CISM Information Security Programme Practice Question
A retail company is developing its information security program and needs to establish a process for identifying and managing risks associated with its e-commerce platform. The CISO has been asked to recommend a risk management approach that aligns with the organization's goal of maintaining customer trust and complying with PCI DSS. Which of the following should be the FIRST step in the risk management process?
⚠ Common exam trap
The trap here is jumping to risk treatment options like controls, insurance, or disaster recovery without first conducting a risk assessment to understand what needs to be treated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a risk assessment to identify and prioritize risks.
The correct answer is conducting a risk assessment to identify and prioritize risks. Risk management begins with understanding the risks to the organization's assets and objectives. This assessment informs all subsequent decisions, including which controls to implement, what risks to transfer, and how to plan for recovery. It ensures that efforts are targeted and effective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementing security controls to mitigate identified risks.
Why it's wrong here
Implementing controls is a later step in risk management, after risks have been identified and assessed. Without first identifying and prioritizing risks, controls may be misapplied or ineffective. This option skips the critical initial phase of understanding what risks exist. It could lead to unnecessary spending or gaps in protection, and does not align with a systematic risk management process.
- ✗
Purchasing cyber insurance to transfer risk.
Why it's wrong here
Cyber insurance is a risk treatment option, typically considered after risks have been assessed. It does not replace the need to identify and evaluate risks. Purchasing insurance without a clear understanding of the risk landscape could result in inadequate coverage or unnecessary premiums. It is not the first step; it is a response to identified risks that the organization chooses to transfer.
- ✓
Conducting a risk assessment to identify and prioritize risks.
Why this is correct
The first step in risk management is to identify and assess risks. This involves understanding the assets, threats, vulnerabilities, and potential impacts. For an e-commerce platform, this includes risks to customer data, payment processing, and availability. A risk assessment provides the foundation for all subsequent risk management activities, ensuring that controls are applied where they are most needed and that resources are allocated effectively.
- ✗
Developing a disaster recovery plan for the e-commerce platform.
Why it's wrong here
A disaster recovery plan is a component of risk treatment and business continuity, not the initial step. It addresses availability risks but does not encompass the full risk management process. Without a prior risk assessment, the plan may not address the most critical risks. Therefore, it is not the first step in risk management.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.