All certifications / CISM / Cheat sheet
CISM 2026 exam content outline cheat sheet
Domain 1: Information security governance (18%)
Exam tips
- CISM answers favor the manager who advises and informs decision-makers over the one who acts alone. Accountability stays with the board and senior management; the CISO is responsible for running the program.
- When a question describes a policy people ignore, look for the answer that addresses the cause, such as culture, leadership support or impractical design, rather than more enforcement or monitoring.
- When a new law or market appears in a question, the first step is to identify the requirements and their impact, not to jump to a specific control or data move. Compliance is a minimum, not proof that risk is acceptable.
- Watch for independence problems: auditors should not run controls, and security findings about IT should not be filtered through IT operations. Owners are business managers, not IT staff.
- Gap analysis needs a desired state, and the desired state comes from business objectives. An answer that starts with a framework gap assessment before understanding the business is usually premature.
- Certification questions point to ISO/IEC 27001, not 27002 or NIST CSF. Enterprise IT governance and goal alignment point to COBIT. The Govern function is new in CSF 2.0.
- Business cases that win on the exam emphasize risk to business objectives relative to cost. Technical features, fear from competitors' breaches or vulnerability counts are weaker justifications.
- Appetite is set by senior management. If residual risk exceeds it, the answer is escalation for a decision, never self-acceptance by the security manager or changing the rating.
Key terms
- Governance
- Direction and oversight by the board and executives: setting objectives, risk appetite and accountability, and monitoring results.
- Management
- Planning, building, running and monitoring activities within the direction set by governance.
- Accountability
- The obligation to answer for an outcome; it cannot be delegated, even when responsibility for the work is.
- Responsibility
- The duty to carry out a task or operate a control, which can be assigned to others.
- Strategic alignment
- Security goals and spending are derived from, and support, the organization's business objectives.
- Value delivery
- Achieving security outcomes at a cost that is justified by the business benefit they provide.
- Senior management commitment
- Visible leadership support through approved strategy, funding and personal example, the key success factor for a security program.
- Security culture
- The shared attitudes and habits that determine whether people behave securely when no one is checking.
- Tone at the top
- The example and priorities set by senior leaders, which strongly shape employee behavior.
- Blame-free reporting
- A practice where people can report mistakes and incidents without fear of punishment, so problems surface early.
- Security champion
- A volunteer in a business or technical team who receives extra training and promotes secure practices locally.
- Workaround
- An unofficial way of getting work done that bypasses a control, often a sign the control does not fit how work happens.
- Culture assessment
- A structured review of attitudes and behavior, using surveys, interviews and metrics, to find where controls may erode.
- Regulatory requirement
- An obligation imposed by a law or regulator, usually with penalties for noncompliance.
- Contractual requirement
- An obligation the organization accepts in an agreement, such as PCI DSS through card brand contracts.
- Data localization
- A legal requirement that certain data be stored or processed within a specific country.
- Compliance register
- A maintained list of applicable obligations, what they require, where they apply and who owns them.
- Right to audit
- A contract clause allowing the customer or its auditors to verify a provider's controls.
- Principle-based requirement
- A rule that states an outcome, such as appropriate security, and leaves the organization to justify its controls by risk.
- Board of directors
- The body that sets overall direction and risk appetite and is ultimately accountable for the organization.
- Steering committee
- A cross-functional group of senior leaders that prioritizes and oversees security initiatives.
- Chief information security officer (CISO)
- The executive responsible for designing and running the information security program and reporting on risk.
- Data owner
- A business manager accountable for an information asset, including its classification and access approvals.
- Data custodian
- The person or team, often IT, that implements and operates the controls the owner has chosen.
- RACI
- A matrix showing who is responsible, accountable, consulted and informed for each activity.
- Internal audit
- An independent function that gives the board assurance that controls are designed and operating effectively.
- Current state
- A documented picture of today's security capabilities, controls and maturity.
- Desired state
- The target capabilities and risk position needed to support business objectives within appetite.
- Gap analysis
- A comparison of current and desired state that identifies what must change.
- Roadmap
- A sequenced, resourced plan of initiatives that closes the prioritized gaps.
- Maturity model
- A scale that rates how well defined, managed and improved a process is, used to express current and target states.
