CISM Information Security Risk Management Practice Question
A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
Given the risk owner's refusal and the high residual risk exceeding appetite, the security manager should formally escalate to the risk management committee for a final decision, as per the established governance process. This ensures proper oversight and documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a detailed cost-benefit analysis to convince the risk owner to upgrade, but do not escalate until the analysis is complete.
Why it's wrong here
While a cost-benefit analysis might help, the immediate non-compliance and high risk require escalation per policy; delaying escalates the risk.
- ✗
Accept the risk owner's decision and update the risk register to reflect the deferred treatment with a note of the risk owner's acceptance.
Why it's wrong here
Deferring without escalation violates the risk appetite policy and could lead to non-compliance; the risk owner does not have the authority to accept such a high residual risk.
- ✗
Implement a compensating control, such as strong application-layer encryption, to reduce the residual risk to an acceptable level without upgrading TLS.
Why it's wrong here
Compensating controls may not meet the specific regulatory requirement; the regulation mandates TLS 1.3, so a compensating control is likely insufficient and still non-compliant.
- ✓
Escalate the issue to the risk management committee for a decision on whether to accept, mitigate, or defer the risk.
Why this is correct
This follows the governance process and ensures that the risk is evaluated at the appropriate level with authority to override the risk owner's stance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.