CISM Information Security Risk Management Practice Question
A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?
⚠ Common exam trap
Candidates often confuse risk appetite with risk tolerance or with operational risk concepts such as assessment and residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The amount and type of risk that the organization is willing to pursue or retain to achieve its objectives.
Risk appetite expresses the amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives. It is a strategic, governance-level concept that sets the boundaries for risk-taking and guides decisions about security investments and risk treatment. It is distinct from tolerance, which defines acceptable variation, and from assessment or residual risk, which are operational concepts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The amount and type of risk that the organization is willing to pursue or retain to achieve its objectives.
Why this is correct
Risk appetite is a strategic statement of how much risk the organization is willing to accept in pursuit of its goals. It guides decision-making by setting boundaries for risk-taking and helps ensure that security investments align with business objectives. It is broader than tolerance and provides the context within which specific tolerances and thresholds are defined.
- ✗
The residual risk that remains after all reasonable controls have been implemented.
Why it's wrong here
This describes residual risk, not risk appetite. Residual risk is what remains after controls are applied, whereas risk appetite is the willingness to accept risk in the first place. Understanding the difference is important because appetite informs how much residual risk is acceptable, but it is not the same as the remaining risk itself.
- ✗
The process of identifying, analyzing and evaluating risks to determine their significance.
Why it's wrong here
This describes risk assessment, not risk appetite. Risk assessment is an operational activity that produces information about risks, while risk appetite is a governance-level statement about how much risk the organization is willing to take. Mistaking the two can cause the steering committee to focus on process mechanics instead of defining strategic risk boundaries.
- ✗
The maximum level of risk that the organization can tolerate before exceeding its risk tolerance.
Why it's wrong here
This describes risk tolerance or risk threshold, not risk appetite. Risk appetite is the amount and type of risk an organization is willing to pursue or retain in alignment with its objectives. Tolerance is the acceptable variation around that appetite. Confusing the two can lead to misaligned decisions, such as treating every risk above a threshold as unacceptable without considering strategic intent.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.