Courseiva
Information Security Risk ManagementmediumMultiple ChoiceObjective-mapped

CISM Information Security Risk Management Practice Question

A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?

⚠ Common exam trap

Many candidates confuse risk acceptance with ignoring the risk, but CISM requires that acceptance be a deliberate, documented decision based on cost-benefit analysis, not merely a default when no controls exist.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The cost to mitigate is higher than the potential financial loss from a breach

Risk acceptance is justified when the cost of mitigation exceeds the potential financial loss from a breach. This aligns with the cost-benefit analysis principle in risk management: if the cost to implement controls (e.g., migrating to a more secure vendor or adding encryption) is higher than the expected loss (e.g., $50,000 in breach costs vs. $100,000 in mitigation), accepting the residual risk is economically rational. The decision must still ensure the risk is within the organization's risk appetite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The organization has no compensating controls in place

    Why it's wrong here

    Lack of controls increases risk, so acceptance without any controls is not prudent.

  • The cost to mitigate is higher than the potential financial loss from a breach

    Why this is correct

    If mitigation costs outweigh the expected loss, acceptance is a sound business decision.

  • The risk is within the organization's risk appetite but the business impact is high

    Why it's wrong here

    If impact is high, even moderate likelihood may exceed appetite; acceptance should only occur if residual risk is low.

  • The vendor has a history of security incidents

    Why it's wrong here

    A history of incidents suggests higher likelihood, making acceptance inadvisable.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.