Courseiva

CISM Information Security Programme Practice Question

A security manager is establishing a formal risk management process. The organization wants to ensure that risk treatment decisions are consistent and documented. Which TWO of the following are essential elements of an effective risk treatment plan? (Choose two.)

⚠ Common exam trap

The trap here is treating assessment inputs or funding activities as treatment plan elements, when the plan must capture risk response decisions and accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Defined risk response options mapped to each identified risk

An effective risk treatment plan documents the chosen response for each risk and records formal acceptance of residual risk by the accountable business owner. These elements ensure decisions are consistent, traceable, and aligned with risk appetite, enabling the organization to demonstrate due care and manage risk deliberately rather than incidentally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Defined risk response options mapped to each identified risk

    Why this is correct

    A risk treatment plan must specify the chosen response—mitigate, transfer, avoid, or accept—for each risk. Mapping responses ensures consistency and clarity. This element transforms assessment findings into actionable decisions, providing direction for control implementation and establishing the basis for measuring treatment effectiveness over time.

  • ✗

    Technical vulnerability scan results for all systems

    Why it's wrong here

    Vulnerability scan results are inputs to risk identification and assessment, not an element of the treatment plan itself. While valuable for understanding exposure, they do not define how risk will be treated, who owns it, or what residual level is acceptable. Including scans as a treatment element confuses assessment activities with treatment decisions.

  • ✗

    Approval of the IT budget for security tools

    Why it's wrong here

    Budget approval is a funding activity that may follow risk treatment decisions, but it is not an essential element of the treatment plan. The plan defines what will be done about each risk; funding enables execution. Treating budget approval as a plan element inverts the sequence and can result in tool purchases that are not tied to prioritized risks.

  • ✓

    Documented risk acceptance by the appropriate business owner

    Why this is correct

    Risk acceptance must be formally documented and approved by the business owner who has authority over the affected asset or process. This ensures accountability and provides an audit trail. Without documented acceptance, residual risk remains unmanaged and the organization cannot demonstrate due care to regulators or stakeholders.

  • ✗

    A list of all security controls implemented across the enterprise

    Why it's wrong here

    An inventory of controls supports assessment and gap analysis but is not itself a treatment plan element. The plan focuses on decisions about specific risks, not a catalog of existing controls. Confusing the two can lead to control-centric planning that misses whether risks are actually reduced to acceptable levels.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.