🇺🇸 Certified Information Security Manager (CISM) · flashcards
Certified Information Security Manager (CISM) Information Security Governance Flashcards
67 question-and-answer cards covering Information Security Governance as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Information Security Governance deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What is a standard in the policy hierarchy?
A mandatory rule specifying uniform requirements (e.g., specific technologies, configurations, or methods) used to support and enforce policy.
What is a procedure?
A detailed, mandatory, step-by-step set of instructions describing how to perform a specific task to comply with policies and standards.
What is a guideline?
A recommended, non-mandatory set of best practices or suggestions that provide flexibility where mandatory standards are not appropriate.
What is the difference between a policy and a procedure?
A policy states what must be achieved and why (high-level intent, rarely changes); a procedure states how to do it (detailed steps, changes more often).
What is a RACI chart used for in security governance?
To define and clarify roles by mapping who is Responsible, Accountable, Consulted, and Informed for each task or decision, eliminating ambiguity.
In RACI, what is the difference between 'Responsible' and 'Accountable'?
Responsible = the person who does the work; Accountable = the single person ultimately answerable for the outcome and who approves it (only one 'A' per task).
What is the role of a data owner vs. a data custodian?
The data owner (a business manager) is accountable for classification and protection decisions; the custodian (often IT) implements and maintains the controls the owner specifies.
What is the purpose of security metrics and reporting?
To measure program performance, support decision-making, demonstrate value/effectiveness, ensure accountability, and communicate status to management.
What is a Key Performance Indicator (KPI) vs. a Key Risk Indicator (KRI)?
A KPI measures how well a process/control is performing (effectiveness/efficiency); a KRI is a forward-looking metric that signals increasing risk exposure or that a threshold is being approached.
What is a Key Goal Indicator (KGI)?
A metric that indicates whether a process or objective has achieved its intended goal/outcome (a measure of success after the fact).
What makes a security metric effective (SMART criteria)?
It should be Specific, Measurable, Attainable, Relevant, and Time-bound — and meaningful, actionable, and tied to business objectives.
What is a security balanced scorecard?
A reporting tool that measures the security program across multiple perspectives (e.g., financial, customer, internal process, learning/growth) to link it to business strategy.
Why should metrics reported to senior management be different from technical metrics?
Executives need business-relevant, risk- and value-oriented metrics for decision-making, not detailed technical data; reporting should match the audience's needs.
What is assurance in information security governance?
The confidence that controls are operating effectively and objectives are being met, gained through activities such as audits, reviews, testing, and certifications.
What is a maturity model?
A framework that describes progressive levels of process capability/maturity, used to assess the current state and define improvement targets for a security program.
What are the five levels of the CMMI maturity model?
1) Initial (ad hoc), 2) Managed/Repeatable, 3) Defined, 4) Quantitatively Managed/Measured, 5) Optimizing (continuous improvement).
What does CMMI Level 0 represent (in CMMI/COBIT process maturity)?
Non-existent / Incomplete — there is a complete lack of any recognizable process; the organization has not recognized the need to address the issue.
What is assurance process integration and why is it important?
Aligning and coordinating the various assurance functions (audit, risk, security, compliance, legal) so they work together, avoid gaps/overlaps, and provide comprehensive coverage.
What is the purpose of a maturity assessment in strategy?
To benchmark the current capability level against a target level, identify gaps, and prioritize improvements toward the desired state.
What is the difference between effectiveness and efficiency of a control?
Effectiveness measures whether the control achieves its intended security objective; efficiency measures whether it does so with optimal use of resources/cost.
What is 'tone at the top' and why is it critical to governance?
The ethical climate and commitment to security demonstrated by senior leadership; it drives organizational culture and is the single most important factor in program success.
What is the difference between a threat, a vulnerability, and a risk?
A threat is a potential cause of harm; a vulnerability is a weakness that a threat can exploit; risk is the likelihood and impact of a threat exploiting a vulnerability.
What are the three lines of defense model roles in governance?
1st line: operational management (owns and manages risk); 2nd line: risk/compliance/security functions (oversight); 3rd line: internal audit (independent assurance).
Why must security policies be approved by senior management?
To give them organizational authority and enforceability, demonstrate management commitment, and ensure alignment with business objectives and risk appetite.
What this deck covers
The Information Security Governance deck follows the Certified Information Security Manager (CISM) Information Security Governance syllabus — 3 chapters and 11 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 22.3 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 156 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Information Security Governance flashcards FAQ
How many Information Security Governance flashcards are in this Certified Information Security Manager (CISM) deck?
67 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Information Security Manager (CISM) flashcards free?
Yes. The preview here is free to read with no signup, and the full 67-card deck is free inside the Examius app.
What do the Information Security Governance cards cover?
They follow the Certified Information Security Manager (CISM) Information Security Governance syllabus — 3 chapters and 11 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.