🇺🇸 Certified Information Security Manager (CISM) · flashcards

Certified Information Security Manager (CISM) Information Security Program Development and Management Flashcards

51 question-and-answer cards covering Information Security Program Development and Management as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
15Syllabus topics
~191Chars per answer
FreePrice

24 sample cards from the Information Security Program Development and Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is the role of a Public Key Infrastructure (PKI)?

    To manage digital certificates and public-key encryption—including a Certificate Authority (CA), Registration Authority (RA), certificate issuance, distribution, revocation (CRL/OCSP), and trust binding of keys to identities.

  2. What is data classification and why is it foundational to data protection?

    The process of categorizing data by sensitivity/criticality (e.g., public, internal, confidential, restricted) so that appropriate, proportionate handling and protection controls can be applied.

  3. What is Data Loss Prevention (DLP)?

    A set of technologies and processes that detect and prevent unauthorized exfiltration or disclosure of sensitive data across endpoints, networks, and storage, based on content/classification policies.

  4. What security challenges are introduced by cloud computing's shared responsibility model?

    Security duties are split between provider and customer (varying by IaaS/PaaS/SaaS); misunderstanding the boundary leads to gaps. Customers always retain responsibility for data, identities, and access governance.

  5. What security concerns are associated with IoT devices?

    Weak/default credentials, limited patching capability, large attack surface, lack of encryption, weak physical security, and difficulty in inventory and lifecycle management.

  6. What is a key security consideration when adopting AI/machine learning systems?

    Risks include data poisoning, model/prompt manipulation, training-data privacy leakage, bias, and adversarial inputs; governance over data sourcing, model integrity, and output validation is required.

  7. Why must security be embedded early in DevOps (DevSecOps)?

    Because rapid, automated CI/CD pipelines can deploy vulnerabilities quickly; integrating automated security testing and 'shift-left' practices catches issues early and reduces cost of remediation.

  8. What is the primary objective of a security awareness program?

    To change behavior and build a security-conscious culture so personnel recognize, avoid, and report threats—reducing human-factor risk such as phishing and social engineering.

  9. What is the difference between awareness, training, and education?

    Awareness focuses attention to change behavior (the 'what'); training teaches specific job skills (the 'how'); education provides deeper conceptual understanding (the 'why'), often for security professionals.

  10. How should the effectiveness of a security awareness program be measured?

    Through metrics such as phishing simulation click/report rates, incident reporting rates, training completion, policy acknowledgment, and trends in human-error incidents over time.

  11. What is the difference between policies, standards, procedures, and guidelines?

    Policies are high-level mandatory intent; standards are mandatory specific requirements/metrics; procedures are step-by-step mandatory instructions; guidelines are recommended, non-mandatory best practices.

  12. What is a baseline in the context of security standards?

    A minimum mandatory level of security configuration or control that a system, platform, or process must meet (e.g., a hardened OS configuration baseline).

  13. Why is stakeholder engagement critical to security program success?

    Stakeholders provide funding, authority, and adoption; engaging them builds buy-in, aligns the program to business needs, resolves conflicts, and ensures controls are accepted rather than circumvented.

  14. What is the difference between a metric and a Key Performance Indicator (KPI)?

    A metric is any measured value; a KPI is a selected metric tied to a critical objective that indicates how well the program is performing against its goals.

  15. What is a Key Risk Indicator (KRI) and how does it differ from a KPI?

    A KRI is a forward-looking metric signaling increasing risk exposure (predictive), while a KPI measures performance/achievement of objectives (often retrospective).

  16. What makes a security metric effective (SMART criteria)?

    It should be Specific, Measurable, Attainable, Relevant, and Timely—plus meaningful to its audience, actionable, and tied to objectives rather than just activity counts.

  17. What is the difference between control testing and control validation?

    Control testing checks whether a control is implemented and operating as designed; validation confirms the control actually achieves its intended risk-reduction objective (effectiveness vs. mere existence).

  18. What is the difference between vulnerability assessment and penetration testing?

    A vulnerability assessment identifies and catalogs weaknesses (broad, automated, no exploitation); a penetration test actively exploits weaknesses to demonstrate real-world impact (focused, often manual).

  19. What is the difference between testing control 'design effectiveness' and 'operating effectiveness'?

    Design effectiveness asks whether the control, if operating, would meet its objective; operating effectiveness asks whether it actually functioned consistently over a period of time.

  20. What is the difference between an internal audit and an external audit?

    Internal audits are conducted by the organization's own auditors for management assurance and improvement; external audits are performed by independent third parties for objective assurance to regulators, customers, or boards.

  21. What is the difference between compliance and security?

    Compliance is meeting external/internal mandatory requirements (laws, regulations, standards); security is actual protection of assets. Being compliant does not guarantee being secure, and vice versa.

  22. What is a gap analysis in audit and compliance management?

    A systematic comparison of the current state against a required standard, framework, or regulation to identify deficiencies that must be remediated, prioritized by risk.

  23. What is continuous improvement in a security program, and which model supports it?

    An ongoing cycle of measuring, learning, and enhancing the program based on metrics, audits, and incidents. The Plan-Do-Check-Act (PDCA) cycle is the classic model supporting it.

  24. What is a maturity model and how is it used for continuous improvement?

    A model (e.g., CMMI) that rates capability across defined levels from ad hoc to optimized; it benchmarks current maturity, sets target maturity, and guides prioritized improvement of processes.

What this deck covers

The Information Security Program Development and Management deck follows the Certified Information Security Manager (CISM) Information Security Program Development and Management syllabus — 4 chapters and 15 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 12.8 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 191 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security Program Development and Management flashcards FAQ

How many Information Security Program Development and Management flashcards are in this Certified Information Security Manager (CISM) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Security Manager (CISM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Information Security Program Development and Management cards cover?

They follow the Certified Information Security Manager (CISM) Information Security Program Development and Management syllabus — 4 chapters and 15 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.