StudyToCert

All certifications / CISM / Cheat sheet

CISM 2026 exam content outline cheat sheet

Every exam tip and key term from the free CISM lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Information security governance (18%)

Exam tips

Key terms

Governance
Direction and oversight by the board and executives: setting objectives, risk appetite and accountability, and monitoring results.
Management
Planning, building, running and monitoring activities within the direction set by governance.
Accountability
The obligation to answer for an outcome; it cannot be delegated, even when responsibility for the work is.
Responsibility
The duty to carry out a task or operate a control, which can be assigned to others.
Strategic alignment
Security goals and spending are derived from, and support, the organization's business objectives.
Value delivery
Achieving security outcomes at a cost that is justified by the business benefit they provide.
Senior management commitment
Visible leadership support through approved strategy, funding and personal example, the key success factor for a security program.
Security culture
The shared attitudes and habits that determine whether people behave securely when no one is checking.
Tone at the top
The example and priorities set by senior leaders, which strongly shape employee behavior.
Blame-free reporting
A practice where people can report mistakes and incidents without fear of punishment, so problems surface early.
Security champion
A volunteer in a business or technical team who receives extra training and promotes secure practices locally.
Workaround
An unofficial way of getting work done that bypasses a control, often a sign the control does not fit how work happens.
Culture assessment
A structured review of attitudes and behavior, using surveys, interviews and metrics, to find where controls may erode.
Regulatory requirement
An obligation imposed by a law or regulator, usually with penalties for noncompliance.
Contractual requirement
An obligation the organization accepts in an agreement, such as PCI DSS through card brand contracts.
Data localization
A legal requirement that certain data be stored or processed within a specific country.
Compliance register
A maintained list of applicable obligations, what they require, where they apply and who owns them.
Right to audit
A contract clause allowing the customer or its auditors to verify a provider's controls.
Principle-based requirement
A rule that states an outcome, such as appropriate security, and leaves the organization to justify its controls by risk.
Board of directors
The body that sets overall direction and risk appetite and is ultimately accountable for the organization.
Steering committee
A cross-functional group of senior leaders that prioritizes and oversees security initiatives.
Chief information security officer (CISO)
The executive responsible for designing and running the information security program and reporting on risk.
Data owner
A business manager accountable for an information asset, including its classification and access approvals.
Data custodian
The person or team, often IT, that implements and operates the controls the owner has chosen.
RACI
A matrix showing who is responsible, accountable, consulted and informed for each activity.
Internal audit
An independent function that gives the board assurance that controls are designed and operating effectively.
Current state
A documented picture of today's security capabilities, controls and maturity.
Desired state
The target capabilities and risk position needed to support business objectives within appetite.
Gap analysis
A comparison of current and desired state that identifies what must change.
Roadmap
A sequenced, resourced plan of initiatives that closes the prioritized gaps.
Maturity model
A scale that rates how well defined, managed and improved a process is, used to express current and target states.
Constraint
A limit on the strategy, such as budget, staff, culture, law or time, that shapes what can be achieved.
COBIT
ISACA's framework for governance and management of enterprise information and technology.
ISMS
Information security management system: the policies, processes and controls used to manage information security risk, as defined by ISO/IEC 27001.
Statement of applicability
An ISO/IEC 27001 document listing which controls apply, whether they are implemented and why any are excluded.
ISO/IEC 27002
A catalog of information security controls with implementation guidance that supports ISO/IEC 27001 but is not certifiable.
NIST CSF 2.0
A voluntary framework of cybersecurity outcomes organized into Govern, Identify, Protect, Detect, Respond and Recover.
Profile
In NIST CSF, a description of current or target cybersecurity outcomes used to find and prioritize gaps.
Business case
A document that justifies an investment by comparing options, costs, benefits and risks, and states the decision needed.
Capital expenditure (CapEx)
A one-time investment in assets or projects, such as buying hardware or building a system.
Operating expenditure (OpEx)
Ongoing costs such as subscriptions, salaries and managed services.
Total cost of ownership (TCO)
The full cost of a control over its life, including purchase, integration, operation, staff and retirement.
Return on security investment (ROSI)
An estimate of value: the reduction in expected loss, minus the control's cost, relative to that cost.
Resource allocation
Deciding how money, staff time and skills are distributed across initiatives according to priority.
Risk appetite
The amount and type of risk the organization is willing to accept in pursuit of its objectives, set by senior leadership.
Risk tolerance
The acceptable deviation from appetite for a specific objective, often expressed as a measurable threshold.
Risk capacity
The maximum risk an organization can absorb before it can no longer meet its obligations or survive.
Residual risk
The risk that remains after controls are applied.
Risk acceptance criteria
Defined rules stating which risk levels may be accepted and by which level of management.
Escalation
Referring a risk that exceeds someone's authority or the appetite to a higher level for decision.

