Courseiva

CISM Information Security Risk Management Practice Question

A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?

⚠ Common exam trap

The trap here is assuming that the highest-scoring or most business-critical risks automatically go to the board, when escalation is actually governed by residual risk exceeding documented risk appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risks whose residual risk level exceeds the organization's defined risk appetite.

Board-level risk acceptance is triggered when residual risk exceeds the appetite and tolerance thresholds that executive management has established. Inherent scores, business criticality, and remediation delays are inputs to analysis but do not by themselves indicate that a decision above delegated authority is required. Routing only appetite-breaching residual risks keeps the committee focused on exposures that genuinely require formal acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risks whose residual risk level exceeds the organization's defined risk appetite.

    Why this is correct

    Escalation for formal acceptance is driven by residual risk, not inherent risk, because implemented controls already reduce exposure. Only when the remaining exposure breaches the tolerance thresholds set by executive management does the risk require a decision at board level. Risks sitting inside appetite are managed by line management under delegated authority, so this criterion correctly routes decisions to the body empowered to accept them.

  • ✗

    Risks that the security team has been unable to remediate within the current fiscal year.

    Why it's wrong here

    Remediation delay reflects resourcing and scheduling constraints rather than the magnitude of exposure or the organization's willingness to bear it. A low-severity risk may linger for years without warranting board attention, while a newly identified severe exposure may require immediate escalation. The board accepts risk based on appetite breach, not on how long a ticket has remained open in the remediation queue.

  • ✗

    Risks that received the highest inherent risk scores before any controls were applied.

    Why it's wrong here

    Inherent scores describe exposure in a hypothetical uncontrolled state and are useful for prioritizing assessment effort, but they ignore the controls already deployed. A risk that scores extremely high inherently may be fully mitigated to an acceptable residual level, requiring no board action. Escalating on inherent scores alone floods the committee with risks that are already managed and dilutes attention from genuine exposures.

  • ✗

    Risks associated with systems that support the organization's most revenue-generating business processes.

    Why it's wrong here

    Business criticality is one input into impact rating, but it is not the escalation criterion by itself. A revenue-critical system with strong, tested controls may carry low residual risk and need no board acceptance. Conversely, a non-revenue system handling regulated data could breach appetite and demand escalation. Using revenue association alone misroutes governance decisions and ignores likelihood and control effectiveness.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.