🇺🇸 Certified Information Security Manager (CISM) · flashcards

Certified Information Security Manager (CISM) Information Security Risk Response and Reporting Flashcards

51 question-and-answer cards covering Information Security Risk Response and Reporting as it is examined in Certified Information Security Manager (CISM). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
9Syllabus topics
~166Chars per answer
FreePrice

24 sample cards from the Information Security Risk Response and Reporting deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is a Key Risk Indicator (KRI)?

    A metric that provides an early warning signal of increasing risk exposure, often with thresholds that trigger escalation when breached.

  2. What characteristics make an effective KRI?

    Measurable, relevant/linked to a specific risk, predictive (leading indicator), reliable, and tied to defined thresholds for action.

  3. What is the difference between a KRI and a KPI?

    A KRI signals the level/likelihood of risk (early warning of exposure), while a KPI measures performance against business objectives. A KRI may be derived from KPI thresholds.

  4. What is the difference between a KRI and a KCI?

    A KRI indicates the level of risk exposure; a KCI indicates how well a specific control is performing. A failing KCI can drive a worsening KRI.

  5. What events should trigger a reassessment of a previously assessed risk?

    Significant changes such as new threats/vulnerabilities, major system or business process changes, mergers, new regulations, incidents, or audit findings.

  6. What is 'continuous monitoring' in risk management?

    The ongoing, often automated collection and analysis of control and risk data to maintain near-real-time awareness of the organization's risk posture.

  7. What is a risk register?

    A central repository/document that records identified risks along with their description, owner, assessment (likelihood/impact), treatment, status, and residual risk.

  8. What are the essential data elements typically captured for each entry in a risk register?

    Risk ID/description, owner, likelihood and impact, inherent and residual risk ratings, treatment/response, controls, status, and review date.

  9. What is the primary purpose of maintaining a risk register?

    To provide a single, current view of the organization's risks for prioritization, tracking treatment, accountability, and management reporting/decision-making.

  10. Why must a risk register be kept current ('living document')?

    Because outdated entries lead to poor decisions; risks, controls, and residual levels change, and the register supports ongoing monitoring and reporting.

  11. What is 'aggregate risk' and why does the register help reveal it?

    Aggregate risk is the combined exposure from multiple individual risks that may be acceptable alone but significant together; a register lets management view and total exposures across the organization.

  12. What is the primary purpose of risk reporting to senior management and the board?

    To communicate the organization's risk posture in business terms so leaders can make informed decisions on resource allocation and risk acceptance.

  13. Why should risk reports be tailored to the audience?

    Because executives/board need concise, business-impact and trend information for decisions, while operational staff need detailed technical metrics; reporting must match the audience's needs and authority.

  14. What is risk escalation and when should a risk be escalated?

    Escalation is raising a risk to a higher authority for decision/action. It occurs when a risk exceeds the owner's tolerance/authority, breaches a KRI threshold, or requires resources/acceptance beyond the owner's level.

  15. What visualization tool commonly summarizes risk levels for management reporting?

    A risk heat map (risk matrix) plotting likelihood against impact, using color coding to prioritize risks.

  16. Why must risk reporting be timely and consistent?

    So decisions are based on current information and trends can be compared over time; inconsistent or late reporting undermines credibility and decision quality.

  17. At what stage of the SDLC is it most cost-effective to address security risk?

    As early as possible — in the requirements/design phases — because fixing security flaws later (testing/production) is far more expensive and disruptive ('shift left').

  18. What is 'security by design'?

    Integrating security requirements and controls into every SDLC phase from the start, rather than adding security after development is complete.

  19. In the SDLC, what security activity belongs in the requirements/design phase?

    Defining security and compliance requirements, performing threat modeling, and conducting a risk assessment to drive control selection in the design.

  20. What security control gate should occur before a system moves into production?

    Security testing/assessment and formal authorization (certification and accreditation / sign-off) confirming residual risk is acceptable before go-live.

  21. What is the most important risk concern in the disposal/decommission phase of the SDLC?

    Secure data sanitization/destruction and proper disposal of media to prevent disclosure of residual sensitive information.

  22. In a third-party/cloud arrangement, can an organization transfer accountability for its data risk to the provider?

    No. Responsibility for a control can be shared, but ultimate accountability for protecting the organization's data and meeting compliance remains with the organization.

  23. What is the 'shared responsibility model' in cloud computing?

    A division of security duties where the cloud provider secures the underlying infrastructure ('security of the cloud') and the customer secures their data, access, and configurations ('security in the cloud'), varying by IaaS/PaaS/SaaS.

  24. What should be evaluated before onboarding a third party, and what contractual element governs ongoing security expectations?

    Perform third-party due diligence/risk assessment (security posture, financials, compliance); govern via contracts with security requirements, SLAs, right-to-audit clauses, and breach-notification obligations. Foster a risk-aware culture so security becomes part of everyday behavior and decisions.

What this deck covers

The Information Security Risk Response and Reporting deck follows the Certified Information Security Manager (CISM) Information Security Risk Response and Reporting syllabus — 3 chapters and 9 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 166 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security Risk Response and Reporting flashcards FAQ

How many Information Security Risk Response and Reporting flashcards are in this Certified Information Security Manager (CISM) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Security Manager (CISM) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Information Security Risk Response and Reporting cards cover?

They follow the Certified Information Security Manager (CISM) Information Security Risk Response and Reporting syllabus — 3 chapters and 9 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.