CISM Information Security Risk Management Practice Question
An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)
⚠ Common exam trap
The trap here is treating the risk register as a catch-all repository for technical inventories, when ownership and likelihood and impact ratings are the essential governance elements of each entry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The likelihood and impact ratings used to determine the risk level.
A risk register entry must identify who owns the risk and how severe it is. The named owner provides accountability for treatment and reporting, while likelihood and impact ratings establish the risk level that drives prioritization. Supporting details such as product versions, access lists, and network diagrams live in other repositories and should be referenced rather than embedded in the register.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The likelihood and impact ratings used to determine the risk level.
Why this is correct
Likelihood and impact ratings are core to any risk entry because they establish the risk level used for prioritization and comparison across the register. Without these ratings, the organization cannot consistently rank risks or track whether treatment reduces exposure over time. They also connect the entry to the risk analysis methodology and the organization's defined risk criteria.
- ✓
A named risk owner accountable for treatment decisions.
Why this is correct
Every risk entry needs an assigned owner who is accountable for selecting and executing treatment and for reporting status. Without ownership, risks linger unresolved because no one is answerable. The owner is typically the business or process leader who controls the affected asset, not the security team, ensuring that treatment decisions align with business priorities and that accountability is clear.
- ✗
The complete network diagram of the data center hosting the asset.
Why it's wrong here
Network diagrams are architecture documentation referenced during assessment, not components of an individual risk entry. Embedding full diagrams makes the register unwieldy and duplicates information maintained elsewhere. The risk entry should instead reference the affected asset or process, leaving detailed topology in the configuration management or architecture repository where it is version controlled.
- ✗
The specific antivirus product version deployed on affected endpoints.
Why it's wrong here
Product version details belong in asset or configuration inventories, not in the risk register entry itself. A risk register captures the risk statement, its causes, likelihood, impact, and treatment. Recording a specific endpoint product version adds maintenance burden and becomes stale quickly, while contributing nothing to understanding or managing the underlying risk.
- ✗
The names of every employee who has access to the affected system.
Why it's wrong here
Full access lists are access management records, not risk register content. Including them would bloat the register with volatile data that changes constantly and is better maintained in identity and access management systems. The register should describe the risk and its treatment, not serve as a personnel or entitlement inventory for the affected system.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.