The three primary goals of an information security program are to prevent the loss of confidentiality, the loss of integrity, and the loss of availability for any IT systems and data.
“The best solution for these “unknown unknowns” is to have an external, competent firm perform an organization’s risk assessment every few years or for such an organization to thoroughly examine an organization’s risk assessment for the purpose of discovering opportunities for improvement, including expanding the span of threats, threat actors, and vulnerabilities so that there are fewer or no unknown risks.”
― CISM Certified Information Security Manager All-in-One Exam Guide
― CISM Certified Information Security Manager All-in-One Exam Guide
“ultimate responsibility or ownership for protecting information is at the executive leadership and board of directors level.”
― CISM Certified Information Security Manager All-in-One Exam Guide
― CISM Certified Information Security Manager All-in-One Exam Guide
“Understanding and changing aspects of an organization’s culture is one of the most important success factors in an organization and also one of the most difficult.”
― CISM Certified Information Security Manager All-in-One Exam Guide
― CISM Certified Information Security Manager All-in-One Exam Guide
“Incident management is the IT function that is used to analyze service outages, service slowdowns, service errors, security incidents, and software bugs, as well as to restore the agreed-on service as soon as possible.”
― CISM Certified Information Security Manager All-in-One Exam Guide
― CISM Certified Information Security Manager All-in-One Exam Guide
“The leftover risk, known as residual risk, should be entered into the risk register for its own round of risk treatment.”
― CISM Certified Information Security Manager All-in-One Exam Guide
― CISM Certified Information Security Manager All-in-One Exam Guide
Johnson’s 2025 Year in Books
Take a look at Johnson’s Year in Books, including some fun facts about their reading.
More friends…
Favorite Genres
Polls voted on by Johnson
Lists liked by Johnson






























