ISACA CISM (Certified Information Security Manager) Exam Guide
The **CISM** focuses on security management. It is the certification of choice for managers who design, oversee, and assess an enterprise's information security. It is less technical than CISSP and more governance-oriented.
What is the primary goal of Information Security Governance?
Answer : To align security with the organization's business objectives.
Ensures security supports rather than hinders organizational goals.
What is the first phase of Incident Management?
Answer : Preparation.
Setting up the plans, teams, and tools before an actual incident occurs.
What is 'Risk Appetite'?
Answer : The amount of risk an organization is willing to accept in pursuit of its goals.
Set by senior management to guide security investment and decision-making.
Which document sets the high-level expectations from management for security?
Answer : Security Policy.
The foundational document that outlines mandatory rules for the entire organization.
How does a BCP differ from a DRP?
Answer : BCP handles business operations; DRP focuses specifically on IT system restoration.
A Disaster Recovery Plan (DRP) is a technical subset of a Business Continuity Plan (BCP).
Related Certifications