- Constraint
- A limit on the strategy, such as budget, staff, culture, law or time, that shapes what can be achieved.
- COBIT
- ISACA's framework for governance and management of enterprise information and technology.
- ISMS
- Information security management system: the policies, processes and controls used to manage information security risk, as defined by ISO/IEC 27001.
- Statement of applicability
- An ISO/IEC 27001 document listing which controls apply, whether they are implemented and why any are excluded.
- ISO/IEC 27002
- A catalog of information security controls with implementation guidance that supports ISO/IEC 27001 but is not certifiable.
- NIST CSF 2.0
- A voluntary framework of cybersecurity outcomes organized into Govern, Identify, Protect, Detect, Respond and Recover.
- Profile
- In NIST CSF, a description of current or target cybersecurity outcomes used to find and prioritize gaps.
- Business case
- A document that justifies an investment by comparing options, costs, benefits and risks, and states the decision needed.
- Capital expenditure (CapEx)
- A one-time investment in assets or projects, such as buying hardware or building a system.
- Operating expenditure (OpEx)
- Ongoing costs such as subscriptions, salaries and managed services.
- Total cost of ownership (TCO)
- The full cost of a control over its life, including purchase, integration, operation, staff and retirement.
- Return on security investment (ROSI)
- An estimate of value: the reduction in expected loss, minus the control's cost, relative to that cost.
- Resource allocation
- Deciding how money, staff time and skills are distributed across initiatives according to priority.
- Risk appetite
- The amount and type of risk the organization is willing to accept in pursuit of its objectives, set by senior leadership.
- Risk tolerance
- The acceptable deviation from appetite for a specific objective, often expressed as a measurable threshold.
- Risk capacity
- The maximum risk an organization can absorb before it can no longer meet its obligations or survive.
- Residual risk
- The risk that remains after controls are applied.
- Risk acceptance criteria
- Defined rules stating which risk levels may be accepted and by which level of management.
- Escalation
- Referring a risk that exceeds someone's authority or the appetite to a higher level for decision.
Domain 2: Information security risk management (20%)
Exam tips
- New threat information triggers assessment of relevance and exposure first. Answers that buy tools, notify customers or cut connectivity before assessing are usually wrong.
- Technical severity is not business risk. When a question gives a tester's 'critical' rating, the best answer adds business context such as asset value, exposure and exploitability.
- Practice the arithmetic: SLE = AV x EF, ALE = SLE x ARO, and an event every N years has ARO = 1/N. Distractors often use the SLE as the answer or multiply by N instead of dividing.
- A complete scenario has a threat, a vulnerability, an asset and a business consequence. Options that mention only a tool, only a threat or only a technical effect are incomplete.
- Insurance transfers financial impact, not accountability or legal responsibility. And the security manager never accepts risk on the owner's behalf.
- Identifying a risk does not make security its owner. Look for the business manager accountable for the affected process, and remember that control owners and risk owners have different jobs.
- KRIs look forward and signal rising exposure; KPIs measure performance. Counts of tools, staff certifications or rules are rarely good KRIs.
- For the board, choose answers about top risks in business terms, trends and appetite. Technical detail and complete lists belong elsewhere.
Key terms
- Threat landscape
- The current set of threat actors, their motives, capabilities and techniques relevant to an organization.
- Threat intelligence
- Analyzed information about threats that supports decisions, from strategic trends to specific indicators.
- ISAC
- Information Sharing and Analysis Center: an industry group where members share threat information.
- Emerging risk
- A new or changing risk whose likelihood or impact is not yet well understood.
- Indicator of compromise (IOC)
- A technical artifact, such as a malicious domain or file hash, that suggests a system may be compromised.
- Horizon scanning
- A periodic structured review of trends that could create new risks over the coming years.
- Vulnerability
- A weakness in an asset, process or control that a threat could exploit.
- Control deficiency
- A gap where a required control is missing, poorly designed or not operating effectively.
- CVSS
- Common Vulnerability Scoring System: a standard way to rate the technical severity of vulnerabilities.
- CVE
- Common Vulnerabilities and Exposures: a public identifier assigned to a specific known vulnerability.
