CertArcStart 21 Day Free Access

CISM Glossary

108 CISM concepts defined from an exam and practitioner perspective. Covers risk management, governance, access control, incident response, BCP/DR, and security programme management — the four domains of the CISM exam.

ABCDEFGIKLMNOPRSTVZ

A

Access control
The process of limiting access to systems, data, and resources based on identity and assigned permissions. CISM covers access control from a programme management perspective: how policies are set, who owns them, and how compliance is monitored.
Annual Loss Expectancy (ALE)
A quantitative risk metric calculated as: ALE = Annual Rate of Occurrence (ARO) × Single Loss Expectancy (SLE). Expresses the expected financial loss from a risk per year. Used in quantitative risk assessment.
Annual Rate of Occurrence (ARO)
The estimated frequency that a specific threat event will occur within a one-year period. Used in quantitative risk calculations.
Asset
Anything of value to an organisation that must be protected. Information assets include data, systems, infrastructure, and intangibles like reputation. Asset classification drives the level of security controls applied.
Asset classification
The process of assigning value and sensitivity labels to information assets to drive proportionate security controls. Typical levels: public, internal, confidential, restricted. Owned by the data owner, not IT.
Audit trail
A chronological record of system activities that enables reconstruction of events. Audit trails support accountability, fraud investigation, and compliance verification.
Authentication
Verification of identity before granting access. Methods include something you know (password), something you have (token), something you are (biometric). Multi-factor authentication combines two or more methods.
Authorisation
Granting or denying specific permissions to an authenticated identity. Authentication asks "who are you?"; authorisation asks "what are you allowed to do?"
Availability
One of the three pillars of the CIA triad. Information and systems must be accessible to authorised users when needed. Availability threats include DDoS, hardware failure, and natural disasters.

B

Baseline security
The minimum set of security controls required for a system or environment. Anything below baseline is unacceptable. Controls above baseline are optional enhancements.
Business continuity plan (BCP)
A documented plan ensuring critical business functions can continue during and after a disruptive event. Broader than DR — covers people, processes, facilities, and technology. Developed using the Business Impact Analysis.
Business Impact Analysis (BIA)
The process of identifying critical business functions and quantifying the impact of disrupting them. Outputs: recovery priorities, RTOs, and RPOs. BIA is the foundation of BCP and DRP; business owners drive it, not IT.

C

Change management
The process for managing changes to systems and infrastructure in a controlled manner. Change management reduces the risk of unintended outages or security vulnerabilities introduced through uncontrolled changes.
Chief Information Security Officer (CISO)
The executive responsible for an organisation's information security programme. Typically reports to the CIO, CTO, or CEO. The CISM certification is directly aligned with this role.
CIA triad
The three core principles of information security: Confidentiality (limiting access to authorised users), Integrity (ensuring accuracy and completeness), Availability (ensuring access when needed). All security decisions reference the CIA triad.
COBIT
Control Objectives for Information and Related Technology. An ISACA governance framework aligning IT goals with business objectives. Referenced frequently in Domain 1 (Governance) questions. Provides a maturity model for evaluating governance performance.
Compensating control
A control implemented to mitigate a risk when the primary control cannot be implemented. Must provide equivalent or better risk reduction. Compensating controls require formal documentation and approval.
Compliance
Adherence to laws, regulations, standards, and internal policies. Compliance is a subset of governance. Compliance alone does not equal security — a system can be compliant with PCI DSS and still have exploitable vulnerabilities.
Confidentiality
Ensuring that information is accessible only to those authorised to access it. One pillar of the CIA triad. Controls for confidentiality include access control, encryption, and data classification.
Configuration management
The systematic management of system configurations to maintain consistency, integrity, and security. Includes baseline configurations, change tracking, and configuration audits.
Control
A safeguard or countermeasure designed to reduce risk. Controls are classified as preventive (stop an incident), detective (identify an incident), corrective (remediate after an incident), or deterrent (discourage action).
Corrective control
A control that minimises the impact of an incident and restores normal operations. Examples: restoring from backup, patching a compromised system. Applied after detection.
Cryptography
The science of securing information through encryption. CISM covers cryptography at a programme management level: key management policies, data-at-rest vs data-in-transit requirements, encryption standards, and certificate lifecycle management.

