ISACA free flashcards

Free CISM flashcards

8 real CISM flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.

The full deck has 471 flashcards. For a domain-by-domain breakdown and a study plan, read the CISM study guide.

ConceptInformation Security Program

What should primarily determine the sensitivity level assigned to an information asset in a classification scheme?

Classification expresses the worth of information to the organisation, and that worth is judged by the business impact if the asset's confidentiality, integrity, or availability were compromised. Impact is the primary driver because it measures the consequences of disclosure, alteration, or loss, rather than format, demand, or age.

MisconceptionInformation Security Program

A standard, which specifies the mandatory technical requirements a system must meet, is the document that gives the step-by-step instructions for a task.

Tempting because standards are detailed and mandatory, but a standard states what must be achieved rather than the ordered steps of how to perform the task. The sequential how belongs to a procedure.

ConceptIncident Management

Under a mandatory breach notification regime, what primarily determines the deadline by which the supervisory authority must be notified?

Statutory breach regimes start the notification clock from the moment the organisation became aware, or reasonably should have become aware, of a notifiable breach. Awareness, not containment or internal governance, triggers and bounds the regulatory deadline.

MisconceptionIncident Management

The notification deadline to the regulator should run from the date technical containment of the affected systems is fully completed.

Containment is an important operational milestone, so tying the clock to it feels logical. But notification obligations are anchored to awareness of the breach, not to completing technical remediation, which may come much later.

ConceptInformation Security Risk Management

Why is qualitative analysis the right first choice when a risk needs a fast, defensible prioritisation but no reliable frequency or loss data exists?

Quantitative methods depend on credible occurrence and impact data to avoid false precision. When such data is unavailable and time is short, structured qualitative ratings of likelihood and impact give a defensible first-pass prioritisation that can later be refined quantitatively as data matures.

MisconceptionInformation Security Risk Management

Express every risk in annual loss expectancy so the board gets the precise monetary ranking it expects.

Monetary figures look authoritative, which makes this tempting. But without occurrence and loss data the annual loss expectancy values rest on guessed inputs, producing false precision rather than a defensible ranking.

ConceptInformation Security Governance

When a frozen, fully committed budget cannot cover a new high-priority regulatory project, what is the disciplined resource-allocation response?

Resource management means continuously steering finite funds toward the greatest risk reduction. Re-prioritise the existing portfolio and reallocate from lower-risk initiatives, supported by an impact assessment, so the highest-risk obligation is met without breaching governance and the deferred work stays visible.

MisconceptionInformation Security Governance

If the funding freeze blocks the regulatory project, the right move is to defer it to the next cycle and formally document the compliance exposure as an accepted risk.

Tempting because it respects the freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship, and the manager rarely has authority to accept that level of risk alone.

Get all 471 CISM flashcards free

Drop your email and we will keep you posted as new CISM study material ships. No spam - we mail you only when it is worth your time.

Frequently asked questions

Are these CISM flashcards free?

Yes. Every card on this page is free to read with no sign-up. The full deck has 471 flashcards; drop your email below and we will keep you posted, or create a free account to study the rest.

What is a misconception card?

A card built from a tempting wrong answer in our question bank, naming the trap and explaining why it fails. Most flashcard decks only drill the fact (a concept card); we pair each one with the misconception the exam actually tests you against.

Are these real CISM exam questions or vendor content?

No. These are original flashcards written from our own blueprint-aligned practice questions. We never reproduce live exam items or vendor material.

How many flashcards are in the full CISM deck?

471 cards spread across all 4 domains. For the full domain-by-domain breakdown, read the study guide.

Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CISM and related marks belong to their respective owners.