- Compensating control
- An alternative control that meets the intent of a required control that cannot be implemented.
- Design deficiency
- A weakness where a control would not meet its objective even if performed perfectly.
- Operating deficiency
- A weakness where a well-designed control is not performed consistently or correctly.
- Single loss expectancy (SLE)
- Expected loss from one occurrence: asset value multiplied by exposure factor.
- Exposure factor (EF)
- The percentage of an asset's value expected to be lost in a single event.
- Annualized rate of occurrence (ARO)
- How many times per year an event is expected; once every 20 years is 0.05.
- Annualized loss expectancy (ALE)
- Expected yearly loss: SLE multiplied by ARO.
- Heat map
- A grid showing likelihood against impact, colored to show risk levels, used in qualitative analysis.
- Semi-quantitative analysis
- Assigning numeric scores to qualitative categories so risks can be ranked consistently.
- FAIR
- Factor Analysis of Information Risk: a quantitative model that estimates risk as ranges of loss frequency and magnitude.
- Risk scenario
- A description of a plausible event in which a threat exploits a vulnerability in an asset and causes a business impact.
- Likelihood
- The probability or frequency that a scenario will occur within a defined period.
- Impact
- The consequence of the scenario for the organization, expressed in financial, operational, legal, reputational or safety terms.
- Inherent risk
- The level of risk before controls are considered.
- Residual risk
- The level of risk that remains after existing controls are taken into account.
- Impact table
- A defined scale explaining what each impact level means for each consequence type, used to rate impact consistently.
- Risk mitigation
- Applying controls to reduce the likelihood or impact of a risk.
- Risk transfer
- Shifting some financial consequences to a third party, such as an insurer, without transferring accountability.
- Risk avoidance
- Eliminating a risk by not performing the activity that causes it.
- Risk acceptance
- An informed, documented decision by an authorized owner to bear a risk.
- Treatment plan
- A record of the chosen response, actions, owners, deadlines and expected residual risk.
- Cyber insurance
- A policy that covers some financial costs of security incidents, such as forensics, legal fees and notification.
- Risk owner
- The person accountable for a risk, with authority to decide its treatment and accept residual risk.
- Control owner
- The person responsible for designing, operating and evidencing a specific control.
- Acceptance authority
- The defined level of management permitted to accept risks of a given rating.
- Attestation
- A control owner's formal confirmation, usually periodic, that a control operated as designed.
- Escalation
- Referring a risk to a higher level of management when it exceeds the current owner's authority.
- Role-based ownership
- Assigning ownership to a job role rather than only a named person, so it survives staff changes.
- Risk register
- A maintained record of identified risks with owners, ratings, responses and status.
- Key risk indicator (KRI)
- A metric with thresholds that signals increasing risk exposure.
- Key performance indicator (KPI)
- A metric showing how well a process or control performs against its target.
- Threshold
- The KRI value at which a predefined action or escalation is triggered.
- Leading indicator
- A metric that changes before a loss occurs, giving early warning.
- Lagging indicator
- A metric that reports what has already happened, such as losses or incidents in the last quarter.
- Risk monitoring
- Ongoing tracking of risks, indicators, controls and events so that decisions stay current.
- Risk dashboard
- A concise visual summary of top risks, trends, appetite status and key indicators.
- Escalation criteria
- Predefined conditions that require a risk or event to be reported to a higher level immediately.
- Material risk
- A risk significant enough to affect the organization's objectives, finances or reputation in a way leadership must know about.
- Audit and risk committee
- A board committee that oversees internal control, audit and risk on the board's behalf.
- Decision request
- A clear statement in a report of the approval or direction needed from leadership.
- Risk trend
- The direction a risk has moved since the last report, with the reason for the change.
Domain 3: Information security program (33%)
Exam tips
- Resource questions turn on skills that match the strategy, not on raw headcount or a single certification. Outsourcing can provide skills but never transfers accountability.
- Classification is based on business impact of loss of confidentiality, integrity or availability, and the data owner assigns it. The inventory comes first, and tools like DLP come after classification.
- Frameworks are chosen and tailored based on risk assessment; they never replace it and never guarantee that breaches will not occur.
- Architecture questions reward answers that build security into design consistently and early. Zero trust means verify every request regardless of network location.
