🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards

CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance Flashcards

61 question-and-answer cards covering Business Continuity, Incident Management and Assurance as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

61Cards in deck
24Free preview
12Syllabus topics
~206Chars per answer
FreePrice

24 sample cards from the Business Continuity, Incident Management and Assurance deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Why must business continuity and disaster recovery plans be regularly tested?

    To validate that plans actually work, that recovery objectives (RTO/RPO) are achievable, to train staff, and to identify gaps before a real disaster occurs.

  2. Compare a 'tabletop exercise' (desktop walkthrough) with a 'full-scale/live test' of a BC plan.

    A tabletop exercise is a discussion-based walkthrough of the plan against a scenario — low cost, no disruption. A full-scale/live test actually invokes recovery (e.g. failing over to the DR site) — most realistic but costly and potentially disruptive.

  3. Name the common escalating levels of BC/DR plan testing.

    Plan review/checklist; tabletop (desktop) exercise; walkthrough/simulation; parallel test (recovery runs alongside live); and full interruption (live) test.

  4. Why must BC and DR plans be maintained, and what events should trigger an update?

    To keep them accurate as the organisation changes. Triggers include changes in business processes, technology, staff/contacts, suppliers, premises, after a test, or after a real incident.

  5. How does incident management relate to information security's CIA triad?

    Incidents threaten Confidentiality, Integrity and/or Availability. Incident management and business continuity primarily protect Availability (and Integrity), restoring service and limiting CIA breaches.

  6. What is the relationship between business continuity and risk management?

    Risk management identifies and assesses threats and their likelihood/impact; BCM is a treatment/response that builds resilience and recovery capability for risks that cannot be fully eliminated, especially high-impact disruptive ones.

  7. Define 'security assurance'.

    The grounds for confidence that an entity (system, control or organisation) meets its security objectives and that controls are correctly implemented, operating effectively and achieving the desired outcome.

  8. Distinguish a vulnerability assessment from a penetration test.

    A vulnerability assessment identifies and reports known weaknesses, typically using automated scanning, broad coverage, no exploitation. A penetration test actively attempts to exploit weaknesses to demonstrate real-world impact and depth.

  9. What is the difference between an audit and a penetration test as assurance methods?

    An audit checks compliance of controls/processes against a standard, policy or requirement (evidence-based review). A penetration test technically attacks systems to find and exploit exploitable security weaknesses.

  10. Compare black-box, white-box and grey-box penetration testing.

    Black-box: tester has no prior knowledge (simulates outsider). White-box: tester has full knowledge (source code, architecture, credentials). Grey-box: tester has partial knowledge (e.g. standard user access).

  11. What is the UK 'Cyber Essentials' scheme and how does it relate to assurance?

    A UK government-backed certification scheme defining baseline technical controls against common internet threats. Cyber Essentials is self-assessment; Cyber Essentials Plus adds independent technical verification, providing greater assurance.

  12. What is the difference between a Type I and Type II assurance report (e.g. SOC reports)?

    A Type I report assesses the design/suitability of controls at a point in time. A Type II report assesses both design and operating effectiveness of controls over a period of time, giving stronger assurance.

  13. What is the role of internal audit versus external (independent) audit in security assurance?

    Internal audit provides ongoing, in-house assurance to management on control effectiveness. External/independent audit provides objective, impartial assurance to stakeholders and can support certification or regulatory confidence.

  14. In an investigation, why is it important to preserve evidence and follow due process before any disciplinary action?

    To ensure findings are fair, defensible and legally sound — protecting evidence integrity, the rights of the accused, and avoiding unfair dismissal claims or rejection of evidence in court or tribunal.

  15. What is the danger of acting on a suspected insider incident without HR and Legal involvement?

    Improper handling can breach employment law and data protection rules, compromise evidence, expose the organisation to legal claims (e.g. unfair dismissal), and prejudice any subsequent prosecution.

  16. What is the difference between a security 'metric' and a Key Performance Indicator (KPI)?

    A metric is any measurement of a security attribute (e.g. number of incidents). A KPI is a selected metric tied to an objective/target that indicates how well a goal is being achieved.

  17. Define Mean Time To Detect (MTTD) and Mean Time To Respond/Recover (MTTR).

    MTTD is the average time taken to detect an incident after it occurs. MTTR is the average time taken to respond to and recover from an incident. $MTTR = \frac{\text{total recovery time}}{\text{number of incidents}}$.

  18. What is a Key Risk Indicator (KRI) and how does it differ from a KPI?

    A KRI is a forward-looking metric signalling increasing exposure to a risk (e.g. rising number of unpatched systems). A KPI measures performance against an objective. KRIs warn of risk; KPIs measure achievement.

  19. Why should security metrics be tailored to their audience (e.g. technical team vs board)?

    Different audiences need different detail and framing: technical teams need operational detail to act, while the board needs concise, business-risk-oriented information to make strategic and resourcing decisions.

  20. What makes a security metric effective (a common set of criteria)?

    It should be SMART-like: Specific, Measurable, Actionable/Achievable, Relevant and Timely — objective, repeatable, and clearly linked to a security objective or decision.

  21. What is 'continual improvement' in an information security management context?

    The ongoing, iterative enhancement of the ISMS, controls and processes — using feedback from audits, incidents, metrics and reviews to progressively reduce risk and improve effectiveness.

  22. Describe the Plan-Do-Check-Act (PDCA) cycle and its role in continual improvement.

    Plan: establish objectives and controls. Do: implement them. Check: monitor, measure and audit performance. Act: take corrective/improvement actions. The cycle repeats, driving continual improvement of the ISMS (e.g. in ISO/IEC 27001).

  23. What is the difference between 'corrective action' and 'preventive action' in an ISMS?

    Corrective action eliminates the cause of a detected nonconformity/incident to stop it recurring. Preventive action addresses potential causes to stop a problem occurring in the first place.

  24. How do incident lessons learned, audit findings and metrics together drive continual improvement?

    They provide evidence of weaknesses and trends; management review evaluates this input and authorises corrective/preventive actions and control changes, feeding the PDCA cycle to continually strengthen security.

What this deck covers

The Business Continuity, Incident Management and Assurance deck follows the CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 20.3 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 206 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Business Continuity, Incident Management and Assurance flashcards FAQ

How many Business Continuity, Incident Management and Assurance flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?

61 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CISMP (Certificate in Information Security Management Principles) flashcards free?

Yes. The preview here is free to read with no signup, and the full 61-card deck is free inside the Examius app.

What do the Business Continuity, Incident Management and Assurance cards cover?

They follow the CISMP (Certificate in Information Security Management Principles) Business Continuity, Incident Management and Assurance syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.