CISM Cheat Sheet 2026

The 30 highest-yield CISM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
240 min time limit
70.00% to pass
  1. Which risk assessment approach assigns numerical values to probability and impact to calculate risk scores? Quantitative risk assessment
  2. The following conditions lead to the MOST successful IT risk management activities: Integrated within business processes
  3. What is the FIRST step in developing a Business Continuity Plan? Conducting a Business Impact Analysis (BIA)
  4. What is the purpose of a risk register in information security management? To record identified risks, their assessments, and treatment decisions
  5. When reviewing BC/DR plans, the information security manager should PRIMARILY ensure that: Security controls are maintained and not bypassed during recovery operations
  6. When assigning ownership of information assets, the MOST appropriate owner is typically: The business unit manager responsible for the asset
  7. When conducting a third-party vendor risk assessment, which document provides the MOST assurance regarding a vendor's security controls? A SOC 2 Type II report from an independent auditor
  8. Who holds ULTIMATE responsibility for ensuring that business continuity planning is adequate and funded? Senior management or the board of directors
  9. Which of the following is the BEST indicator that an organization's security culture is mature? Employees report suspicious activities voluntarily without being prompted
  10. Which factor MOST influences the priority of information security risk treatment? The likelihood and potential business impact of the risk
  11. A risk assessment reveals that a control is more expensive than the risk it mitigates. A CISM should RECOMMEND: Accepting the risk if it falls within the risk appetite
  12. A CISM is developing a security governance framework. Which document should serve as the TOP-LEVEL foundation? Information security policy
  13. What is the FIRST step in the incident response lifecycle according to best practices? Preparation
  14. Which of the following BEST describes the purpose of a security operations center (SOC)? To continuously monitor, detect, and respond to security incidents
  15. Which of the following is the MOST effective way to ensure third-party vendors comply with the organization's security requirements? Include security requirements in contracts and conduct periodic audits
  16. The Federal Information Security Modernization Act (FISMA) PRIMARILY applies to: US federal agencies and contractors that handle federal information
  17. An organization is merging with another company. The MOST important information security consideration during due diligence is: Assessing the target company's security posture and existing vulnerabilities
  18. Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in the context of information security? To identify critical processes and the impact of their disruption
  19. Which of the following BEST describes the concept of 'privacy by design' in a compliance context? Embedding privacy protections into systems and processes from the beginning of development
  20. Which of the following BEST describes the role of a CISM during a major security incident? Providing strategic oversight, coordination, and communication
  21. A CISM discovers that business units are making risk decisions without consulting the security team. The BEST corrective action is to: Implement mandatory security reviews into the project management process
  22. A security manager is asked to measure the return on security investment (ROSI). Which component is ESSENTIAL to calculate ROSI? Annualized Loss Expectancy (ALE) before and after implementing controls
  23. Which of the following BEST describes the relationship between information security governance and IT governance? Information security governance is a subset of IT governance
  24. Which of the following is the PRIMARY purpose of a Business Impact Analysis (BIA)? To determine the criticality of business processes and recovery time requirements
  25. A security incident causes a 6-hour outage for a system with an RTO of 4 hours. This PRIMARILY indicates a failure in: Business continuity / disaster recovery planning
  26. A CISM is implementing a security control framework. Which of the following is MOST important when selecting a framework? It should align with the organization's risk profile and industry requirements
  27. A CISM is presenting a security governance roadmap to the CEO. The presentation should PRIMARILY focus on: Security risk in terms of business impact and strategic alignment
  28. A CISM is establishing data classification as part of the security program. The PRIMARY benefit is to: Ensure appropriate controls are applied based on data sensitivity
  29. What distinguishes a Recovery Point Objective (RPO) from a Recovery Time Objective (RTO)? RPO measures acceptable data loss in time; RTO measures recovery speed
  30. What is the PRIMARY objective of change management from an information security perspective? To ensure changes do not introduce new security vulnerabilities or risks
Turn these facts into recall:
Was this helpful?