- Specific mandatory settings go in standards, not policies. Guidelines are never mandatory. Policies get their authority from senior management approval, and exceptions must be risk-assessed, approved at the right level and time-limited.
- For senior management, pick metrics that tie to business risk and appetite. A KRI warns of rising exposure; a KPI measures performance against target. Activity counts such as blocked spam or rule changes are operational, not strategic.
- Classify a control by what it does: finding a change after it happens is detective, stopping it is preventive, fixing it is corrective. An alternative used when the preferred control is impossible is compensating. Selection starts from risk-based control objectives.
- Even urgent security changes go through change management, using the emergency change path if needed. Integrating security early in the SDLC is cheaper and more effective than retrofitting, and every control needs an owner and monitoring.
- Documentation proves design, not operation. Inquiry alone is weak evidence and reperformance is the strongest. Self-assessments complement but never replace independent audits, and failed tests mean residual risk is higher than assumed.
- The goal of awareness is behavior change that reduces risk. The best measure combines falling click rates with rising report rates, not completion counts or quiz scores, and training should be tailored to roles.
- Assess before you sign, write requirements into the contract, and monitor throughout the relationship. Never test a provider without written permission, and remember accountability for your data always stays with you.
- Match the message to the audience and link it to business objectives and risk. One detailed technical report for everyone, or reporting only after incidents, is the wrong answer. Boards want risk, trends and decisions.
Key terms
- Information security program
- The organized activities, resources and controls that implement the security strategy.
- GRC
- Governance, risk and compliance: the functions that manage policy, risk and regulatory obligations.
- Managed security service
- An outsourced security function, such as monitoring or detection, run by a provider under contract.
- Skills inventory
- A record of the capabilities each role needs and who has them, used to find skill gaps.
- Service level agreement (SLA)
- A contract term defining the measurable service a provider must deliver, such as response times.
- Succession planning
- Preparing backup people for critical roles so capabilities do not depend on one person.
- Asset inventory
- A maintained list of information assets with owners, locations and purposes.
- Asset valuation
- Estimating an asset's importance by the business impact of losing its confidentiality, integrity or availability.
- Classification scheme
- A defined set of sensitivity levels with handling rules for each.
- Handling requirements
- Rules for labeling, storing, transmitting, sharing, retaining and disposing of information at each classification level.
- Data loss prevention (DLP)
- Tools that detect and block unauthorized movement of sensitive data, usually relying on classification labels or content rules.
- Shadow IT
- Systems or services adopted by business units without the knowledge or approval of IT and security.
- Business impact analysis (BIA)
- A study of how disruption to processes and assets would affect the business over time, used to set availability requirements.
- Control framework
- A structured catalog of controls that organizations select and tailor to their risks.
- Tailoring
- Adjusting a framework's controls to an organization's specific risks, excluding or adding controls with documented reasons.
- Control mapping
- Linking internal controls to requirements in multiple frameworks so one control satisfies several obligations.
- CIS Critical Security Controls
- A prioritized set of technical safeguards grouped into implementation groups.
- NIST SP 800-53
- A detailed catalog of security and privacy controls with baselines for low, moderate and high impact systems.
- SOC 2
- An independent assurance report on a service organization's controls, based on trust services criteria.
- Enterprise architecture
- A description of how business processes, information, applications and technology fit together, now and in a target state.
- Security architecture
- The structure of security controls and services across the enterprise architecture layers.
- Reference architecture
- An approved, reusable design pattern that projects follow to meet security and other requirements consistently.
- Zero trust
- An approach that grants no implicit trust based on network location and verifies every access request.
- Defense in depth
- Layering multiple independent controls so that the failure of one does not expose the asset.
- SABSA
- Sherwood Applied Business Security Architecture: a method that derives security architecture from business requirements.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer.
- Policy
- A high-level, mandatory statement of management intent and direction, approved by senior management.
- Standard
- A mandatory, specific requirement, such as a technology, setting or measurable value, that implements a policy.
- Baseline
- A standard defining the minimum security configuration for a particular platform or system type.
- Procedure
- Mandatory step-by-step instructions for carrying out a task consistently.
- Guideline
- Optional, recommended advice that helps people meet policies and standards.