Domain 2: Information security risk management (20%)

Exam tips

Key terms

Threat landscape
The current set of threat actors, their motives, capabilities and techniques relevant to an organization.
Threat intelligence
Analyzed information about threats that supports decisions, from strategic trends to specific indicators.
ISAC
Information Sharing and Analysis Center: an industry group where members share threat information.
Emerging risk
A new or changing risk whose likelihood or impact is not yet well understood.
Indicator of compromise (IOC)
A technical artifact, such as a malicious domain or file hash, that suggests a system may be compromised.
Horizon scanning
A periodic structured review of trends that could create new risks over the coming years.
Vulnerability
A weakness in an asset, process or control that a threat could exploit.
Control deficiency
A gap where a required control is missing, poorly designed or not operating effectively.
CVSS
Common Vulnerability Scoring System: a standard way to rate the technical severity of vulnerabilities.
CVE
Common Vulnerabilities and Exposures: a public identifier assigned to a specific known vulnerability.
Compensating control
An alternative control that meets the intent of a required control that cannot be implemented.
Design deficiency
A weakness where a control would not meet its objective even if performed perfectly.
Operating deficiency
A weakness where a well-designed control is not performed consistently or correctly.
Single loss expectancy (SLE)
Expected loss from one occurrence: asset value multiplied by exposure factor.
Exposure factor (EF)
The percentage of an asset's value expected to be lost in a single event.
Annualized rate of occurrence (ARO)
How many times per year an event is expected; once every 20 years is 0.05.
Annualized loss expectancy (ALE)
Expected yearly loss: SLE multiplied by ARO.
Heat map
A grid showing likelihood against impact, colored to show risk levels, used in qualitative analysis.
Semi-quantitative analysis
Assigning numeric scores to qualitative categories so risks can be ranked consistently.
FAIR
Factor Analysis of Information Risk: a quantitative model that estimates risk as ranges of loss frequency and magnitude.
Risk scenario
A description of a plausible event in which a threat exploits a vulnerability in an asset and causes a business impact.
Likelihood
The probability or frequency that a scenario will occur within a defined period.
Impact
The consequence of the scenario for the organization, expressed in financial, operational, legal, reputational or safety terms.
Inherent risk
The level of risk before controls are considered.
Residual risk
The level of risk that remains after existing controls are taken into account.
Impact table
A defined scale explaining what each impact level means for each consequence type, used to rate impact consistently.
Risk mitigation
Applying controls to reduce the likelihood or impact of a risk.
Risk transfer
Shifting some financial consequences to a third party, such as an insurer, without transferring accountability.
Risk avoidance
Eliminating a risk by not performing the activity that causes it.
Risk acceptance
An informed, documented decision by an authorized owner to bear a risk.
Treatment plan
A record of the chosen response, actions, owners, deadlines and expected residual risk.
Cyber insurance
A policy that covers some financial costs of security incidents, such as forensics, legal fees and notification.
Risk owner
The person accountable for a risk, with authority to decide its treatment and accept residual risk.
Control owner
The person responsible for designing, operating and evidencing a specific control.
Acceptance authority
The defined level of management permitted to accept risks of a given rating.
Attestation
A control owner's formal confirmation, usually periodic, that a control operated as designed.
Escalation
Referring a risk to a higher level of management when it exceeds the current owner's authority.
Role-based ownership
Assigning ownership to a job role rather than only a named person, so it survives staff changes.
Risk register
A maintained record of identified risks with owners, ratings, responses and status.
Key risk indicator (KRI)
A metric with thresholds that signals increasing risk exposure.
Key performance indicator (KPI)
A metric showing how well a process or control performs against its target.
Threshold
The KRI value at which a predefined action or escalation is triggered.
Leading indicator
A metric that changes before a loss occurs, giving early warning.
Lagging indicator
A metric that reports what has already happened, such as losses or incidents in the last quarter.
Risk monitoring
Ongoing tracking of risks, indicators, controls and events so that decisions stay current.
Risk dashboard
A concise visual summary of top risks, trends, appetite status and key indicators.
Escalation criteria
Predefined conditions that require a risk or event to be reported to a higher level immediately.
Material risk
A risk significant enough to affect the organization's objectives, finances or reputation in a way leadership must know about.
Audit and risk committee
A board committee that oversees internal control, audit and risk on the board's behalf.
Decision request
A clear statement in a report of the approval or direction needed from leadership.
Risk trend
The direction a risk has moved since the last report, with the reason for the change.

