Courseiva

CISM Information Security Risk Management Practice Question

A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)

⚠ Common exam trap

The trap here is assuming that post-acquisition integration is mainly about collecting risk lists, when reliable assurance requires both standardized methodology and independent validation of the subsidiary's work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require the subsidiary to use the parent company's approved risk assessment methodology, scales, and scoring criteria.

Reliability of subsidiary risk data rests on two pillars: a common methodology so outputs are comparable, and independent validation so the process is actually followed and conclusions are evidence-based. Filtering reported risks, retaining divergent templates, and delegating acceptance without oversight each undermine one or both pillars, leaving the parent unable to trust or aggregate subsidiary assessments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delegate full authority for risk acceptance to the subsidiary's local management without oversight.

    Why it's wrong here

    Delegating acceptance without oversight removes the parent's ability to ensure that decisions align with enterprise appetite, particularly where subsidiary risks could affect group obligations, shared infrastructure, or consolidated financial reporting. Delegation can be appropriate within defined limits, but unbounded authority eliminates the governance linkage that makes the subsidiary's risk program part of the enterprise program rather than a parallel one.

  • ✗

    Allow the subsidiary to retain its existing risk assessment templates to preserve continuity with prior years.

    Why it's wrong here

    Preserving legacy templates perpetuates incompatible rating scales, risk categories, and definitions, making consolidation into enterprise reporting unreliable and error prone. Continuity with prior subsidiary reporting has some value for internal trending, but it cannot outweigh the need for consistent enterprise-level data after an acquisition. Mapping historical results into the new framework is the appropriate way to preserve trend information.

  • ✓

    Require the subsidiary to use the parent company's approved risk assessment methodology, scales, and scoring criteria.

    Why this is correct

    Consistent methodology is foundational to comparability and reliability. When the subsidiary scores likelihood and impact using the parent's defined scales and criteria, its outputs can be aggregated, trended, and compared against enterprise appetite without translation errors. Divergent methodologies produce ratings that look comparable numerically but rest on different assumptions, which silently corrupts enterprise-level reporting and prioritization decisions.

  • ✗

    Instruct the subsidiary to report only risks that exceed the enterprise risk appetite threshold.

    Why it's wrong here

    Filtering at the source hides the population of lower-rated risks that may aggregate into significant exposures or indicate emerging trends. It also removes the data the parent needs to validate scoring calibration, because only extreme cases would ever be visible. Reliable risk reporting requires the full assessment record to be available for review, with filtering applied later during aggregation and escalation.

  • ✓

    Perform independent validation of a sample of the subsidiary's assessments by the parent company's security team.

    Why this is correct

    Independent validation tests whether the assessments were performed as prescribed and whether conclusions are supported by evidence. Sampling a subset, re-scoring scenarios, and comparing results detects drift, bias, and gaps in the subsidiary's process. Combined with a common methodology, this verification activity provides reasonable assurance that reported results reflect actual conditions rather than optimistic self-assessment.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.