D

Data custodian
The IT team or individual responsible for maintaining the systems that store and process data. Implements controls determined by the data owner. Responsible for implementation, not for deciding what controls are needed.
Data owner
The business unit or individual accountable for a dataset — classifying it, defining access requirements, and approving access requests. Data owners are typically business function heads, not IT staff.
Defence-in-depth
A security architecture principle using multiple, overlapping layers of controls. A failure in one layer does not compromise the whole system. The CISM manager designs and oversees defence-in-depth strategies; they do not configure individual controls.
Detective control
A control that identifies and alerts on security events after they occur. Examples: intrusion detection systems, security event logging, access review audits.
Deterrent control
A control that discourages security violations. Examples: security cameras, warning banners on login screens, disciplinary policy statements. Deters rather than prevents.
Disaster recovery plan (DRP)
Documented procedures for restoring IT systems and infrastructure after a disruptive event. A subset of BCP focused on technology recovery. RTO and RPO targets from the BIA drive DRP design.
Due care
The level of care a reasonable and prudent person would exercise in the same situation. A legal standard that informs minimum security obligations. Organisations that fail due care can face legal liability.
Due diligence
The investigation and verification process before making a decision. In information security, applied to vendor risk assessments, M&A security reviews, and third-party evaluations.

E

Encryption
Transformation of readable data into an unreadable format using cryptographic algorithms. Protects confidentiality. CISM covers encryption governance: where it is required, what standards apply, and how keys are managed.
Exposure factor (EF)
The percentage of an asset's value that would be lost in a single loss event. Used in quantitative risk calculation: SLE = Asset Value × EF.

F

Firewall
A network security control that filters traffic based on defined rules. CISM covers firewalls as programme management artefacts: policy-driven configuration, change management, and periodic rule review.
Forensics (digital)
The process of collecting, preserving, analysing, and presenting digital evidence. CISM covers forensics from a programme perspective: maintaining chain of custody, legal hold procedures, and when to engage forensic specialists.

G

Gap analysis
A comparison of the current security posture against a target state or framework to identify deficiencies. Used in security strategy development and compliance assessments.
Governance
The system by which an organisation is directed and controlled. In information security: the framework of policies, roles, and accountability structures ensuring security objectives align with business objectives.
Guideline
Advisory recommended practice — the only non-mandatory level of the policy hierarchy. Guidelines suggest best practices but do not require compliance. Not to be confused with policies or standards, which are mandatory.

I

Identity and access management (IAM)
The framework for managing digital identities and access rights. Includes authentication, authorisation, provisioning, deprovisioning, and periodic access reviews. IAM failure patterns (privilege creep, orphaned accounts) are CISM exam favourites.
Impact
The magnitude of harm resulting from a threat successfully exploiting a vulnerability. One of two factors (with likelihood) used to calculate inherent risk. Impact should be expressed in business terms, not technical terms.
Incident
An event that has, or may negatively affect, the confidentiality, integrity, or availability of information assets. Not all events are incidents. Incidents require a response process; events require monitoring.
Incident response plan (IRP)
Documented procedures for detecting, containing, eradicating, and recovering from security incidents. The IRP is a subset of the overall incident management programme.
Information security governance
The collection of processes, structures, and mechanisms by which an organisation directs and controls its information security activities. The purpose: align security decisions with business strategy and ensure accountability.
Information security manager
The professional responsible for managing an organisation's information security programme. The CISM is designed for this role. Key responsibilities: strategy development, risk management, programme governance, and board reporting.
Information security policy
A mandatory high-level document stating management's intent regarding information security. All standards, procedures, and guidelines derive from policy. Approved by senior management or the board.
Information security programme
The totality of security activities, controls, resources, and governance mechanisms an organisation operates to manage information risk. Domain 3 (33% of CISM) covers programme management.
Inherent risk
The risk that exists before any controls are applied. Used as a starting point in risk assessment. Most organisations manage residual risk (risk after controls) in practice.
Integrity
Ensuring that information is accurate, complete, and has not been altered without authorisation. One pillar of the CIA triad. Controls for integrity include hashing, digital signatures, and version control.
ISO 27001
The international standard for an Information Security Management System (ISMS). Provides requirements for establishing, implementing, maintaining, and improving security. A certifiable standard — organisations can be audited for compliance.
ISO 27002
The code of practice for information security controls — companion to ISO 27001. Provides guidance on control selection and implementation across 14 control categories. The right framework when selecting controls for an ISMS.

