Instiq

Information Security Management ExaminationStudy guide

SG (Information Security Management): Japan’s national level-2 exam certifying practical information-security management—threats and controls, ISMS, risk assessment, incident response, and related law.

About Information Security Management Examination (SG)

Information Security Management Examination (SG) is a Associate-level certification from IPA(情報処理技術者試験). This page organizes the exam scope into a 5-chapter, 22-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."

Exam domains (approximate weighting)

  • Security fundamentals~20%
  • Security management (ISMS/risk)~26%
  • Security controls~20%
  • Related fields & law~14%
  • Practice (Exam B case studies)~20%

Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.

Official exam information: https://www.ipa.go.jp/shiken/kubun/sg/outline.html

1Security fundamentals

  • 1.1Security Fundamentals (CIA, Authenticity, Accountability, Non-Repudiation)

    Learn the three pillars of information security (confidentiality, integrity, availability, i.e. CIA) and the complementary properties that extend them: authenticity, accountability, non-repudiation, and reliability. Since SG focuses on managing information security from the user-organization side, the aim is not rote memorization but understanding which management objective each property serves in practice.

  • 1.2Threats and Vulnerabilities (Human, Technical, and Physical Threats; Insider Misuse and Negligence)

    Learn the three categories of threats (human threats, technical threats, physical threats) and their relationship to vulnerabilities, and how risk materializes. SG places particular management emphasis on insider misuse and negligence—not just external attacks but how an organization manages intentional and unintentional risks from people inside it.

  • 1.3Cyberattack Techniques (Malware, Targeted Attacks, Web App Attacks, DoS, Supply Chain Attacks)

    Learn the types of malware, targeted attacks, phishing, and BEC (business email compromise), web application attacks such as SQL injection, XSS, and CSRF, DoS/DDoS attacks, password attacks, social engineering that exploits human psychology, and supply chain attacks that route through business partners. SG emphasizes not the attack mechanics themselves but how an organization detects, defends against, and responds to them.

  • 1.4Cryptography (Symmetric-Key, Public-Key, Hybrid Cryptography, Hashing, Key Management)

    Learn how symmetric-key cryptography and public-key cryptography work and when to use each, the hybrid cryptography that combines both, hash functions used to detect tampering, the phenomenon of cryptographic obsolescence where an older cryptographic scheme stops being safe, and, importantly for a manager, key management—the lifecycle of generating, storing, rotating, and disposing of keys.

  • 1.5Authentication and Digital Signatures (MFA, PKI, SSL/TLS)

    Learn about multi-factor authentication (MFA) and biometric authentication, which verify identity via multiple factors; digital signatures that prove authorship; the PKI (public-key infrastructure) and certificate authorities (CAs) that guarantee a public key's validity; challenge-response authentication that prevents impersonation over a network; and SSL/TLS that protects web communications.

2Security management

  • 2.1Information Asset Management and Risk Assessment

    Learn how to identify and classify information assets, the risk assessment procedure (risk identification, risk analysis, risk evaluation), how to choose among the risk treatment options (risk reduction, risk avoidance, risk transfer, risk acceptance), the difference between quantitative and qualitative risk analysis, and the residual risk that remains after treatment.

  • 2.2ISMS and Information Security Policy

    Learn about the ISMS (information security management system), the international standard ISO/IEC 27001, the operating cycle PDCA, the three-tier structure of information security policy, standards, and procedures, the Statement of Applicability (SoA) prepared for certification, and the meaning of ISMS certification.

  • 2.3Types of Controls and the Security Organization

    Learn the four categories of controls (technical, physical, human/personnel, and organizational controls), separation of duties and the principle of least privilege, organizational structures such as the CISO (Chief Information Security Officer) and a security committee, and the role of education and training.

  • 2.4Incident Management and CSIRT

    Learn the incident response process (detection/reporting -> triage -> containment -> eradication -> recovery -> post-incident activity), the difference in roles between CSIRT and SOC, internal reporting and escalation, evidence preservation and digital forensics, and the roles of the external organizations JPCERT/CC and JVN.

  • 2.5Business Continuity Management

    Learn the difference between BCP (business continuity plan) and BCM (business continuity management), the meaning and calculation of RTO (recovery time objective) and RPO (recovery point objective), disaster countermeasures (alternate sites, redundancy), and backup strategy (full, differential, and incremental backup, and the 3-2-1 rule).

