dc dotCreds
Reference guide

CISM Course Notes

Study CISM section notes, then jump straight into the guided course or related practice questions without losing your place.

Continue CourseStart PracticePDF downloads available in Pro.
Checking access

Checking Pro access...

Looking for your active Pro access before showing Course Notes. This usually takes just a moment.

Course Notes preview

Unlock Pro for the full per-exam reference guide.

Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.

Includes full Course Mode and Course Notes.

Section 11. Information Security Governance (17%)Preview
More in this section
  • 14 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 5 more exam tips in Pro version
  • 31 more related questions in Pro version

Summary

Governance makes security a business responsibility rather than a purely technical function. The information security strategy must support enterprise objectives, fit organizational culture, satisfy applicable obligations, and operate through clearly defined authority and accountability. Senior management sets direction and risk appetite; business and risk owners make business-risk decisions; the security manager advises, enables, measures, and reports. Frameworks, policies, metrics, budgets, and business cases should all trace back to business value and risk reduction.

Key Points

  • Governance sets direction, accountability, and oversight; management executes within that direction.

Common Mistakes

  • Treating governance as an IT or security-department responsibility only.

Exam Tips

  • CISM thinks top-down: business goals -> governance -> strategy -> program -> controls.
Section 22. Information Security Risk Management (20%)Preview
More in this section
  • 17 more key points in Pro version
  • 9 more common mistakes in Pro version
  • 5 more exam tips in Pro version
  • 37 more related questions in Pro version

Summary

Risk management identifies what matters to the enterprise, what could harm it, how likely and severe that harm is, and what management should do about it. Assess risk in business context, including emerging threats, vulnerabilities, control deficiencies, third parties, and dependencies. Choose treatments that bring residual risk within appetite/tolerance, assign accountable owners, and monitor for changes. CISM does not chase every vulnerability: it prioritizes risk to enterprise objectives.

Key Points

  • Risk exists in relation to an objective or asset; context determines significance.

Common Mistakes

  • Equating vulnerability severity with enterprise risk.

Exam Tips

  • CISM risk sequence: context -> assess -> treat -> owner accepts residual -> monitor/report.
Section 33. Information Security Program (33%)Preview
More in this section
  • 21 more key points in Pro version
  • 11 more common mistakes in Pro version
  • 6 more exam tips in Pro version
  • 63 more related questions in Pro version

Summary

The security program turns governance and strategy into repeatable operations. Build the right organization, inventory and classify assets, establish policies and standards, select and implement controls based on risk, test whether they work, measure the program, train people, manage external services, and report results. Program management is lifecycle work: design, implement, integrate, operate, assess, improve, and communicate. Controls are means to manage risk—not the end goal.

Key Points

  • The security program implements the information security strategy; the strategy should not be rewritten around whatever program already exists.

Common Mistakes

  • Treating the program as a collection of security tools.

Exam Tips

  • Program = people + process + technology + governance support.
Section 44. Incident Management (30%)Preview
More in this section
  • 21 more key points in Pro version
  • 11 more common mistakes in Pro version
  • 6 more exam tips in Pro version
  • 57 more related questions in Pro version

Summary

Incident management is a business capability, not just a technical response team. Prepare plans, roles, communication paths, BIA/BCP/DRP dependencies, classification criteria, tools, training, and exercises before an event. During an incident, confirm and assess what happened, prioritize by business impact, contain damage, preserve evidence, coordinate communications and third parties, eradicate the cause, recover safely, and track actions. Afterward, perform a blameless review, identify root cause and control/process failures, implement corrective actions, and reassess risk.

Key Points

  • Preparation determines response quality; roles and authority should not be invented during a major incident.

Common Mistakes

  • Treating incident response as only containment.

Exam Tips

  • Incident lifecycle mindset: prepare -> identify/evaluate -> contain -> communicate -> eradicate -> recover -> learn.