mediumMultiple Choice
CISM Practice Question: A large enterprise is implementing a new…
A large enterprise is implementing a new governance framework. The board has approved a risk appetite statement. What is the MOST important next step for the information security manager?
⚠ Common exam trap
It's easy for candidates to confuse the order of governance steps, mistakenly thinking that implementing controls (Option A) is the immediate next action, when in fact the risk acceptance criteria must be defined first to ensure controls are properly scoped and aligned with the board's risk appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define risk acceptance criteria and thresholds
Once the board has approved a risk appetite statement, the information security manager must translate that high-level appetite into actionable risk acceptance criteria and thresholds. This step is critical because it defines the specific boundaries (e.g., maximum acceptable monetary loss per incident, maximum tolerable downtime) that guide all subsequent risk treatment decisions. Without these criteria, technical controls (Option A) and training (Option D) cannot be properly scoped, and audit plans (Option B) would lack measurable benchmarks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement technical controls to reduce risks
Why it's wrong here
Deploying controls before translating the board's risk appetite into tolerance thresholds and treatment criteria inverts governance order; appetite must first be operationalised. It is tempting because controls deliver tangible risk reduction, and would be correct once appetite has been mapped to specific risk decisions.
- ✗
Develop an audit plan to monitor risk levels
Why it's wrong here
An audit plan measures conformance after criteria exist; with appetite approved but not yet translated into tolerance levels, there is nothing defined to audit against. It is tempting because monitoring provides assurance, and would be correct once risk tolerance thresholds have been established.
- ✓
Define risk acceptance criteria and thresholds
Why this is correct
A risk appetite statement expresses tolerance in principle; translating it into concrete acceptance criteria and thresholds makes it operational. This gives the information security manager measurable boundaries for deciding which risks require treatment, directly enabling consistent governance decisions across the enterprise.
- ✗
Conduct security awareness training for employees
Why it's wrong here
Awareness training addresses human behaviour, not the governance gap left after appetite approval; risk tolerance must first be defined and communicated. It is tempting because training is a common early response, and would be correct once appetite is translated into policy requirements employees must follow.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.