CISM Information Security Risk Management Practice Question
A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?
⚠ Common exam trap
The trap here is assuming that technical severity or control cost alone dictates risk treatment, rather than the organization's risk appetite and tolerance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The organization's risk appetite and tolerance
Risk treatment must be driven by the organization's risk appetite and tolerance, because these express how much risk leadership is willing to accept while pursuing objectives. Technical severity, control cost, and risk counts inform the analysis, but they do not determine acceptability. The chosen treatment should bring residual risk within tolerance and remain consistent with regulatory and business obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The number of similar risks already identified in the risk register
Why it's wrong here
The count of similar risks may indicate a trend or systemic issue, but it does not establish the acceptability of this specific risk. Treatment depends on the risk's likelihood, impact, and alignment with risk appetite. A large number of similar risks could even signal a need for stronger controls, but volume alone is not the deciding factor.
- ✗
The cost of the control compared to the asset's book value
Why it's wrong here
Control cost is relevant, but comparing it only to book value ignores data sensitivity, regulatory penalties, reputational harm, and patient safety. For protected health information, the business impact can far exceed the asset's book value. Treatment decisions should consider overall risk exposure and organizational tolerance, not merely a narrow accounting comparison.
- ✗
The technical severity rating from the vulnerability scanner
Why it's wrong here
Technical severity is an input to risk analysis, but it does not by itself determine treatment. A high-severity finding may be acceptable if the business impact is low or if compensating controls exist. Treatment decisions must reflect business context, regulatory obligations, and risk tolerance, not just scanner ratings, which can be noisy and lack business relevance.
- ✓
The organization's risk appetite and tolerance
Why this is correct
Risk appetite and tolerance define the amount and type of risk the organization is willing to accept in pursuit of its objectives. Treatment decisions must align with these thresholds. Without this context, a control decision may be inappropriate even if technically sound. This makes risk appetite and tolerance the primary factor guiding whether to accept, mitigate, transfer, or avoid the risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.