3Security controls

  • 3.1Malware Countermeasures (Antivirus, EDR, Patch Management, Ransomware Defense)

    Learn how antivirus software detects malware via pattern matching (signature/definition files), and how behavior-based detection and EDR (Endpoint Detection and Response) address unknown threats. Cover patch management to close vulnerabilities, the sandbox technique for safely testing unknown executables in an isolated environment, and backups (the 3-2-1 rule, offline/offsite storage) as the cornerstone of ransomware defense — all from the perspective of organizational operational management.

  • 3.2Unauthorized Access and Network Security Controls (FW/IDS/IPS/WAF, DMZ, Zero Trust)

    Learn the division of labor among four mechanisms that protect different layers of network communication: firewalls, IDS (Intrusion Detection Systems), IPS (Intrusion Prevention Systems), and WAF (Web Application Firewall). Also cover the DMZ that isolates externally facing servers, VPNs that protect inter-site and remote-worker traffic, proxies that relay and control web access, the zero trust approach that goes beyond the limits of perimeter defense, and wireless LAN security (WPA3, rogue access point countermeasures).

  • 3.3Data Leak Prevention and Physical Security Controls (DLP, Encryption, Clear Desk, Access Control)

    Learn technical data-leak prevention controls — DLP (Data Loss Prevention), data encryption, and removable-device/data-exfiltration control — alongside physical controls: clear desk and clear screen policies, physical access (entry/exit) control, locks and surveillance cameras, physical destruction of storage media, and tamper resistance. These are organized through the lens of defense in depth, where technical and physical controls complement each other.

  • 3.4Access Management and Authorization (Least Privilege, RBAC, Privileged Account Management, Log Management)

    Learn the difference between three related-but-distinct concepts — identification, authentication, and authorization — plus the principle of least privilege and need-to-know, RBAC (Role-Based Access Control) that assigns permissions by role, the strict management required for privileged accounts that can touch the core of a system, the account lifecycle from onboarding through role changes to offboarding, and log management and monitoring that underpins after-the-fact traceability and anomaly detection.

4Related fields and law

  • 4.1Network and Database Fundamentals

    Learn the layered structure of TCP/IP, IP addresses and subnets, DNS name resolution, the roles of key protocols (HTTP/HTTPS, SMTP, DHCP), and the basics of database transaction management and access control—all to the depth an SG candidate needs.

  • 4.2System Audit and Service Management

    Learn the flow of system audit, in which an independent third party evaluates information systems, and its relationship to internal control; ITIL and the SLA (service level agreement) that underpin the continuous operation of IT services; availability management, which keeps systems running, and capacity management, which prepares for future load; and how audit evidence (logs) is handled as the basis for an audit.

  • 4.3Security-related Laws

    Learn the Act on the Protection of Personal Information, which governs proper handling of personal data; the Unauthorized Computer Access Prohibition Act; the Act on Countermeasures for Information Distribution Platforms (formerly the Provider Liability Limitation Act), which addresses rights-infringing information online; the Basic Act on Cybersecurity, setting national cybersecurity policy; the Unfair Competition Prevention Act, protecting trade secrets; the Electronic Signature Act, preventing impersonation; and the Penal Code offense of obstructing business by damaging a computer.

  • 4.4Management and Security Governance

    Learn information security governance led by management, corporate governance that disciplines the enterprise as a whole and the internal control that forms part of it, the Cybersecurity Management Guidelines that push executives toward security investment, and how supplier management fits within security governance.

5Practice (Exam B)

  • 5.1Risk Assessment in Practice

    Learn, through concrete organizational scenarios, how to identify and classify information assets in the field, calculate risk values (threat x vulnerability x asset value), set risk acceptance criteria, and build a response plan (mitigation, retention, avoidance, transfer) for the calculated risk.

  • 5.2Vendor and Supply Chain Management

    Learn, through concrete outsourcing scenarios, vendor selection and security requirements in contracts, managing re-subcontracting, the division of responsibility when using cloud services (the shared responsibility model), how to embed security requirements into an SLA, and audit and reporting obligations for vendors.

  • 5.3Security Education, Training, and Rule Operation

    Learn, through concrete organizational scenarios, how to design employee education, run and evaluate targeted-attack drills, thoroughly communicate rules and procedures, handle onboarding/offboarding procedures (account issuance and privilege revocation), respond to rule violations, and raise organization-wide security awareness.

  • 5.4Incident Response in Practice

    Learn, through a concrete incident response scenario, the flow of detection, initial response, containment, eradication, recovery, and post-incident activity, reporting and public communication, evidence preservation, recurrence prevention, and notification to relevant authorities (such as JPCERT/CC).