Courseiva

CISM Information Security Governance Practice Question

A CISO is reviewing the organization's risk management process. The board has asked how the CISO ensures that security risks are managed within the organization's risk appetite. Which activity BEST demonstrates this?

⚠ Common exam trap

The trap here is equating a risk register or annual assessment with ongoing management within risk appetite, when appetite definition and KRI monitoring are the key governance activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defining risk appetite and tolerance levels, and monitoring key risk indicators against them.

The correct answer is defining risk appetite and tolerance levels and monitoring key risk indicators against them. In CISM, risk appetite is set by the board and communicated to management. The CISO ensures that security risks are managed within that appetite by establishing tolerance thresholds and monitoring KRIs. This provides continuous assurance that risks are within acceptable limits and that treatment decisions are aligned with business objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Purchasing cyber insurance to transfer residual risks that exceed the organization's tolerance.

    Why it's wrong here

    Cyber insurance is a risk treatment option, but it does not demonstrate that risks are managed within appetite. It transfers some financial impact but does not address the likelihood or other impacts of risks. The board needs assurance that risks are identified, assessed, and treated according to appetite, not just transferred.

  • ✗

    Implementing a risk register that lists all identified risks and their owners.

    Why it's wrong here

    A risk register is a tool for tracking risks, but it does not by itself ensure that risks are managed within appetite. It lacks the linkage to appetite and tolerance, and without monitoring against thresholds, it does not provide assurance. The register must be part of a broader process that includes appetite definition and KRI monitoring.

  • ✓

    Defining risk appetite and tolerance levels, and monitoring key risk indicators against them.

    Why this is correct

    This is correct because CISM defines risk appetite as the amount of risk an organization is willing to accept. By defining appetite and tolerance, and monitoring key risk indicators (KRIs), the CISO can demonstrate that risks are being kept within those bounds. This is an ongoing governance activity that provides the board with assurance that risk management is proactive and aligned with business objectives.

  • ✗

    Conducting an annual risk assessment and presenting the results to the board.

    Why it's wrong here

    An annual risk assessment is important, but it is a point-in-time activity. It does not demonstrate ongoing alignment with risk appetite or that risks are being managed within that appetite throughout the year. The board needs assurance that risk management is continuous and integrated into decision-making, not just an annual event.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.