K

Key Performance Indicator (KPI)
A measurable value demonstrating how effectively a security programme is achieving its objectives. KPIs are retrospective — they measure past performance. Complement with KRIs for forward-looking risk visibility.
Key Risk Indicator (KRI)
A metric providing early warning of increasing risk exposure. Forward-looking — signals risk trends before incidents occur. Example: number of critical patches undeployed beyond 14 days.

L

Least privilege
The principle that users should have the minimum access rights needed to perform their job functions. Reduces the attack surface for insider threats and credential compromise.
Likelihood
The probability that a threat will exploit a vulnerability to cause harm. One of two factors (with impact) used to calculate inherent risk. Can be expressed qualitatively (high/medium/low) or quantitatively (ARO).

M

Malware
Malicious software designed to disrupt, damage, or gain unauthorised access to systems. Types include viruses, worms, ransomware, spyware, and rootkits. CISM covers malware from a programme perspective: detection, response, and recovery processes.
Maximum tolerable downtime (MTD)
The maximum period an organisation can tolerate loss of a critical business function before the impact becomes unacceptable. MTD drives RTO requirements — RTO must be shorter than MTD.
Maturity model
A framework for evaluating the sophistication and effectiveness of a process or programme. CMMI and ISO 21827 (SSE-CMM) are security-relevant maturity models. CISM exams may reference maturity assessment in programme management contexts.

N

NIST CSF
NIST Cybersecurity Framework. A voluntary US framework organising security activities into five functions: Identify, Protect, Detect, Respond, Recover. Widely adopted as a communication and prioritisation tool. Not a certification standard.
NIST SP 800-53
A comprehensive catalogue of security and privacy controls for federal information systems, widely adopted in the private sector. More prescriptive than ISO 27002. Referenced in Domain 3 for control selection.
Non-repudiation
The ability to ensure that a party cannot deny having performed an action. Achieved through digital signatures, audit logs, and timestamping. Relevant in legal proceedings and fraud investigation.

O

Orphaned account
A user account that remains active after the user has left the organisation or changed roles. A common IAM failure mode; orphaned accounts represent an access control vulnerability.
Outsourcing risk
The risk that a third-party service provider introduces vulnerabilities or fails to maintain expected security controls. Critical principle: the organisation retains accountability even when functions are outsourced.

P

Patch management
The systematic process of applying software updates to remediate vulnerabilities. CISM covers patch management as a programme governance function: establishing standards, measuring compliance, and reporting on patch posture to management.
Penetration testing
Authorised simulated attacks on systems to identify exploitable vulnerabilities. Penetration testing is a technical activity; the CISM manager commissions tests, reviews results, and drives remediation — they do not conduct the tests themselves.
Physical security
Controls protecting physical access to facilities, hardware, and information assets. Includes access controls, surveillance, environmental controls (temperature, fire suppression), and clean desk policies.
Policy
A mandatory high-level statement of management intent. States what must be achieved but not how. Approved by senior management or the board. The highest level of the policy hierarchy.
Preventive control
A control designed to stop an undesirable event from occurring. Examples: access controls, encryption, multi-factor authentication, firewalls. Preferable to detective or corrective controls when cost is justified.
Privacy
The right of individuals to control how their personal information is collected, used, and disclosed. Privacy requirements (GDPR, PDPA, CCPA) are external constraints on information security programme design.
Privilege creep
The gradual accumulation of access rights beyond what a user needs, typically from inadequate periodic access reviews. A common IAM failure mode. Prevented through regular access reviews and role changes triggering immediate review.
Privileged access management (PAM)
Controls specifically applied to accounts with elevated privileges (domain admin, root, database admin). PAM controls include separate privileged accounts, session logging, privileged access workstations, and periodic privilege reviews.
Procedure
Step-by-step operational instructions for implementing a standard. The third level of the policy hierarchy. Mandatory in the sense that following the procedure is how the standard is met; operational staff use procedures daily.