- Policy exception
- A formally approved, risk-assessed and time-limited deviation from a policy or standard, tracked in a register.
- Key performance indicator (KPI)
- A measure of whether a process or control is performing to its target.
- Key risk indicator (KRI)
- A forward-looking measure that signals rising exposure, with thresholds that trigger escalation.
- Key goal indicator (KGI)
- A measure showing whether a defined goal has been achieved.
- SMART metric
- A metric that is specific, measurable, attainable, relevant and timely.
- Maturity model
- A scale that rates how well processes are defined, managed and improved, from ad hoc to optimized.
- Vanity metric
- A number that looks impressive but does not support any decision or action.
- Threshold
- A predefined value at which a metric changes status and triggers review or escalation.
- Control
- Any measure, such as a policy, process, device or practice, that modifies risk.
- Control objective
- A statement of what a control or set of controls must achieve to address a risk.
- Preventive control
- A control that stops an unwanted event from occurring.
- Detective control
- A control that identifies an event while it is happening or after it has occurred.
- Corrective control
- A control that limits the impact of an event and fixes the underlying problem.
- Compensating control
- An alternative control that meets the intent of a requirement when the preferred control cannot be used.
- Change management
- The formal process for requesting, assessing, approving, testing, implementing and recording changes to production.
- Change advisory board (CAB)
- The group that reviews and approves significant changes.
- Emergency change
- An urgent change made through an expedited approval path and reviewed afterward.
- System development life cycle (SDLC)
- The phases a system goes through from requirements and design to operation and retirement.
- Configuration management
- The practice of keeping systems aligned with approved baselines and detecting and correcting drift.
- Control owner
- The person accountable for operating and maintaining a control so it stays effective.
- Backout plan
- Documented steps to return to the previous state if a change fails.
- Design effectiveness
- Whether a control, as designed, is capable of meeting its objective.
- Operating effectiveness
- Whether a control actually operates as designed, consistently, over a period.
- Inquiry
- Asking people how a control works; the weakest form of evidence on its own.
- Reperformance
- The tester independently executing a control to confirm it produces the correct result; the strongest method.
- Sampling
- Testing a selected subset of items from a population to draw a conclusion about the whole.
- Continuous control monitoring
- Automated, ongoing checks that detect control failures quickly between formal tests.
- Deficiency
- A gap in the design or operation of a control that leaves a risk less well managed than intended.
- Security awareness
- Activities that help everyone recognize security risks and know how to respond.
- Role-based training
- Training that builds the specific security skills required for a particular job function.
- Security education
- Longer-term learning that builds deep understanding, often for security professionals.
- Phishing simulation
- A controlled, harmless test email used to measure and improve how staff recognize and report phishing.
- Report rate
- The percentage of recipients who report a suspicious or simulated message to the security team.
- Security culture
- The shared attitudes and habits that shape how people in an organization treat security.
- Third-party risk management (TPRM)
- The process of identifying, assessing, contracting for and monitoring risks from external providers.
- Due diligence
- Investigation of a provider's security, stability and suitability before entering a relationship.
- Right to audit
- A contract clause allowing the customer to audit the provider or receive independent assurance reports.
- SOC 2 Type II report
- An independent auditor's report on the design and operating effectiveness of a service organization's controls over a period.
- Fourth party
- A subcontractor or supplier of your vendor, on which you depend without a direct contract.
- Stakeholder
- Any person or group affected by, or able to influence, the information security program.
- Stakeholder map
- A list of stakeholder groups with their interests, influence and preferred communication channels.
- Steering committee
- A cross-functional group of business and IT leaders that guides and supports the security program.
- Escalation trigger
- A predefined condition that requires immediate reporting outside the normal schedule.
- Security dashboard
- A visual summary of key metrics and risks tailored to a particular audience.
- Business alignment
- Ensuring security activities and messages support the organization's goals and priorities.
Domain 4: Incident management (29%)
Exam tips
- The main purpose of the IRP is a timely, coordinated response that limits business impact. Incident teams include legal, communications, HR and business owners, not only technical staff, and decision authority must be defined before an incident.