Domain 3: Information security program (33%)

Exam tips

Key terms

Information security program
The organized activities, resources and controls that implement the security strategy.
GRC
Governance, risk and compliance: the functions that manage policy, risk and regulatory obligations.
Managed security service
An outsourced security function, such as monitoring or detection, run by a provider under contract.
Skills inventory
A record of the capabilities each role needs and who has them, used to find skill gaps.
Service level agreement (SLA)
A contract term defining the measurable service a provider must deliver, such as response times.
Succession planning
Preparing backup people for critical roles so capabilities do not depend on one person.
Asset inventory
A maintained list of information assets with owners, locations and purposes.
Asset valuation
Estimating an asset's importance by the business impact of losing its confidentiality, integrity or availability.
Classification scheme
A defined set of sensitivity levels with handling rules for each.
Handling requirements
Rules for labeling, storing, transmitting, sharing, retaining and disposing of information at each classification level.
Data loss prevention (DLP)
Tools that detect and block unauthorized movement of sensitive data, usually relying on classification labels or content rules.
Shadow IT
Systems or services adopted by business units without the knowledge or approval of IT and security.
Business impact analysis (BIA)
A study of how disruption to processes and assets would affect the business over time, used to set availability requirements.
Control framework
A structured catalog of controls that organizations select and tailor to their risks.
Tailoring
Adjusting a framework's controls to an organization's specific risks, excluding or adding controls with documented reasons.
Control mapping
Linking internal controls to requirements in multiple frameworks so one control satisfies several obligations.
CIS Critical Security Controls
A prioritized set of technical safeguards grouped into implementation groups.
NIST SP 800-53
A detailed catalog of security and privacy controls with baselines for low, moderate and high impact systems.
SOC 2
An independent assurance report on a service organization's controls, based on trust services criteria.
Enterprise architecture
A description of how business processes, information, applications and technology fit together, now and in a target state.
Security architecture
The structure of security controls and services across the enterprise architecture layers.
Reference architecture
An approved, reusable design pattern that projects follow to meet security and other requirements consistently.
Zero trust
An approach that grants no implicit trust based on network location and verifies every access request.
Defense in depth
Layering multiple independent controls so that the failure of one does not expose the asset.
SABSA
Sherwood Applied Business Security Architecture: a method that derives security architecture from business requirements.
Shared responsibility model
The division of security duties between a cloud provider and its customer.
Policy
A high-level, mandatory statement of management intent and direction, approved by senior management.
Standard
A mandatory, specific requirement, such as a technology, setting or measurable value, that implements a policy.
Baseline
A standard defining the minimum security configuration for a particular platform or system type.
Procedure
Mandatory step-by-step instructions for carrying out a task consistently.
Guideline
Optional, recommended advice that helps people meet policies and standards.
Policy exception
A formally approved, risk-assessed and time-limited deviation from a policy or standard, tracked in a register.
Key performance indicator (KPI)
A measure of whether a process or control is performing to its target.
Key risk indicator (KRI)
A forward-looking measure that signals rising exposure, with thresholds that trigger escalation.
Key goal indicator (KGI)
A measure showing whether a defined goal has been achieved.
SMART metric
A metric that is specific, measurable, attainable, relevant and timely.
Maturity model
A scale that rates how well processes are defined, managed and improved, from ad hoc to optimized.
Vanity metric
A number that looks impressive but does not support any decision or action.
Threshold
A predefined value at which a metric changes status and triggers review or escalation.
Control
Any measure, such as a policy, process, device or practice, that modifies risk.
Control objective
A statement of what a control or set of controls must achieve to address a risk.
Preventive control
A control that stops an unwanted event from occurring.
Detective control
A control that identifies an event while it is happening or after it has occurred.
Corrective control
A control that limits the impact of an event and fixes the underlying problem.
Compensating control
An alternative control that meets the intent of a requirement when the preferred control cannot be used.
Change management
The formal process for requesting, assessing, approving, testing, implementing and recording changes to production.
Change advisory board (CAB)
The group that reviews and approves significant changes.
Emergency change
An urgent change made through an expedited approval path and reviewed afterward.
System development life cycle (SDLC)
The phases a system goes through from requirements and design to operation and retirement.
Configuration management
The practice of keeping systems aligned with approved baselines and detecting and correcting drift.
Control owner
The person accountable for operating and maintaining a control so it stays effective.
Backout plan
Documented steps to return to the previous state if a change fails.
Design effectiveness
Whether a control, as designed, is capable of meeting its objective.
Operating effectiveness
Whether a control actually operates as designed, consistently, over a period.
Inquiry
Asking people how a control works; the weakest form of evidence on its own.
Reperformance
The tester independently executing a control to confirm it produces the correct result; the strongest method.
Sampling
Testing a selected subset of items from a population to draw a conclusion about the whole.
Continuous control monitoring
Automated, ongoing checks that detect control failures quickly between formal tests.
Deficiency
A gap in the design or operation of a control that leaves a risk less well managed than intended.
Security awareness
Activities that help everyone recognize security risks and know how to respond.
Role-based training
Training that builds the specific security skills required for a particular job function.
Security education
Longer-term learning that builds deep understanding, often for security professionals.
Phishing simulation
A controlled, harmless test email used to measure and improve how staff recognize and report phishing.
Report rate
The percentage of recipients who report a suspicious or simulated message to the security team.
Security culture
The shared attitudes and habits that shape how people in an organization treat security.
Third-party risk management (TPRM)
The process of identifying, assessing, contracting for and monitoring risks from external providers.
Due diligence
Investigation of a provider's security, stability and suitability before entering a relationship.
Right to audit
A contract clause allowing the customer to audit the provider or receive independent assurance reports.
SOC 2 Type II report
An independent auditor's report on the design and operating effectiveness of a service organization's controls over a period.
Fourth party
A subcontractor or supplier of your vendor, on which you depend without a direct contract.
Stakeholder
Any person or group affected by, or able to influence, the information security program.
Stakeholder map
A list of stakeholder groups with their interests, influence and preferred communication channels.
Steering committee
A cross-functional group of business and IT leaders that guides and supports the security program.
Escalation trigger
A predefined condition that requires immediate reporting outside the normal schedule.
Security dashboard
A visual summary of key metrics and risks tailored to a particular audience.
Business alignment
Ensuring security activities and messages support the organization's goals and priorities.

