Glossary

CISM Glossary of Key Terms

By The Exam Atlas Editorial Team · Verified 2026-05-29

Plain-English definitions of the management terms that recur in CISM study. Simplified for learning; ISACA’s material is authoritative.

TermDefinition
GovernanceThe strategy, policies and oversight that direct and control security.
Business alignmentEnsuring security supports the organisation’s objectives.
Risk appetiteThe amount and type of risk an organisation is willing to pursue.
Risk toleranceThe acceptable variation around the risk appetite.
Residual riskThe risk left after controls are applied.
Inherent riskRisk before any controls are applied.
Risk responseAvoiding, transferring, mitigating or accepting a risk.
KPIKey Performance Indicator — measures how well something performs.
KRIKey Risk Indicator — signals rising risk.
PolicyA high-level statement of management intent.
StandardA mandatory rule supporting a policy.
ProcedureStep-by-step instructions to meet a standard.
RACIA responsibility model: Responsible, Accountable, Consulted, Informed.
Due careTaking reasonable steps to protect assets.
Due diligenceOngoing effort to identify and manage risk.
BIABusiness Impact Analysis — identifies critical functions and impacts.
RTORecovery Time Objective — target time to restore a function.
RPORecovery Point Objective — acceptable data loss.
Incident responseThe organised approach to handling a security incident.
Maturity modelA scale used to assess how developed a process is.
Third-party riskRisk introduced by vendors and partners.
Gap analysisComparing the current state to a desired state.

Sources