R

Recovery point objective (RPO)
The maximum acceptable age of data that must be recovered after an incident. An RPO of 2 hours means losing up to 2 hours of data is acceptable. RPO drives backup frequency requirements.
Recovery time objective (RTO)
The maximum time allowed to restore a system or process after an incident. If a business function has an RTO of 4 hours, the organisation must restore it within 4 hours of a disruption. RTO must be shorter than MTD.
Residual risk
The risk remaining after controls have been applied. Residual risk must be formally accepted by the appropriate business owner, not the security team. Even the best controls leave residual risk.
Risk
The potential for an event to occur that will have a negative impact on the organisation. CISM treats risk as a function of threat, vulnerability, likelihood, and impact — always expressed in business terms.
Risk acceptance
A risk treatment option where the organisation acknowledges the risk and decides not to implement additional controls. Must be formally documented and approved by the appropriate business owner at the correct authority level.
Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of strategic objectives. Set by the board. Strategic, not operational. The security manager implements within risk appetite; the board defines it.
Risk assessment
The systematic process of identifying threats, vulnerabilities, likelihood, and impact to produce a risk rating. The output drives risk treatment decisions. CISM favours risk assessment before any treatment action.
Risk avoidance
A risk treatment option where the organisation stops the activity that creates the risk entirely. Example: not storing credit card numbers eliminates PCI DSS scope. Appropriate when risk cannot be economically mitigated.
Risk capacity
The maximum level of risk an organisation can absorb before financial or operational viability is threatened. Distinct from risk appetite (what the organisation is willing to accept) and risk tolerance (the operational threshold).
Risk management
The systematic process of identifying, assessing, treating, and monitoring risks to the organisation. Domain 2 of the CISM exam (20%). Risk management is an ongoing programme function, not a one-time project.
Risk mitigation
A risk treatment option where controls are implemented to reduce the likelihood or impact of a risk. The most common treatment. Mitigation reduces risk but rarely eliminates it — residual risk remains.
Risk register
A living document recording identified risks, their ratings, treatment decisions, owners, and status. The central tool of the risk management programme. Requires ongoing maintenance; not a one-time deliverable.
Risk tolerance
The acceptable variation from risk appetite in day-to-day operations. Set by senior management. The operational threshold below which security does not need to escalate. Distinct from risk appetite (board-level).
Risk transfer
A risk treatment option where the financial impact is shifted to a third party through insurance or contractual indemnification. Transfer does not eliminate the risk or the organisation's accountability — it manages the financial consequence.
Role-based access control (RBAC)
An access control model assigning permissions based on roles rather than individual identities. Simplifies IAM at scale: change the role, change the permissions for all users in that role.