Domain 4: Incident management (29%)

Exam tips

Key terms

Incident
An event that threatens the confidentiality, integrity or availability of information or systems, or violates security policy.
Incident response plan (IRP)
The approved document defining how the organization prepares for, detects, responds to and recovers from incidents.
Incident manager
The person who coordinates the response, makes or escalates decisions and keeps the timeline.
Computer security incident response team (CSIRT)
A team with defined responsibility for handling security incidents.
Playbook
A detailed, step-by-step procedure for responding to a specific type of incident.
Incident response retainer
A pre-arranged contract with an external firm to provide response support quickly when needed.
Out-of-band communication
A communication channel separate from potentially compromised systems, used during incidents.
Business impact analysis (BIA)
An analysis that identifies critical processes, their dependencies and the impact of disruption over time.
Maximum tolerable downtime (MTD)
The longest a process can be unavailable before causing unacceptable harm to the organization.
Recovery time objective (RTO)
The target time to restore a process or system after a disruption; it must be less than the MTD.
Recovery point objective (RPO)
The maximum acceptable amount of data loss, measured as time before the disruption.
Work recovery time (WRT)
The time needed after systems are restored to verify data and resume normal work.
Service delivery objective (SDO)
The minimum level of service that must be provided during alternate or degraded operations.
Dependency
A resource, such as a system, supplier or person, that a process needs in order to operate.
Business continuity plan (BCP)
A plan for keeping critical business functions operating or restoring them quickly during and after a disruption.
Business continuity management (BCM)
The ongoing program of governance, analysis, planning, testing and maintenance for continuity.
Continuity strategy
The approach chosen to keep a critical process running, such as an alternate site, remote work or manual workaround.
Activation criteria
The conditions and authority under which a continuity plan is declared and put into action.
Manual workaround
A temporary non-automated way of performing a process while systems are unavailable.
Crisis management
The executive-level coordination of the organization's response to a major disruption, including communications.
Disaster recovery plan (DRP)
A plan for restoring IT systems, data and infrastructure after a disruption to meet recovery targets.
Hot site
A fully equipped recovery site with current systems and data that can take over within minutes to hours.
Warm site
A partly equipped recovery site that needs data restoration and configuration, taking hours to days.
Cold site
A recovery site providing only space, power and cooling, requiring days to weeks to become operational.
Incremental backup
A backup of changes since the last backup of any kind; restores need the full backup plus every incremental.
Differential backup
A backup of all changes since the last full backup; restores need the full backup plus the latest differential.
Immutable backup
A backup copy that cannot be altered or deleted for a set period, protecting it from ransomware.
Failback
Returning operations from the recovery site to the primary site once it is ready.
Event
Any observable occurrence in a system or network.
Alert
An event flagged by a tool as potentially significant, which requires triage.
Breach
An incident in which data is confirmed to have been accessed or disclosed without authorization.
Categorization
Labeling an incident by type, such as malware or unauthorized access, to route it and support trend analysis.
Severity matrix
A table defining severity levels, their criteria and the required response and escalation for each.
Triage
The initial assessment that decides whether an alert is an incident and how it should be prioritized.
Checklist review
A desk check of the plan's contents, such as contacts and procedures, for accuracy and completeness.
Walkthrough