- The BIA comes before setting recovery strategies and choosing recovery sites. RTO is about time to restore; RPO is about how much data can be lost. RTO must be less than MTD, and business owners, not IT alone, determine criticality.
- The BCP keeps business functions running; the DRP restores IT. The BCP program starts with senior management support and the BIA, not with picking an alternate site, and BCP and DRP recovery targets must match.
- Match the site to the RTO: hot for fastest and most expensive, cold for slowest and cheapest, warm in between. Verify backups with actual restore tests, not job success messages, and restore dependencies such as identity and networks first.
- Classification criteria should be based on business impact, data sensitivity and scope, not on the malware family, detection time or alert count. Severity is reassessed as facts emerge.
- Tabletop means discussion without touching systems; full interruption is the most disruptive and realistic. Test regularly and after major changes, not only when auditors ask, and the key output is tracked improvements.
- SOAR speeds and standardizes response; it does not replace staff or log collection. A SIEM correlates logs; EDR contains endpoints. When an alert fires, validate it before taking drastic action.
- Preserve first: capture volatile data, create a forensic image, hash it, analyze the copy and keep chain of custody. Options that browse, scan, reboot or reimage the original destroy evidence.
- Order matters: contain before restoring. Before recovery, verify backups are clean and the vulnerability is fixed. Disruptive containment needs business owner input, and paying a ransom is a business and legal decision, not containment.
- Notification decisions are made by senior management with legal counsel, following the plan. Employees refer outside inquiries to the designated contact, and sensitive incident communication uses out-of-band channels.
- The purpose of lessons learned is improvement, not blame. Every finding needs an owner and due date, and repeated incidents of the same kind point to an unfixed root cause.
Key terms
- Incident
- An event that threatens the confidentiality, integrity or availability of information or systems, or violates security policy.
- Incident response plan (IRP)
- The approved document defining how the organization prepares for, detects, responds to and recovers from incidents.
- Incident manager
- The person who coordinates the response, makes or escalates decisions and keeps the timeline.
- Computer security incident response team (CSIRT)
- A team with defined responsibility for handling security incidents.
- Playbook
- A detailed, step-by-step procedure for responding to a specific type of incident.
- Incident response retainer
- A pre-arranged contract with an external firm to provide response support quickly when needed.
- Out-of-band communication
- A communication channel separate from potentially compromised systems, used during incidents.
- Business impact analysis (BIA)
- An analysis that identifies critical processes, their dependencies and the impact of disruption over time.
- Maximum tolerable downtime (MTD)
- The longest a process can be unavailable before causing unacceptable harm to the organization.
- Recovery time objective (RTO)
- The target time to restore a process or system after a disruption; it must be less than the MTD.
- Recovery point objective (RPO)
- The maximum acceptable amount of data loss, measured as time before the disruption.
- Work recovery time (WRT)
- The time needed after systems are restored to verify data and resume normal work.
- Service delivery objective (SDO)
- The minimum level of service that must be provided during alternate or degraded operations.
- Dependency
- A resource, such as a system, supplier or person, that a process needs in order to operate.
- Business continuity plan (BCP)
- A plan for keeping critical business functions operating or restoring them quickly during and after a disruption.
- Business continuity management (BCM)
- The ongoing program of governance, analysis, planning, testing and maintenance for continuity.
- Continuity strategy
- The approach chosen to keep a critical process running, such as an alternate site, remote work or manual workaround.
- Activation criteria
- The conditions and authority under which a continuity plan is declared and put into action.
- Manual workaround
- A temporary non-automated way of performing a process while systems are unavailable.
- Crisis management
- The executive-level coordination of the organization's response to a major disruption, including communications.
- Disaster recovery plan (DRP)
- A plan for restoring IT systems, data and infrastructure after a disruption to meet recovery targets.
- Hot site
- A fully equipped recovery site with current systems and data that can take over within minutes to hours.
- Warm site
- A partly equipped recovery site that needs data restoration and configuration, taking hours to days.
- Cold site
- A recovery site providing only space, power and cooling, requiring days to weeks to become operational.
- Incremental backup
- A backup of changes since the last backup of any kind; restores need the full backup plus every incremental.
- Differential backup
- A backup of all changes since the last full backup; restores need the full backup plus the latest differential.
