8 real CISM flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.
The full deck has 471 flashcards. For a domain-by-domain breakdown and a study plan, read the CISM study guide.
schoolConceptInformation Security Program
What should primarily determine the sensitivity level assigned to an information asset in a classification scheme?
arrow_downward
Classification expresses the worth of information to the organisation, and that worth is judged by the business impact if the asset's confidentiality, integrity, or availability were compromised. Impact is the primary driver because it measures the consequences of disclosure, alteration, or loss, rather than format, demand, or age.
errorMisconceptionInformation Security Program
A standard, which specifies the mandatory technical requirements a system must meet, is the document that gives the step-by-step instructions for a task.
arrow_downward
Tempting because standards are detailed and mandatory, but a standard states what must be achieved rather than the ordered steps of how to perform the task. The sequential how belongs to a procedure.
schoolConceptIncident Management
Under a mandatory breach notification regime, what primarily determines the deadline by which the supervisory authority must be notified?
arrow_downward
Statutory breach regimes start the notification clock from the moment the organisation became aware, or reasonably should have become aware, of a notifiable breach. Awareness, not containment or internal governance, triggers and bounds the regulatory deadline.
errorMisconceptionIncident Management
The notification deadline to the regulator should run from the date technical containment of the affected systems is fully completed.
arrow_downward
Containment is an important operational milestone, so tying the clock to it feels logical. But notification obligations are anchored to awareness of the breach, not to completing technical remediation, which may come much later.
schoolConceptInformation Security Risk Management
Why is qualitative analysis the right first choice when a risk needs a fast, defensible prioritisation but no reliable frequency or loss data exists?
arrow_downward
Quantitative methods depend on credible occurrence and impact data to avoid false precision. When such data is unavailable and time is short, structured qualitative ratings of likelihood and impact give a defensible first-pass prioritisation that can later be refined quantitatively as data matures.
errorMisconceptionInformation Security Risk Management
Express every risk in annual loss expectancy so the board gets the precise monetary ranking it expects.
arrow_downward
Monetary figures look authoritative, which makes this tempting. But without occurrence and loss data the annual loss expectancy values rest on guessed inputs, producing false precision rather than a defensible ranking.
schoolConceptInformation Security Governance
When a frozen, fully committed budget cannot cover a new high-priority regulatory project, what is the disciplined resource-allocation response?
arrow_downward
Resource management means continuously steering finite funds toward the greatest risk reduction. Re-prioritise the existing portfolio and reallocate from lower-risk initiatives, supported by an impact assessment, so the highest-risk obligation is met without breaching governance and the deferred work stays visible.
errorMisconceptionInformation Security Governance
If the funding freeze blocks the regulatory project, the right move is to defer it to the next cycle and formally document the compliance exposure as an accepted risk.
arrow_downward
Tempting because it respects the freeze and uses formal risk acceptance, but accepting a known regulatory breach when reallocation is possible is poor stewardship, and the manager rarely has authority to accept that level of risk alone.
Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CISM and related marks belong to their respective owners.