S

Security architecture
The design of security controls, technologies, and processes collectively protecting an organisation's information assets. The CISM manager oversees architecture decisions; they do not design individual system configurations.
Security awareness programme
The ongoing effort to educate employees about security policies, threats, and responsibilities. The CISM candidate designs and oversees the programme. Effectiveness is measured through phishing simulation results, assessment scores, and incident pattern analysis.
Security baseline
The minimum set of security controls required for a system or environment. Below baseline is unacceptable. Controls above baseline are optional. Baselines should be maintained and updated as threats evolve.
Security governance framework
The structure of policies, roles, processes, and accountability mechanisms enabling security governance. Examples: COBIT, ISO 27001, NIST CSF. The CISM manager selects and adapts a framework appropriate to the organisation.
Security metrics
Measurements communicating the effectiveness of security controls and programme performance. Useful metrics are actionable, comparable to targets, and expressed in business terms. Volume metrics (number of incidents) are less useful than outcome metrics (mean time to contain).
Security operations centre (SOC)
A team and facility dedicated to monitoring, detecting, and responding to security events. The CISM manager governs the SOC: defines scope, sets metrics, and integrates SOC operations with incident response and risk management.
Security policy
The top-level mandatory document establishing management's intent and direction for information security. All security standards, procedures, and guidelines derive from the security policy. Approved by senior management.
Security strategy
A plan for achieving the organisation's security objectives, aligned to business strategy. Developed by the CISM manager, approved by senior management. The strategy defines direction; the programme implements it.
Segregation of duties (SoD)
A control dividing critical functions between multiple people to prevent fraud or error. No single person should control an entire high-risk process end-to-end. Classic example: the person who authorises a payment should not be the person who executes it.
SIEM
Security Information and Event Management. Technology aggregating and correlating log data from multiple sources to detect security events. The CISM manager governs SIEM as a detective control: defines what is monitored, what alerts are generated, and how events are triaged.
Single Loss Expectancy (SLE)
The expected financial loss from a single occurrence of a risk event. Calculated as: SLE = Asset Value × Exposure Factor (EF). Used in quantitative risk assessment.
Social engineering
Manipulation of people to obtain confidential information or access. Phishing, vishing, and pretexting are common forms. Security awareness training is the primary control. Social engineering bypasses technical controls by targeting humans.
Standard
A specific, mandatory requirement supporting a policy. Where policies state "what" must be done, standards state "how" at a measurable level. More specific than policy; less prescriptive than a procedure.

T

Third-party risk management
The process of assessing, monitoring, and managing security risks introduced by vendors, partners, and service providers. The organisation retains accountability for data processed by third parties. Requires pre-engagement assessment, contractual requirements, and ongoing monitoring.
Threat
A potential cause of an unwanted incident. Threats exploit vulnerabilities. ISACA classifies threats as natural, human (accidental or intentional), or environmental. Risk = f(threat, vulnerability, likelihood, impact).
Threat intelligence
Information about current or emerging threats, threat actors, and their tactics, techniques, and procedures (TTPs). Input to risk assessment and incident response. Used to prioritise controls and anticipate attack vectors.
Threat modelling
A structured process for identifying potential threats to a system and evaluating their risk. Used in security architecture and application security. Output: prioritised list of threats and recommended mitigations.
Two-person integrity
A control requiring two authorised individuals to perform a critical function together. Prevents single-person fraud or error. Stricter form of segregation of duties applied to the highest-risk operations.

V

Vendor risk assessment
An evaluation of a third-party vendor's security posture before engagement. Includes review of security policies, certifications (ISO 27001, SOC 2), penetration test results, and contractual security requirements. Ongoing, not just at onboarding.
Vulnerability
A weakness in a system, process, or control that could be exploited by a threat to cause harm. Vulnerabilities are identified through vulnerability assessments, penetration tests, and security reviews.
Vulnerability management
The systematic process of identifying, classifying, prioritising, and remediating vulnerabilities in information systems. A programme management function: establish policy, measure compliance, and report posture to management.

Z

Zero trust
A security architecture principle that does not assume trust based on network location. Every access request is verified, regardless of source. "Never trust, always verify." The CISM manager governs zero trust adoption as a programme-level strategic decision.
CISM FAQ →Domain 1: Governance →Domain 2: Risk Management →Study plan →

CertArc — CISM Exam Prep

Train the reasoning, not the answer

Scenario-based CISM practice. CISM Lens explanations that show why the stronger managerial answer wins. Adaptive spaced repetition that finds your weak domains.

Start free assessment

CertArc is not affiliated with, endorsed by, or sponsored by ISACA®. CISM® is a registered trademark of ISACA.