Cheat Sheet

CISM Cheat Sheet: Domains, Governance & Risk Terms

By The Exam Atlas Editorial Team · Verified 2026-05-29

A final-revision summary for CISM. Study aid only — no notes are allowed in the proctored exam.

The four domains and weights

DomainApprox. weight
Information Security Governance~17%
Information Security Risk Management~20%
Information Security Program~33%
Incident Management~30%

Governance essentials

TermIdea
StrategySecurity direction aligned to business goals
Policy / standard / procedureIntent / mandatory rules / step-by-step how-to
RACIResponsible, Accountable, Consulted, Informed
KPI vs KRIPerformance indicator vs risk indicator

Risk management essentials

TermIdea
Risk = likelihood × impactThe core equation
Risk responsesAvoid, transfer, mitigate, accept
Risk appetite / toleranceHow much risk the business will accept
Residual riskRisk remaining after controls

Incident management lifecycle

Preparation → Identification → Containment → Eradication → Recovery → Lessons learned.

TermMeaning
BIABusiness Impact Analysis
RTO / RPORecovery Time / Recovery Point Objective
SLA / OLAService / Operational Level Agreement

FAQ

Can I bring notes to the CISM exam?
No. CISM is a proctored exam. Use this for final revision before exam day only.

Sources