Courseiva

CISM Information Security Risk Management Practice Question

An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?

⚠ Common exam trap

The trap here is assuming that local expertise or qualitative-only ratings can deliver consistency, when the key requirement is a defined and uniformly applied scoring scale.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It uses a defined and consistently applied risk scoring scale

Consistency across business units and jurisdictions depends on a defined, uniformly applied risk scoring scale. This ensures that likelihood and impact ratings are comparable, allowing the bank to aggregate risks, prioritize investments, and report meaningfully to the board and regulators. Local judgment and qualitative input are valuable, but they must operate within a common framework to produce reliable enterprise risk information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It automatically assigns the highest possible risk rating to all regulatory findings

    Why it's wrong here

    Automatically assigning the highest rating to every regulatory finding distorts prioritization and resource allocation. Not all findings carry equal risk, and treating them uniformly prevents management from focusing on the most significant exposures. A consistent methodology should rate each risk based on defined likelihood and impact criteria, not on the source of the finding.

  • ✗

    It uses qualitative ratings only, avoiding numerical scores

    Why it's wrong here

    Qualitative ratings can be useful, but without defined numerical or ordinal anchors, they are difficult to compare and aggregate across business units. The bank needs consistent measurement to prioritize risks and track changes over time. A purely qualitative approach without calibration increases subjectivity and reduces the reliability of enterprise-level risk reporting.

  • ✓

    It uses a defined and consistently applied risk scoring scale

    Why this is correct

    A defined, consistently applied scoring scale ensures that likelihood and impact ratings mean the same thing across business units and jurisdictions. This enables aggregation, comparison, and prioritization at the enterprise level. Without a common scale, risk results become subjective and cannot be reliably combined, undermining the bank's ability to manage risk holistically and report accurately to regulators and the board.

  • ✗

    It relies on the judgment of each local risk manager without central guidance

    Why it's wrong here

    Local judgment alone leads to inconsistent ratings, because different managers may interpret likelihood and impact differently. While local expertise is valuable, it must be constrained by a common framework. Without central guidance and calibration, the bank cannot compare or aggregate risks across jurisdictions, weakening enterprise risk management and regulatory reporting.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.