This document discusses information risk management and the role of the information security manager (ISM). It covers topics like implementing a risk management program, risk assessment methodologies, information security controls, and integrating risk management into business processes. The document is intended to represent approximately 33% of the content on the CISM examination.