CISM Cheat Sheet 2026
The 30 highest-yield CISM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
240 min time limit
70.00% to pass
- Which risk assessment approach assigns numerical values to probability and impact to calculate risk scores? → Quantitative risk assessment
- The following conditions lead to the MOST successful IT risk management activities: → Integrated within business processes
- What is the FIRST step in developing a Business Continuity Plan? → Conducting a Business Impact Analysis (BIA)
- What is the purpose of a risk register in information security management? → To record identified risks, their assessments, and treatment decisions
- When reviewing BC/DR plans, the information security manager should PRIMARILY ensure that: → Security controls are maintained and not bypassed during recovery operations
- When assigning ownership of information assets, the MOST appropriate owner is typically: → The business unit manager responsible for the asset
- When conducting a third-party vendor risk assessment, which document provides the MOST assurance regarding a vendor's security controls? → A SOC 2 Type II report from an independent auditor
- Who holds ULTIMATE responsibility for ensuring that business continuity planning is adequate and funded? → Senior management or the board of directors
- Which of the following is the BEST indicator that an organization's security culture is mature? → Employees report suspicious activities voluntarily without being prompted
- Which factor MOST influences the priority of information security risk treatment? → The likelihood and potential business impact of the risk
- A risk assessment reveals that a control is more expensive than the risk it mitigates. A CISM should RECOMMEND: → Accepting the risk if it falls within the risk appetite
- A CISM is developing a security governance framework. Which document should serve as the TOP-LEVEL foundation? → Information security policy
- What is the FIRST step in the incident response lifecycle according to best practices? → Preparation
- Which of the following BEST describes the purpose of a security operations center (SOC)? → To continuously monitor, detect, and respond to security incidents
- Which of the following is the MOST effective way to ensure third-party vendors comply with the organization's security requirements? → Include security requirements in contracts and conduct periodic audits
- The Federal Information Security Modernization Act (FISMA) PRIMARILY applies to: → US federal agencies and contractors that handle federal information
- An organization is merging with another company. The MOST important information security consideration during due diligence is: → Assessing the target company's security posture and existing vulnerabilities
- Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in the context of information security? → To identify critical processes and the impact of their disruption
- Which of the following BEST describes the concept of 'privacy by design' in a compliance context? → Embedding privacy protections into systems and processes from the beginning of development
- Which of the following BEST describes the role of a CISM during a major security incident? → Providing strategic oversight, coordination, and communication
- A CISM discovers that business units are making risk decisions without consulting the security team. The BEST corrective action is to: → Implement mandatory security reviews into the project management process
- A security manager is asked to measure the return on security investment (ROSI). Which component is ESSENTIAL to calculate ROSI? → Annualized Loss Expectancy (ALE) before and after implementing controls
- Which of the following BEST describes the relationship between information security governance and IT governance? → Information security governance is a subset of IT governance
- Which of the following is the PRIMARY purpose of a Business Impact Analysis (BIA)? → To determine the criticality of business processes and recovery time requirements
- A security incident causes a 6-hour outage for a system with an RTO of 4 hours. This PRIMARILY indicates a failure in: → Business continuity / disaster recovery planning
- A CISM is implementing a security control framework. Which of the following is MOST important when selecting a framework? → It should align with the organization's risk profile and industry requirements
- A CISM is presenting a security governance roadmap to the CEO. The presentation should PRIMARILY focus on: → Security risk in terms of business impact and strategic alignment
- A CISM is establishing data classification as part of the security program. The PRIMARY benefit is to: → Ensure appropriate controls are applied based on data sensitivity
- What distinguishes a Recovery Point Objective (RPO) from a Recovery Time Objective (RTO)? → RPO measures acceptable data loss in time; RTO measures recovery speed
- What is the PRIMARY objective of change management from an information security perspective? → To ensure changes do not introduce new security vulnerabilities or risks
Turn these facts into recall:
Was this helpful?