CISM Information Security Risk Management Practice Question
A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)
⚠ Common exam trap
The trap here is treating a risk register as a simplified summary rather than a granular, owned, and obligation-linked inventory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Record each risk with an owner, inherent and residual ratings, and the linked business process or asset.
An effective risk register captures ownership, inherent and residual ratings, and business linkage, and it maps risks to the obligations they could affect. These practices enable prioritization and accountability. Aggregating findings, using only financial impact, or excluding controlled risks all reduce the register's usefulness for managing OT exposure where safety and availability are critical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rate every OT risk using only the maximum potential financial loss to keep scoring consistent.
Why it's wrong here
OT risk frequently involves safety, environmental, and availability consequences that financial loss alone does not capture. Using only financial impact understates risks that could cause physical harm or production outages. A consistent scoring method is desirable, but it must include multiple impact dimensions relevant to operational technology rather than a single monetary metric.
- ✓
Record each risk with an owner, inherent and residual ratings, and the linked business process or asset.
Why this is correct
Assigning an owner, documenting inherent and residual ratings, and linking to the affected process or asset makes the register actionable. Ratings show how controls change exposure, and linkage enables prioritization based on business impact. Without these elements, the register becomes a list that cannot drive treatment decisions or accountability in an OT context where safety and availability matter.
- ✗
Exclude risks that already have compensating controls from the register to reduce noise.
Why it's wrong here
Risks with compensating controls still require documentation because controls can fail, degrade, or be bypassed. Excluding them removes visibility into residual risk and prevents reassessment when conditions change. A sound register records the control environment and the residual rating, allowing management to monitor whether compensating measures remain effective over time.
- ✗
Aggregate all OT findings into a single enterprise risk to simplify board reporting.
Why it's wrong here
Aggregating distinct OT findings into one enterprise risk obscures the specific threats, affected assets, and owners needed for treatment. It prevents meaningful prioritization and tracking of residual risk over time. While summary reporting has value, the register itself must retain granular entries so that individual risks can be managed and reassessed as the OT environment changes.
- ✓
Map each OT risk to the relevant regulatory, contractual, or safety obligation it could affect.
Why this is correct
Mapping risks to regulatory, contractual, and safety obligations connects technical findings to compliance and business consequences. This helps prioritize risks that could trigger enforcement, breach contractual commitments, or endanger personnel. In OT environments governed by standards such as IEC 62443 and safety regulations, this linkage is essential for defensible risk decisions and resource allocation.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.