CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2024)

ISACA CISM

When it comes to proving technical competency and business skills in enterprise information security, IT professionals have no better option than becoming CISM certified. The route to attaining CISM involves a crucial exam, which tests a candidate on four knowledge areas (otherwise known as CISM domains).

Incident management (IM) identifies, evaluates, manages and documents security risks that may adversely affect an organization’s information assets. Expertise in IM proves that you can help an organization become more resilient to security incidents while reducing liability and legal exposure.

Let’s dive into the specifics of the IM domain and how it has changed after the latest CISM exam update.

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (1)

$150,040 average salary

ISACA CISM is one of the industry's highest-paying cybersecurity certifications for 2023. Take your information security management career to new heights and enroll now to claim your Exam Pass Guarantee!

View Pricing

Incident management overview

Before the updated CISM exam that became effective on June 1, 2022, incident management had a 19% weightage with 29 exam questions. But after the exam refresh, its weightage increased to 30% with 45 exam questions. This points to the fact that ISACA (the exam creator) now emphasizes the incident management domain, which is crucial to mitigating security events and preventing disruptions in operations.

Candidates will have to demonstrate the ability to contain and manage disruptions, including environmental disruptions (e.g., earthquakes, storms), technical disruptions (e.g., DDoS and malware intrusions), and the broad category of mistakes and intentional acts (e.g., fraud and espionage). The primary cause of each disruption must be clearly defined, and the incident response must be consistent and easy to understand for relevant stakeholders (IT department, management, incident handlers and end users).

Organizations look for proficiency in incident management because such expertise can help them:

  • Diagnose incidents quickly and accurately
  • Identify root causes
  • Minimize and contain the damage
  • Document and report
  • Deploy improvements to prevent a recurrence
  • Restore affected systems and services

CISM candidates should also note that employers will expect them to balance incident management capabilities with baseline security, disaster recovery, and business continuity. For example, if the incident response will take a while to execute, it would be wise to raise the baseline security level. Additionally, candidates should know when the inability to effectively manage a security event calls for a disaster declaration.

What’s new in the incident management domain?

ISACA has divided the incident management domain into two sections:

  • Section 1: Incident management readiness
  • Section 2: Incident management operations

The updated exam also adds a few new topics to the IM domain:

  • Incident Response Concepts.Candidates must show a general understanding of the different concepts relevant to incident response. Examples include basic security principles (e.g., confidentiality and availability), network protocols (e.g., Address Resolution Protocol), and network applications and services (e.g., network file system and secure shell).
  • Incident Management and Incident Response Plans. A new addition to CISM domain 4, this module includes everything from IM resources and objectives to metrics, procedures, and the status of incident response capability.
  • Business Continuity Plan (BCP).This is a new section in domain 4 and includes important measurements like BIA (Business Impact Analysis), MTD (Maximum Tolerable Downtime), and RPO (Recovery Time Objective).
  • Incident Management Systems. A new, independent module in CISM domain 4, incident management systems, explores areas like endpoint detection and response and managed incident strategies.
  • Incident Containment Methods. Candidates may be asked to elaborate on the procedures and strategies for containing an incident (e.g., disabling certain functions, shutting down a system etc.)
  • Incident Eradication and Recovery. This covers both eradication activities and recovery as they relate to the operational areas of the business.

Incident management exam outline

The new CISM exam outline contains a few subtopics that previously weren’t present in the incident management knowledge domain. Here’s a brief overview of what you need to prepare for:

CISM Domain 4: Incident Management

Section 1: Incident Management ReadinessSection 2: Incident Management Operations1.1. Incident Response Plan2.1 Incident Management Techniques and Tools1.2 Business Impact Analysis2.2 Incident Investigation and Evaluation1.3 Business Continuity Plan2.3 Incident Containment Methods1.4 Disaster Recovery Plan2.4 Incident Response Communications (e.g., notification, reporting, escalation)1.5 Incident Categorization/ Classification2.5 Incident Recovery and Eradication1.6 Incident Management Testing, Evaluation, and Training2.6 Post-incident Review Practices

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2)

$150,040 average salary

ISACA CISM is one of the industry's highest-paying cybersecurity certifications for 2023. Take your information security management career to new heights and enroll now to claim your Exam Pass Guarantee!

View Pricing

Summary of incident management

CISM domain 4 covers all the strategies required to manage and respond to unexpected disruptive events. Candidates should be able to do this within an acceptable interruption window (AIM) to minimize the impact on clients and their trust in the organization. The domain may traverse through disaster recovery and business continuity procedures, so candidates should also be prepared for those.

If you’re scheduled to take the CISM exam, familiarizing yourself with the intricate details of incident management will help you ace 30% of the assessment. Hopefully, this domain overview will broaden your horizon and help you develop an effective incident management plan. Check the ISACA CISM hub for a detailed overview of all CISM domainsand other topics related to the CISM exam.

Sources

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2024)
Top Articles
Latest Posts
Article information

Author: Otha Schamberger

Last Updated:

Views: 5718

Rating: 4.4 / 5 (55 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Otha Schamberger

Birthday: 1999-08-15

Address: Suite 490 606 Hammes Ferry, Carterhaven, IL 62290

Phone: +8557035444877

Job: Forward IT Agent

Hobby: Fishing, Flying, Jewelry making, Digital arts, Sand art, Parkour, tabletop games

Introduction: My name is Otha Schamberger, I am a vast, good, healthy, cheerful, energetic, gorgeous, magnificent person who loves writing and wants to share my knowledge and understanding with you.