A final-revision summary for CISM. Study aid only - no notes are allowed in the proctored exam.
The four domains and weights
Domain Approx. weight Information Security Governance ~17% Information Security Risk Management ~20% Information Security Program ~33% Incident Management ~30%
Governance essentials
Term Idea Strategy Security direction aligned to business goals Policy / standard / procedure Intent / mandatory rules / step-by-step how-to RACI Responsible, Accountable, Consulted, Informed KPI vs KRI Performance indicator vs risk indicator
Risk management essentials
Term Idea Risk = likelihood × impact The core equation Risk responses Avoid, transfer, mitigate, accept Risk appetite / tolerance How much risk the business will accept Residual risk Risk remaining after controls
Incident management lifecycle
Preparation → Identification → Containment → Eradication → Recovery → Lessons learned.
Term Meaning BIA Business Impact Analysis RTO / RPO Recovery Time / Recovery Point Objective SLA / OLA Service / Operational Level Agreement
FAQ Can I bring notes to the CISM exam? No. CISM is a proctored exam. Use this for final revision before exam day only. Sources How this page was made
This page was drafted with AI assistance and checked against the official
provider's published information by our editorial team. It is general study
guidance, not official exam material. Verified against official sources on
2026-05-29 .
Independent resource
This page is an independent informational resource and is not affiliated
with, endorsed by, or sponsored by ISACA. Always verify requirements, fees
and policies with the official provider before you register.