CISM · Domain 3
Information Security Program
About 33% of the exam
Program building blocks
- Charter grants authority and scope
- Roadmap sequences initiatives over years
- Policies and standards define requirements
- Architecture shapes how controls fit
- People, process, technology in balance
- Metrics prove the program works
- Governance approves, program delivers
From strategy to running program
- Strategy
- Charter
- Gap analysis
- Roadmap
- Resources
- Implement controls
- Measure
- Improve
- Charter
- mandate, scope, authority, sponsor
- Gap analysis
- current versus target state
- Roadmap
- prioritized, time-phased, funded
- Resources
- budget, people, tools, outsourcing
- Implement
- controls through projects and operations
- Measure
- KPIs, KRIs, maturity against targets
The program is how the strategy gets done; if it does not trace back to strategy, it is noise
Resources and budget
- Prioritize by risk, then by cost
- Build, buy, or partner for missing skills
- Outsource tasks, keep accountability inside
- Budget tied to roadmap milestones
- Show value delivered, not money spent
- Cost of controls below cost of risk
- Skills gap is itself a program risk
Asset classification
- Inventory
- Owner assigned
- Classify by impact
- Label
- Handle
- Review
- Owner classifies, never the security team
- Classification drives the control level
- Keep the scheme simple, three or four levels
- Over-classification costs, under-classification exposes
- Reclassify when value or law changes
Controls and baselines
- Preventive
- stops the event
- Detective
- finds it while or after
- Corrective
- restores after the event
- Deterrent
- discourages the attempt
- Compensating
- stands in for an impractical control
- Baseline
- minimum configuration for a class
- Administrative, technical, physical
- the three control types
Select controls from the risk assessment and the classification, then check cost against risk
Security architecture
- Defense in depth, no single control trusted
- Zero trust: verify every request, assume breach
- Segment networks by trust and function
- Least privilege and separation of duties
- Cloud: know the shared responsibility split
- Standard patterns speed consistent decisions
- Architecture review before major change
Awareness, training, education
- Awareness
- the what, changes attitude
- Training
- the how, builds skills
- Education
- the why, builds judgment
- Role-based
- developers, admins, executives differ
- Best metric
- phishing reported, behavior changed
- Weak metric
- completion rate alone
Measure behavior, not attendance
KGI, KPI and KRI
KGI, key goal indicator
- Was the objective achieved
- Lagging, outcome focused
- Speaks to the board
- Example: incidents with business disruption down
KPI, key performance indicator
- How well the process performs
- Efficiency and effectiveness of activities
- Example: patch SLA met, MTTD, MTTR
- Drives operational management
KRI, key risk indicator
- Early warning that risk is rising
- Leading, threshold triggers action
- Example: privileged accounts unreviewed
- Tied to a register entry
KGI says did we get there, KPI says how well we are doing it, KRI says trouble is coming
What makes a good metric
- Linked to an objective or a risk
- Specific, measurable, actionable, relevant, timely
- Drives the behavior you want
- Consistent definition, repeatable collection
- Normalized before comparing business units
- Measure what matters, not what is easy
- First step: decide the decisions it supports
Dashboards, scorecards, reports
- Dashboard
- current status, operational view
- Scorecard
- performance against set targets
- Board report
- risk posture, trends, business value
- Operational report
- volumes, times, exceptions
- Frequency
- matches decision cadence
- Benchmarking
- peers, needs matching definitions
- Trend
- direction beats a single number
A flat metric that never moves is probably not sensitive enough to be useful
Maturity models
- Level 1
- initial, ad hoc, heroics
- Level 2
- repeatable, project discipline
- Level 3
- defined, documented, standard
- Level 4
- managed, measured, controlled
- Level 5
- optimizing, continuous improvement
- Use
- baseline, target, roadmap priorities
Target the maturity the business needs, not level five everywhere
Integrate with IT and business processes
- Security gates in change management
- Requirements in every SDLC phase
- Procurement checks vendors before purchase
- HR triggers joiner, mover, leaver actions
- Project management includes security sign-off
- Configuration management keeps baselines true
- Embedded beats bolted on, always
Third parties and cloud
- Due diligence scaled to criticality
- Contract carries security requirements and SLAs
- Right to audit or independent reports
- Shared responsibility model spelled out
- Monitor continuously, not only at onboarding
- Exit plan and data return agreed
- Concentration risk from one vendor
Key formulas
- ROSI
- (risk reduction minus cost) over cost
- Risk reduction
- ALE before minus ALE after
- ALE
- SLE x ARO
- MTTD
- mean time to detect
- MTTR
- mean time to respond or recover
- Coverage
- controlled assets over total assets
ROSI credibility rests on the loss estimate; use incident history and threat intelligence
Reference strip: metrics, controls, models, integration
Metric families
- KGI: outcome achieved
- KPI: process performance
- KRI: early warning
- Leading predicts, lagging reports
- Strategic, tactical, operational levels
Control words
- Preventive, detective, corrective
- Deterrent, compensating, recovery
- Administrative, technical, physical
- Baseline, standard, configuration
- Design versus operating effectiveness
Maturity ladder
- Initial, repeatable, defined, managed, optimizing
- Level three: documented and standard
- Assess, set target, plan roadmap
- Reassess periodically to track progress
Program documents
- Charter, roadmap, budget
- Policies, standards, procedures
- Asset inventory and classification
- Architecture principles and patterns
- Metrics catalog and reporting calendar
Integration points
- Change and configuration management
- SDLC and DevOps pipelines
- Procurement and vendor management
- HR lifecycle events
- Project portfolio governance
Quick exam traps
- Trap: Training completion rate proves awareness is effective
- Trap: A KRI and a KPI measure the same thing
- Trap: The security team decides how data is classified
- Trap: Every process should aim for maturity level five
- Trap: More metrics always means better reporting
- Trap: A dashboard and a scorecard are interchangeable
- Trap: Outsourcing a control outsources accountability for it
- Trap: Pick metrics first, decide their purpose later
cybercertprep.com · original revision sheet written from the public body of knowledge