CISM › Information Security Risk Management
CISM Domain 2 covers risk identification, analysis, evaluation, treatment, and monitoring aligned to organizational risk appetite and tolerance. Questions test quantitative methods like SLE, ARO, and ALE, qualitative heat maps, control selection, residual risk calculation, and communicating risk to senior leadership. Expect scenario-based judgment calls on ownership, acceptance, and escalation rather than pure definitions.
CISM Information Security Risk Management — All 151 Questions
Every question in this domain with answers and detailed explanations.