SELECT A LESSON TO BEGIN
ISACA’s security-management standard — governance, risk, program, and incident management.
Security professionals moving into management: people who will own the program, not just operate the tools.
150 questions · 4 hours · passing score 450 (scaled 200–800) · requires 5 years’ experience to certify
Three tasters — the real track has hundreds, graded, with full rationale.
A. MTD = RTO + WRT. The recovery-time objective (restore the system) plus the work-recovery time (validate and resume work) cannot exceed the maximum the business can tolerate.
B. Risk acceptance for material risk is a business decision owned by senior management / the risk owner. The security manager advises and recommends; they do not own the acceptance.
B. A point-in-time MTTD is a KPI (performance). A forward-looking, threshold-breaching trend is a Key Risk Indicator (KRI) — it signals rising risk.
The full CISM track — lectures, graded checks and labs — is free to start. Create an account to save your progress, earn points and climb the leaderboard.