A session in which team members step through the plan together to confirm it is workable.
Tabletop exercise
A discussion-based exercise using a realistic scenario, without touching live systems.
Inject
New information introduced during an exercise to change the scenario and test decisions.
Parallel test
A recovery test that brings up recovery systems alongside production without interrupting it.
Full interruption test
A test that actually shuts down production and fails over to recovery, the most realistic and disruptive type.
After-action report
A written record of what happened in an exercise or incident, with improvements, owners and dates.
Security information and event management (SIEM)
A system that collects, normalizes and correlates logs from many sources and raises alerts.
Security orchestration, automation and response (SOAR)
A platform that connects security tools and automates playbook steps.
Endpoint detection and response (EDR)
Software that monitors endpoints for malicious activity and can contain affected devices.
User and entity behavior analytics (UEBA)
Analytics that detect unusual behavior by comparing activity to a learned baseline.
False positive
An alert that indicates malicious activity when none has occurred.
Mean time to detect (MTTD)
The average time between an incident starting and the organization detecting it.
Indicator of compromise (IOC)
An observable artifact, such as a file hash, domain or account, that suggests a system has been compromised.
Order of volatility
The principle of collecting the most short-lived evidence, such as memory, before more persistent evidence such as disk.
Forensic image
A bit-for-bit copy of storage media made with forensic tools so the original remains unchanged.
Write blocker
A device or software that allows data to be read from media while preventing any writes to it.
Hash
A cryptographic fingerprint of data used to prove a copy is identical to the original and unaltered.
Chain of custody
Documentation of who collected, handled, stored and transferred each item of evidence, and when.
Root cause
The underlying weakness or failure that allowed an incident to happen.
Containment
Actions that limit the spread and impact of an incident, such as isolating systems or disabling accounts.
Eradication
Removing the cause of an incident, including malware, persistence mechanisms and the exploited weakness.
Recovery
Restoring systems and business processes to normal operation and confirming they work correctly.
Persistence mechanism
A method an attacker uses to keep access, such as a scheduled task, new service or hidden account.
Known-good image
A trusted, verified system build used to rebuild compromised systems.
Pre-authorized action
A response action the technical team may take without further approval because the plan allows it.
Escalation
Moving information about an incident to higher levels of management or other teams according to predefined criteria.
Notification
Informing external parties, such as regulators, customers or insurers, about an incident as required or appropriate.
Regulatory notification matrix
A prepared table of which laws and contracts require notification, to whom, under what conditions and by when.
Designated spokesperson
The person authorized to speak publicly for the organization about an incident.
General Data Protection Regulation (GDPR)
The European Union data protection law that includes personal data breach notification requirements.
Post-incident review
A structured meeting and report after an incident to identify what worked, what did not and what to improve.
Blameless review
A review approach that focuses on systemic causes rather than punishing individuals, encouraging honest reporting.
Root cause analysis
A method for finding the underlying reason an incident happened, beyond the immediate trigger.
Five whys
A technique of repeatedly asking why to move from symptoms to root causes.
Improvement action
A specific change arising from a review, with an owner and due date, tracked to completion.
Mean time to contain
The average time from detecting an incident to stopping its spread.
Study CISM for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISM study plan