🇺🇸 Certified Information Security Manager (CISM) · flashcards

Certified Information Security Manager (CISM) Information Security Incident Management Flashcards

61 question-and-answer cards covering Information Security Incident Management as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

61Cards in deck
24Free preview
14Syllabus topics
~201Chars per answer
FreePrice

24 sample cards from the Information Security Incident Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Why are forensic images (bit-for-bit copies) and hashing used in evidence handling?

    Analysis is performed on an exact bit-level copy to protect the original, and cryptographic hashes (e.g., SHA-256) verify the image is identical and unaltered, proving evidence integrity.

  2. What is the difference between forensic evidence integrity and admissibility?

    Integrity means the evidence has not been altered (proven via hashing and chain of custody); admissibility means it can be legally accepted in court, requiring proper, lawful collection and handling per evidence rules.

  3. What is a Business Impact Analysis (BIA)?

    A process that identifies critical business processes and assets, and determines the operational, financial, and reputational impact of their disruption over time to prioritize recovery and resilience efforts.

  4. What is Recovery Time Objective (RTO)?

    The maximum acceptable amount of time a business process or system can be unavailable after a disruption before unacceptable consequences occur—i.e., the target time to restore it.

  5. What is Recovery Point Objective (RPO)?

    The maximum acceptable amount of data loss measured in time—i.e., the point in time to which data must be recovered, defining how frequently backups must be taken.

  6. What is the difference between RTO and RPO?

    RTO measures acceptable downtime (how fast you must restore a system); RPO measures acceptable data loss (how much data, in time, you can afford to lose before recovery).

  7. What is Maximum Tolerable Downtime (MTD)?

    The total maximum time a critical process can be unavailable before the organization suffers irreversible damage; MTD = RTO + Work Recovery Time (WRT).

  8. How do RTO and RPO relate to MTD?

    MTD is the overall limit on disruption; RTO (time to restore systems) plus WRT (time to validate and resume operations) must be less than or equal to the MTD.

  9. What is the difference between a BCP and a DRP?

    A Business Continuity Plan (BCP) keeps essential business functions running during/after a disruption (broad, business-focused); a Disaster Recovery Plan (DRP) focuses on restoring IT systems, data, and infrastructure (technical subset).

  10. Compare hot, warm, and cold recovery sites.

    A hot site is fully equipped and operational for near-immediate failover; a warm site has hardware/connectivity but needs data and configuration (hours to days); a cold site provides only space and utilities, requiring full setup (longest recovery, lowest cost).

  11. Why must incident response, BCP, DRP, and crisis management plans be integrated?

    Because a major incident can escalate into a continuity event; integrated, consistent plans ensure smooth escalation, coordinated roles, shared communication, and a unified response without gaps or conflicts.

  12. Why must incident response plans be regularly reviewed and maintained?

    To keep them current with changes in technology, business processes, threats, personnel, and regulations, and to incorporate lessons learned so the plan remains effective and accurate.

  13. What triggers an update to the incident response plan outside scheduled reviews?

    Significant changes such as new systems/architecture, organizational restructuring, mergers, new regulatory requirements, emerging threats, or findings from incidents and exercises (lessons learned).

  14. What is the primary purpose of incident communication and notification procedures?

    To ensure timely, accurate, and appropriate information flows to the right internal and external stakeholders during an incident, supporting coordinated response, legal compliance, and reputation management.

  15. Why are predefined communication channels and contact lists important during incident response?

    Because normal channels (e.g., email) may be compromised or unavailable; out-of-band, predefined channels and up-to-date contact lists ensure reliable, secure, and rapid communication during a crisis.

  16. What external parties may need to be notified during a security incident?

    Regulators/supervisory authorities, affected customers/data subjects, law enforcement, business partners, cyber-insurance providers, and potentially the public/media—depending on legal and contractual obligations.

  17. Why are breach notification regulatory timelines (e.g., GDPR's 72 hours) important to incident management?

    Many laws mandate notifying authorities and affected individuals within strict deadlines; the incident plan must build in detection, assessment, and notification processes to meet these timelines and avoid penalties.

  18. What is the purpose of a post-incident review (lessons-learned/post-mortem)?

    To analyze how the incident was handled, identify root causes and response gaps, and produce actionable improvements to controls, processes, and the response plan to prevent recurrence.

  19. What questions should a post-incident review answer?

    What happened and when, how well did staff and the plan perform, what information was needed sooner, what would be done differently, what corrective actions are needed, and how to prevent recurrence.

  20. What are common metrics/KPIs used to evaluate incident response effectiveness?

    Mean Time to Detect (MTTD), Mean Time to Respond/Contain (MTTR/MTTC), number and type of incidents, dwell time, cost/impact per incident, and percentage of incidents resolved within SLA.

  21. Why should the root cause—not just the symptoms—be addressed after an incident?

    Treating only symptoms leaves the underlying vulnerability or weakness in place, allowing recurrence; root-cause remediation strengthens controls and prevents repeat incidents.

  22. Why are incident response plans tested and exercised regularly?

    To validate the plan's effectiveness, train staff on their roles, identify gaps and weaknesses before a real incident, and confirm tools, communications, and procedures work as intended.

  23. Compare a tabletop exercise with a full-scale (functional/simulation) test.

    A tabletop is a discussion-based walkthrough where the team talks through their response to a scenario (low cost, low disruption); a full-scale test actually executes the response with real systems and resources (more realistic, more costly and disruptive).

  24. What is the difference between a checklist/walkthrough review and a parallel/full-interruption continuity test?

    A checklist/walkthrough reviews plan completeness on paper; a parallel test brings up recovery systems alongside production without stopping it; a full-interruption test actually shifts operations to recovery systems, providing the most realistic but highest-risk validation.

What this deck covers

The Information Security Incident Management deck follows the Certified Information Security Manager (CISM) Information Security Incident Management syllabus — 4 chapters and 14 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 15.3 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 201 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security Incident Management flashcards FAQ

How many Information Security Incident Management flashcards are in this Certified Information Security Manager (CISM) deck?

61 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Security Manager (CISM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 61-card deck is free inside the Examius app.

What do the Information Security Incident Management cards cover?

They follow the Certified Information Security Manager (CISM) Information Security Incident Management syllabus — 4 chapters and 14 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.