- Immutable backup
- A backup copy that cannot be altered or deleted for a set period, protecting it from ransomware.
- Failback
- Returning operations from the recovery site to the primary site once it is ready.
- Event
- Any observable occurrence in a system or network.
- Alert
- An event flagged by a tool as potentially significant, which requires triage.
- Breach
- An incident in which data is confirmed to have been accessed or disclosed without authorization.
- Categorization
- Labeling an incident by type, such as malware or unauthorized access, to route it and support trend analysis.
- Severity matrix
- A table defining severity levels, their criteria and the required response and escalation for each.
- Triage
- The initial assessment that decides whether an alert is an incident and how it should be prioritized.
- Checklist review
- A desk check of the plan's contents, such as contacts and procedures, for accuracy and completeness.
- Walkthrough
- A session in which team members step through the plan together to confirm it is workable.
- Tabletop exercise
- A discussion-based exercise using a realistic scenario, without touching live systems.
- Inject
- New information introduced during an exercise to change the scenario and test decisions.
- Parallel test
- A recovery test that brings up recovery systems alongside production without interrupting it.
- Full interruption test
- A test that actually shuts down production and fails over to recovery, the most realistic and disruptive type.
- After-action report
- A written record of what happened in an exercise or incident, with improvements, owners and dates.
- Security information and event management (SIEM)
- A system that collects, normalizes and correlates logs from many sources and raises alerts.
- Security orchestration, automation and response (SOAR)
- A platform that connects security tools and automates playbook steps.
- Endpoint detection and response (EDR)
- Software that monitors endpoints for malicious activity and can contain affected devices.
- User and entity behavior analytics (UEBA)
- Analytics that detect unusual behavior by comparing activity to a learned baseline.
- False positive
- An alert that indicates malicious activity when none has occurred.
- Mean time to detect (MTTD)
- The average time between an incident starting and the organization detecting it.
- Indicator of compromise (IOC)
- An observable artifact, such as a file hash, domain or account, that suggests a system has been compromised.
- Order of volatility
- The principle of collecting the most short-lived evidence, such as memory, before more persistent evidence such as disk.
- Forensic image
- A bit-for-bit copy of storage media made with forensic tools so the original remains unchanged.
- Write blocker
- A device or software that allows data to be read from media while preventing any writes to it.
- Hash
- A cryptographic fingerprint of data used to prove a copy is identical to the original and unaltered.
- Chain of custody
- Documentation of who collected, handled, stored and transferred each item of evidence, and when.
- Root cause
- The underlying weakness or failure that allowed an incident to happen.
- Containment
- Actions that limit the spread and impact of an incident, such as isolating systems or disabling accounts.
- Eradication
- Removing the cause of an incident, including malware, persistence mechanisms and the exploited weakness.
- Recovery
- Restoring systems and business processes to normal operation and confirming they work correctly.
- Persistence mechanism
- A method an attacker uses to keep access, such as a scheduled task, new service or hidden account.
- Known-good image
- A trusted, verified system build used to rebuild compromised systems.
- Pre-authorized action
- A response action the technical team may take without further approval because the plan allows it.
- Escalation
- Moving information about an incident to higher levels of management or other teams according to predefined criteria.
- Notification
- Informing external parties, such as regulators, customers or insurers, about an incident as required or appropriate.
- Regulatory notification matrix
- A prepared table of which laws and contracts require notification, to whom, under what conditions and by when.
- Designated spokesperson
- The person authorized to speak publicly for the organization about an incident.
- General Data Protection Regulation (GDPR)
- The European Union data protection law that includes personal data breach notification requirements.
- Post-incident review
- A structured meeting and report after an incident to identify what worked, what did not and what to improve.
- Blameless review
- A review approach that focuses on systemic causes rather than punishing individuals, encouraging honest reporting.
- Root cause analysis
- A method for finding the underlying reason an incident happened, beyond the immediate trigger.
- Five whys
- A technique of repeatedly asking why to move from symptoms to root causes.
- Improvement action
- A specific change arising from a review, with an owner and due date, tracked to completion.
- Mean time to contain
- The average time from detecting an incident to stopping its spread.
Study CISM for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISM study planLessons, quizzes, exam simulations and hands-on labs.