🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards

CISMP (Certificate in Information Security Management Principles) Information Risk Management Flashcards

51 question-and-answer cards covering Information Risk Management as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
12Syllabus topics
~200Chars per answer
FreePrice

24 sample cards from the Information Risk Management deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is a 'risk matrix' (heat map) and how is it used?

    A grid plotting likelihood against impact, each cell coloured (typically red/amber/green) to show risk severity. It supports qualitative risk evaluation and prioritisation.

  2. List the four main risk treatment options.

    1) Treat/Modify (reduce via controls), 2) Tolerate/Accept (retain the risk), 3) Transfer/Share (e.g. insurance, outsourcing), 4) Terminate/Avoid (stop the activity). Often remembered as the '4 Ts'.

  3. What does 'risk transfer' (sharing) involve, and does it remove all risk?

    Passing some or all of the risk to a third party, e.g. via insurance or outsourcing. It does not remove accountability/residual risk — reputational and legal responsibility usually remain with the organisation.

  4. When is 'risk avoidance' (terminate) appropriate?

    When a risk is unacceptable and cannot be cost-effectively reduced or transferred — the organisation withdraws from, or chooses not to start, the activity that gives rise to the risk.

  5. What is risk acceptance (tolerate) and what is required for it?

    A decision to retain a risk without further treatment, usually because it falls within risk appetite or treatment is not cost-effective. It requires formal, documented sign-off by the appropriate risk owner/management.

  6. Who is a 'risk owner'?

    The person or entity with the accountability and authority to manage a particular risk — responsible for ensuring it is treated appropriately and for accepting residual risk.

  7. Define 'stakeholder' in the risk management context.

    Any person or organisation that can affect, be affected by, or perceive themselves to be affected by a risk or a risk decision — e.g. senior management, staff, customers, regulators, suppliers, shareholders.

  8. What is the SIRO (Senior Information Risk Owner) and where is the role common?

    A board-level executive accountable for an organisation's information risk overall, championing information risk management and owning the information risk policy. The role is common in UK government/public sector.

  9. What is an Information Asset Owner (IAO)?

    An individual accountable for a specific information asset — understanding what information is held, how it is used and shared, and ensuring risks to that asset are managed and reported to the SIRO.

  10. What is the purpose of 'risk monitoring and review'?

    To ensure risk assessments remain current and controls remain effective — detecting changes in threats, vulnerabilities, assets, context or appetite, and confirming treatments are working. Risk management is a continuous, iterative cycle.

  11. Name events that should trigger a review of a risk assessment.

    Significant changes to the business, new technology or systems, new or changed threats, security incidents, audit findings, changes in legislation/regulation, or expiry of a defined review period.

  12. What is a 'risk register'?

    A documented record of identified risks including their description, owner, likelihood, impact, risk level, chosen treatment, controls, residual risk and review status. It is a key monitoring and reporting tool.

  13. Which ISO/IEC standard provides guidance specifically on information security risk management?

    ISO/IEC 27005 — it provides guidelines for information security risk management and supports the implementation of an ISMS based on ISO/IEC 27001.

  14. How does ISO/IEC 27005 relate to ISO/IEC 27001 and ISO 31000?

    ISO/IEC 27005 gives detailed information-security-specific risk guidance supporting the ISMS requirements of ISO/IEC 27001, and aligns with the generic, organisation-wide risk management framework of ISO 31000.

  15. What is ISO 31000?

    An international standard providing principles, a framework and a process for managing risk of any kind across an organisation. It is generic (not IT-specific) and underpins sector standards like ISO/IEC 27005.

  16. What does ISO/IEC 27001 require regarding risk?

    It requires organisations to establish a risk assessment and risk treatment process, define risk criteria, produce a Statement of Applicability, and obtain risk owners' approval of the risk treatment plan and acceptance of residual risks.

  17. What is the NIST framework most associated with risk management, and its key publications?

    The NIST Risk Management Framework (RMF), supported by SP 800-30 (risk assessment guidance), SP 800-37 (the RMF process) and SP 800-39 (managing information security risk).

  18. Name recognised risk management methodologies/frameworks used in information security.

    ISO/IEC 27005, ISO 31000, NIST RMF (SP 800-30/37/39), OCTAVE, COSO ERM, and historically the UK government method CRAMM.

  19. What is a Statement of Applicability (SoA) in ISO/IEC 27001?

    A documented statement listing the Annex A controls, whether each is applied, the justification for inclusion or exclusion, and the implementation status — linking selected controls to the risk treatment plan.

  20. What does 'cost-benefit analysis' mean when selecting controls?

    Comparing the cost of implementing and operating a control against the benefit it provides (the reduction in expected loss, e.g. reduction in ALE). A control is justified only if its benefit outweighs its cost.

  21. Define the principle of 'proportionality' in risk treatment.

    Controls and effort should be proportionate to the level of risk and the value of the asset — you should not spend more protecting an asset than the asset (and its risk) is worth, nor under-protect high-value assets.

  22. How do you decide whether a control is cost-justified using ALE?

    Calculate the ALE before and after the control; the annual benefit is the reduction in ALE. The control is justified if: $$(\text{ALE}_{\text{before}} - \text{ALE}_{\text{after}}) > \text{annual cost of control}$$

  23. In the context of accreditation, what is 'accreditation' (authorisation to operate)?

    The formal management decision and authorisation by a senior responsible owner to operate a system, having reviewed and explicitly accepted the residual risks against defined security requirements.

  24. What is the difference between accreditation and certification?

    Certification is the technical assessment confirming a system meets defined security requirements/controls; accreditation is the management decision to accept the residual risk and authorise the system to operate based on that certification evidence.

What this deck covers

The Information Risk Management deck follows the CISMP (Certificate in Information Security Management Principles) Information Risk Management syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 200 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Risk Management flashcards FAQ

How many Information Risk Management flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CISMP (Certificate in Information Security Management Principles) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Information Risk Management cards cover?

They follow the CISMP (Certificate in Information Security Management Principles) Information Risk Management syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.