🇺🇸 Certified Information Security Manager (CISM) · flashcards

Certified Information Security Manager (CISM) Information Security Risk Assessment Flashcards

51 question-and-answer cards covering Information Security Risk Assessment as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
10Syllabus topics
~138Chars per answer
FreePrice

24 sample cards from the Information Security Risk Assessment deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is the purpose of an asset inventory in risk assessment?

    To identify and catalog all assets so their value, ownership, and protection requirements can be determined—you cannot protect what you do not know you have.

  2. What are the typical data classification levels in a commercial scheme?

    Commonly: Public, Internal (Private), Confidential, and Restricted (Highly Confidential)—from least to most sensitive.

  3. What are the classification levels used by the U.S. government/military?

    Unclassified, Confidential, Secret, and Top Secret (from lowest to highest sensitivity).

  4. What three factors typically determine an asset's classification?

    The asset's value, sensitivity, and criticality—based on the impact of compromise to confidentiality, integrity, or availability.

  5. Who is the 'data owner' and what is their classification responsibility?

    The data owner is a senior/business role accountable for the data; they determine its classification level and authorize access.

  6. What is the difference between a data owner and a data custodian?

    The data owner decides classification and access (accountable); the data custodian implements and maintains controls/backups day-to-day (responsible for protection).

  7. What is the primary purpose of a Business Impact Analysis (BIA)?

    To identify critical business functions and the impact of their disruption over time, establishing recovery priorities and requirements.

  8. Define Recovery Time Objective (RTO).

    RTO is the maximum acceptable length of time to restore a business process or system after a disruption before unacceptable consequences occur.

  9. Define Recovery Point Objective (RPO).

    RPO is the maximum acceptable amount of data loss measured in time—how far back data must be recoverable, determining backup frequency.

  10. What is Maximum Tolerable Downtime (MTD)?

    MTD is the total time a business function can be unavailable before the organization suffers irreparable harm; it bounds the sum of RTO and recovery work.

  11. How does a BIA relate to risk assessment?

    The BIA quantifies the impact (criticality) of asset/process loss, providing the impact input that risk assessment combines with likelihood to prioritize risks.

  12. List the typical stages of the data lifecycle.

    Create/Collect, Store, Use, Share/Transmit, Archive/Retain, and Destroy/Dispose.

  13. Why must protection needs be assessed at each stage of the data lifecycle?

    Because data faces different threats and requires different controls (e.g., encryption in transit vs. at rest, secure disposal) at each stage.

  14. What control protects data 'at rest' versus 'in transit'?

    Data at rest is protected by storage/disk encryption and access controls; data in transit is protected by transport encryption such as TLS/VPN.

  15. What is 'data remanence' and why is it a risk?

    Data remanence is residual data remaining on storage media after deletion; it is a risk because sensitive data can be recovered if media is not properly sanitized.

  16. Name common risk identification methods.

    Brainstorming, interviews, checklists, document/asset reviews, threat modeling, vulnerability scanning, and reviewing historical incident data.

  17. What is the Delphi technique in risk identification?

    An anonymous, iterative method where experts independently provide input and feedback is consolidated over rounds to reach consensus without dominant-personality bias.

  18. What is threat modeling (e.g., STRIDE) used to identify?

    It systematically identifies potential threats to a system. STRIDE = Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

  19. Differentiate quantitative and qualitative risk analysis.

    Quantitative analysis assigns numeric/monetary values (e.g., ALE) to risk; qualitative analysis uses descriptive ratings (high/medium/low) based on judgment.

  20. State the formula for Single Loss Expectancy (SLE).

    SLE = Asset Value (AV) × Exposure Factor (EF), where EF is the percentage of asset value lost in a single incident.

  21. State the formula for Annualized Loss Expectancy (ALE).

    ALE = SLE × ARO (Annualized Rate of Occurrence), giving the expected monetary loss per year from a risk.

  22. What is the Exposure Factor (EF) and Annualized Rate of Occurrence (ARO)?

    EF is the proportion (%) of an asset's value lost in a single event; ARO is the estimated number of times the event is expected to occur per year.

  23. What is the formula used to evaluate and rank risk for prioritization?

    Risk = Likelihood × Impact (often plotted on a risk matrix/heat map to rank and prioritize risks for treatment).

  24. What are the four main risk treatment (response) options after evaluation?

    Risk avoidance (eliminate), risk mitigation/reduction (apply controls), risk transfer (e.g., insurance/outsourcing), and risk acceptance (retain within tolerance).

What this deck covers

The Information Security Risk Assessment deck follows the Certified Information Security Manager (CISM) Information Security Risk Assessment syllabus — 3 chapters and 10 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 138 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security Risk Assessment flashcards FAQ

How many Information Security Risk Assessment flashcards are in this Certified Information Security Manager (CISM) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Security Manager (CISM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Information Security Risk Assessment cards cover?

They follow the Certified Information Security Manager (CISM) Information Security Risk Assessment syllabus — 3 chapters and 10 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.