protection (e.g. data, hardware, software, people, reputation, services).
Define a 'threat' in risk terminology.
A potential cause of an unwanted incident that may result in harm to a system or organisation; something that can exploit a vulnerability.
Define a 'vulnerability' in risk terminology.
A weakness in an asset or control that can be exploited by one or more threats.
Define 'risk' in information security.
The potential that a given threat will exploit a vulnerability of an asset and thereby cause harm; the effect of uncertainty on objectives.
State the conceptual relationship/formula for information security risk.
Risk is a function of likelihood and impact: $\text{Risk} = \text{Likelihood} \times \text{Impact}$ (threats exploiting vulnerabilities against assets).
What is the formula for Annualised Loss Expectancy (ALE)?
$\text{ALE} = \text{SLE} \times \text{ARO}$, where SLE is the Single Loss Expectancy and ARO is the Annualised Rate of Occurrence.
What is the formula for Single Loss Expectancy (SLE)?
$\text{SLE} = \text{Asset Value} \times \text{Exposure Factor}$, where the Exposure Factor is the proportion of the asset lost in a single event.
Name the four standard options for treating an identified risk.
Treat (reduce/modify with controls), Tolerate (accept/retain), Transfer (share, e.g. insurance), and Terminate (avoid/eliminate the activity).
Distinguish between inherent risk and residual risk.
Inherent risk is the level of risk before any controls are applied; residual risk is the risk remaining after controls have been implemented.
What is a 'control' (countermeasure) in information security?
A measure that modifies risk, including policies, procedures, practices and technical or organisational safeguards that reduce likelihood or impact.
List the four broad categories of security control by function.
Preventive, Detective, Corrective, and Deterrent (directive/compensating are also sometimes added).
Give the three control types by nature/implementation.
Physical (e.g. locks, fences), Technical/Logical (e.g. firewalls, encryption), and Administrative/Procedural (e.g. policies, training).
See more Information Security Management Principles and Concepts flashcards →
Planning Information Security Management Principles and Concepts for CISMP (Certificate in Information Security Management Principles)
Information Security Management Principles and Concepts is about 15% of the CISMP (Certificate in Information Security Management Principles) syllabus by topic count — 12 of 81 topics, spread over 3 chapters. At roughly 45 minutes per topic plus 12 minutes per sub-topic, a first pass runs to about 15 hours.
The heaviest chapters are Core Security Concepts and Terminology (4 topics), The Information Security Lifecycle and Governance (4 topics), Information Security Management Systems (ISMS) (4 topics) . Front-load those while your energy is high; the short chapters are better revision filler later.
Work top-down: read the chapter, then tick topics off individually rather than marking the whole chapter done. Sub-topics are where silent gaps hide.
Information Security Management Principles and Concepts (CISMP (Certificate in Information Security Management Principles)) FAQ
What is in the CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts syllabus?
Information Security Management Principles and Concepts is split into 3 chapters — Core Security Concepts and Terminology, The Information Security Lifecycle and Governance and Information Security Management Systems (ISMS), containing 12 topics and 27 sub-topics in total.
How is Information Security Management Principles and Concepts structured in the CISMP (Certificate in Information Security Management Principles) syllabus?
3 chapters. Information Security Management Principles and Concepts accounts for about 15% of the topics in the whole CISMP (Certificate in Information Security Management Principles) syllabus (12 of 81).
How long should I spend on Information Security Management Principles and Concepts for CISMP (Certificate in Information Security Management Principles)?
Budget around 15 hours for a first pass through Information Security Management Principles and Concepts — about 45 minutes per topic plus 12 minutes per sub-topic across its 12 topics. Add revision cycles on top.
Are there flashcards for CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts?
Yes — a 50-card Information Security Management Principles and Concepts deck. Sample cards are printed on this page, and the full deck is free in the Examius app with spaced repetition scheduling.