ISACA CISM (Certified Information Security Manager) Exam Guide

The **CISM** focuses on security management. It is the certification of choice for managers who design, oversee, and assess an enterprise's information security. It is less technical than CISSP and more governance-oriented.

What is the primary goal of Information Security Governance?

Answer : To align security with the organization's business objectives.

Ensures security supports rather than hinders organizational goals.

What is the first phase of Incident Management?

Answer : Preparation.

Setting up the plans, teams, and tools before an actual incident occurs.

What is 'Risk Appetite'?

Answer : The amount of risk an organization is willing to accept in pursuit of its goals.

Set by senior management to guide security investment and decision-making.

Which document sets the high-level expectations from management for security?

Answer : Security Policy.

The foundational document that outlines mandatory rules for the entire organization.

How does a BCP differ from a DRP?

Answer : BCP handles business operations; DRP focuses specifically on IT system restoration.

A Disaster Recovery Plan (DRP) is a technical subset of a Business Continuity Plan (BCP).

Related Certifications

Local Testing

Careers

preload
preload
preload
preload
preload
preload