🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards

CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts Flashcards

50 question-and-answer cards covering Information Security Management Principles and Concepts as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

50Cards in deck
24Free preview
12Syllabus topics
~158Chars per answer
FreePrice

24 sample cards from the Information Security Management Principles and Concepts deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. In the PDCA cycle, what happens in the 'Act' phase?

    Maintain and improve the ISMS: take corrective and preventive actions based on review results to achieve continual improvement.

  2. What is 'continual improvement' in the context of an ISMS?

    A recurring activity to enhance performance, ensuring the ISMS adapts to changing threats, business needs and review findings over time.

  3. Define information security governance.

    The system of directing and controlling information security activities, by which the board and senior management provide strategic direction, ensure objectives are met, manage risk and use resources responsibly.

  4. Who holds ultimate accountability for information security in an organisation?

    The board of directors / top (senior) management; security is a board-level governance responsibility that cannot be fully delegated.

  5. What is the typical role of a CISO (Chief Information Security Officer)?

    Senior executive responsible for developing and implementing the information security programme, strategy, policy and risk management across the organisation.

  6. What is the role of an 'information asset owner'?

    The individual accountable for a specific information asset, responsible for its classification, acceptable use, and ensuring appropriate controls are applied.

  7. Differentiate between a data owner and a data custodian.

    The data owner is accountable for the data and decides classification/access; the custodian is responsible for the day-to-day technical safeguarding and maintenance of that data.

  8. What is the role of the SIRO (Senior Information Risk Owner), common in UK public sector?

    A board-level executive who owns the organisation's information risk policy, acts as champion for information risk, and provides assurance to the board.

  9. What is meant by a 'security culture' within an organisation?

    The shared attitudes, values, behaviours and norms regarding security that influence how staff protect information in their daily work.

  10. Why is human behaviour considered critical to information security?

    People are often the weakest link; many incidents stem from human error, negligence or manipulation (e.g. social engineering), so awareness and behaviour are key controls.

  11. What is the purpose of security awareness, training and education programmes?

    To change behaviour and build a positive security culture by ensuring staff understand threats, policies and their responsibilities for protecting information.

  12. What is an ISMS (Information Security Management System)?

    A systematic, risk-based framework of policies, procedures, processes and controls for managing an organisation's information security, based on the PDCA continual improvement approach.

  13. State the primary purpose and scope of an ISMS.

    To preserve the confidentiality, integrity and availability of information by applying a risk management process, giving stakeholders confidence that risks are adequately managed; scope defines the boundaries (assets, locations, units) it covers.

  14. Which ISO/IEC standard specifies the requirements for an ISMS and is certifiable?

    ISO/IEC 27001 — the standard against which organisations are audited and certified.

  15. What is the role of ISO/IEC 27002?

    A code of practice / guidance providing a catalogue of information security controls and implementation advice; it supports 27001 but is not itself certifiable.

  16. Key difference between ISO/IEC 27001 and ISO/IEC 27002?

    27001 states mandatory ISMS requirements (the 'what' you must do to be certified); 27002 gives detailed guidance on selecting and implementing controls (the 'how').

  17. What is a Statement of Applicability (SoA) in ISO/IEC 27001?

    A documented statement listing the controls selected (and excluded), the justification for inclusions/exclusions, and their implementation status.

  18. Which broad family of standards covers information security management systems?

    The ISO/IEC 27000 series (27000 provides the overview and vocabulary, 27001 the requirements, 27002 the controls, etc.).

  19. What is the difference between certification and accreditation?

    Certification is the formal third-party attestation that an organisation/system conforms to a standard (e.g. 27001); accreditation is the formal authority granted to a certification body (or, for systems, formal management approval to operate at an accepted risk level).

  20. In the UK, which body accredits certification bodies that issue ISO/IEC 27001 certificates?

    UKAS — the United Kingdom Accreditation Service.

  21. Define an information security 'policy'.

    A high-level document stating management's intentions, principles and direction for information security; mandatory and approved by senior management.

  22. Define a 'standard' in the policy hierarchy.

    A mandatory rule specifying uniform, measurable requirements (e.g. specific technologies or configurations) that support and enforce the policy.

  23. Differentiate a 'procedure' from a 'guideline'.

    A procedure is a mandatory, step-by-step set of instructions for performing a task; a guideline is recommended, non-mandatory best-practice advice offering flexibility.

  24. Place policy, standards, procedures and guidelines in their hierarchical order from highest to lowest.

    Policy (top, high-level intent) → Standards (mandatory requirements) → Procedures (mandatory step-by-step actions) and Guidelines (optional recommendations) at the operational level.

What this deck covers

The Information Security Management Principles and Concepts deck follows the CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts syllabus — 3 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.7 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 158 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Security Management Principles and Concepts flashcards FAQ

How many Information Security Management Principles and Concepts flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?

50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CISMP (Certificate in Information Security Management Principles) flashcards free?

Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.

What do the Information Security Management Principles and Concepts cards cover?

They follow the CISMP (Certificate in Information Security Management Principles) Information Security Management Principles and Concepts syllabus — 3 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.