Courseiva

CISM Information Security Risk Management Practice Question

A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?

⚠ Common exam trap

Test-takers frequently confuse the governance and documentation attributes of a risk methodology with the measurement consistency that actually makes assessments repeatable and comparable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It uses a consistent set of defined likelihood and impact criteria.

Repeatability and comparability depend on consistent measurement criteria. By defining what likelihood and impact mean and how they are rated, the organization ensures that different assessors evaluating the cloud POS platform or other systems will produce results that can be compared and trended. Documentation, governance approval and ERM alignment support the process but do not by themselves eliminate subjective variation in risk ratings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It documents the risk assessment results in a centralized risk register.

    Why it's wrong here

    A central risk register improves tracking and reporting, but documentation alone does not make assessments repeatable or comparable. The methodology must define consistent scales and criteria for likelihood and impact; otherwise, different assessors could still produce wildly different ratings for the same system, undermining trend analysis across the cloud POS platform and other business units.

  • ✗

    It aligns with the organization’s overall enterprise risk management framework.

    Why it's wrong here

    Alignment with the enterprise risk management framework is important for integration and reporting, but alignment alone does not guarantee repeatable or comparable assessments. The ERM framework provides the overarching structure; the information security risk methodology still needs explicit, consistent likelihood and impact criteria to produce reliable and comparable results for the cloud POS platform.

  • ✗

    It is reviewed and approved annually by the board of directors.

    Why it's wrong here

    Board review and approval provides governance oversight and legitimacy, but it does not ensure that individual assessments are repeatable. Even an approved methodology can be applied inconsistently if likelihood and impact criteria are vague or left to assessor judgment. The board’s role is to endorse the framework, not to define the operational criteria that make each assessment comparable.

  • ✓

    It uses a consistent set of defined likelihood and impact criteria.

    Why this is correct

    Defined likelihood and impact criteria are the foundation of repeatability and comparability. When assessors apply the same scales and definitions across the cloud POS platform and subsequent assessments, results can be meaningfully compared, aggregated and trended. Without this consistency, quantitative or qualitative ratings become subjective and cannot reliably support risk-based decisions or demonstrate changes in risk posture over time.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.