Courseiva

CISM Information Security Risk Management Practice Question

An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?

⚠ Common exam trap

The trap here is believing the security manager should either block the launch outright or defer compliance, when the correct role is to assess the risk and enable an informed business decision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.

Effective risk management supports business objectives by making risk visible and manageable rather than by blocking initiatives. Assessing the launch against the new regulations and presenting treatment options with their business impact allows leadership to weigh speed against compliance exposure and make a documented, risk-aware decision within their authority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recommend blocking the launch until the security team completes a full independent audit of the application.

    Why it's wrong here

    An outright block positions security as an obstacle rather than a business enabler and preempts leadership's authority to make risk decisions. A full audit may also be disproportionate at this stage. The manager's role is to inform the decision with assessed risk and treatment options, not to unilaterally halt a business initiative based on security's own judgment.

  • ✓

    Perform a risk assessment of the launch against the new regulations and present treatment options with business impact to leadership.

    Why this is correct

    Assessing the launch against the new regulatory requirements gives leadership a factual view of the exposure, and presenting treatment options with business impact lets them make an informed risk-based decision. This respects the business unit's objectives while ensuring that regulatory risk is identified, evaluated, and consciously accepted or mitigated by the accountable owners.

  • ✗

    Delegate the regulatory risk decision to the business unit's legal counsel and document the outcome.

    Why it's wrong here

    Legal counsel advises on regulatory interpretation, but accountability for accepting information security risk rests with the business risk owners, informed by the security manager's assessment. Delegating the entire decision sidesteps the risk management process and leaves the security implications of the mobile application unexamined by the function responsible for evaluating them.

  • ✗

    Advise the unit to proceed with the launch and remediate regulatory gaps in a post-launch phase.

    Why it's wrong here

    Launching first and remediating later embeds regulatory and privacy risk into a live customer-facing product, where fixes are costlier and potential fines and reputational damage are already in play. This approach also violates the principle that risk should be identified and treated before committing to an activity, not after exposure to customers has begun.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.