CISM Information Security Risk Management Practice Question
An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?
⚠ Common exam trap
The trap here is believing the security manager should either block the launch outright or defer compliance, when the correct role is to assess the risk and enable an informed business decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.
Effective risk management supports business objectives by making risk visible and manageable rather than by blocking initiatives. Assessing the launch against the new regulations and presenting treatment options with their business impact allows leadership to weigh speed against compliance exposure and make a documented, risk-aware decision within their authority.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recommend blocking the launch until the security team completes a full independent audit of the application.
Why it's wrong here
An outright block positions security as an obstacle rather than a business enabler and preempts leadership's authority to make risk decisions. A full audit may also be disproportionate at this stage. The manager's role is to inform the decision with assessed risk and treatment options, not to unilaterally halt a business initiative based on security's own judgment.
- ✓
Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.
Why this is correct
Assessing the launch against the new regulatory requirements gives leadership a factual view of the exposure, and presenting treatment options with business impact lets them make an informed risk-based decision. This respects the business unit's objectives while ensuring that regulatory risk is identified, evaluated, and consciously accepted or mitigated by the accountable owners.
- ✗
Delegate the regulatory risk decision to the business unit's legal counsel and document the outcome.
Why it's wrong here
Legal counsel advises on regulatory interpretation, but accountability for accepting information security risk rests with the business risk owners, informed by the security manager's assessment. Delegating the entire decision sidesteps the risk management process and leaves the security implications of the mobile application unexamined by the function responsible for evaluating them.
- ✗
Advise the unit to proceed with the launch and remediate regulatory gaps in a post-launch phase.
Why it's wrong here
Launching first and remediating later embeds regulatory and privacy risk into a live customer-facing product, where fixes are costlier and potential fines and reputational damage are already in play. This approach also violates the principle that risk should be identified and treated before committing to an activity, not after exposure to customers has begun.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.