CISM Information Security Risk Management Practice Question
A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
⚠ Common exam trap
CISM often tests the misconception that a risk owner's decision is always final — candidates forget that risk acceptance authority is bounded by the organization's risk appetite and must be escalated when exceeded.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
When a risk owner refuses to accept a risk that exceeds the organization's stated risk appetite and the risk owner also refuses to treat it, the information security manager must escalate through the defined governance channel — here, the risk management committee. The risk appetite statement only permits moderate residual risk with explicit CRO approval, so the head of network operations cannot unilaterally defer a high-rated regulatory risk. Escalation ensures the decision is made at the appropriate authority level with full visibility of regulatory and reputational exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a detailed cost-benefit analysis to convince the risk owner to upgrade, but do not escalate until the analysis is complete.
Why it's wrong here
Delaying escalation while producing a cost-benefit analysis leaves a high regulatory risk untreated and bypasses the risk management committee, contrary to the stated escalation process. It is tempting because cost-benefit analysis is a legitimate step to influence a risk owner, but it does not replace escalation when the owner refuses.
- ✗
Accept the risk owner's decision and update the risk register to reflect the deferred treatment with a note of the risk owner's acceptance.
Why it's wrong here
The risk owner cannot unilaterally accept risk exceeding the appetite statement; only the CRO may approve moderate residual risk, so recording deferral misstates the acceptance. It is tempting because risk registers do document owner-accepted risks, but that applies within delegated authority, not to high regulatory exposure.
- ✗
Implement a compensating control, such as strong application-layer encryption, to reduce the residual risk to an acceptable level without upgrading TLS.
Why it's wrong here
The regulation mandates TLS 1.3 specifically, so application-layer encryption leaves the transport protocol non-compliant regardless of residual risk. It is tempting because compensating controls are valid when a requirement cannot be met, but here the mandated TLS 1.3 upgrade is achievable and the risk owner's refusal must be escalated.
- ✓
Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
Why this is correct
The risk owner's refusal exceeds their delegated authority because the risk appetite statement permits moderate residual risk only with CRO approval. Escalating to the risk management committee routes the accept, mitigate or defer decision to the body mandated to resolve it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.