CISM Information Security Risk Management Practice Question
A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?
⚠ Common exam trap
Many candidates confuse risk acceptance with ignoring the risk, but CISM requires that acceptance be a deliberate, documented decision based on cost-benefit analysis, not merely a default when no controls exist.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The cost to mitigate is higher than the potential financial loss from a breach
Risk acceptance is justified when the cost of mitigation exceeds the potential financial loss from a breach. This aligns with the cost-benefit analysis principle in risk management: if the cost to implement controls (e.g., migrating to a more secure vendor or adding encryption) is higher than the expected loss (e.g., $50,000 in breach costs vs. $100,000 in mitigation), accepting the residual risk is economically rational. The decision must still ensure the risk is within the organization's risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The organization has no compensating controls in place
Why it's wrong here
Lack of controls increases risk, so acceptance without any controls is not prudent.
- ✓
The cost to mitigate is higher than the potential financial loss from a breach
Why this is correct
If mitigation costs outweigh the expected loss, acceptance is a sound business decision.
- ✗
The risk is within the organization's risk appetite but the business impact is high
Why it's wrong here
If impact is high, even moderate likelihood may exceed appetite; acceptance should only occur if residual risk is low.
- ✗
The vendor has a history of security incidents
Why it's wrong here
A history of incidents suggests higher likelihood, making acceptance inadvisable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.