The two highest-yield artifacts in the workshop: the manager’s mindset and the trap-answer patterns. Print this and review it the morning of the exam.
| The trap (tempting but wrong) | What to do instead |
|---|---|
| Jump in and fix the problem yourself, technically | Direct and coordinate. The manager oversees the response and assigns specialists — CISM tests management judgment, not hands-on remediation. |
| Choose the most technically secure option | Choose the business-aligned option. The best answer balances security with cost, risk, and business objectives — not maximum security regardless of impact. |
| Accept the risk because the control is too expensive | Cost is the business’s call. The manager presents the risk and options; the business risk owner / senior management accepts or rejects residual risk. |
| Eradicate the malware immediately | Contain first. Isolate affected systems before eradicating, so the threat can’t spread and forensic evidence is preserved. |
| Patch the critical vulnerability right now | Assess business risk and follow the change/incident process. The manager prioritizes by risk and coordinates — reflexive action is a technician’s reflex. |
| Buy a new tool to close the gap | Start from the control objective and the risk. If an existing layer already meets it, new spend isn’t justified — risk drives selection, not novelty. |
| Conceal or delay the breach to protect reputation | Disclose to the appropriate parties within required timeframes. Duty to stakeholders and the law outranks protecting the organization’s image. |
| Let the IT or security team classify the data | The business data owner classifies data and approves access; IT (the custodian) only implements the protection. |
| Hand the board 4,000 vulnerability findings | Translate them into a few business risks with owners and impact. Governance wants decisions, not a raw data dump. |
| Build the strategy from the latest threats and technology | Build it from business objectives via gap analysis. Strategy flows from the business down — never from technology up. |
CISM® Independent study aid — not affiliated with or endorsed by ISACA. Verify the current exam content outline at isaca.org.