Courseiva

CISM Information Security Risk Management Practice Question

An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?

⚠ Common exam trap

The trap here is assuming that security risk is too technical for ERM and should stay in a separate report, when the real requirement is translation into business impact on shared scales.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Express security risks in business impact terms and integrate them into the enterprise risk register using common scales.

Integrating security risk into ERM requires translating technical exposure into business impact and using the enterprise's common scales so that cyber risk can be compared, aggregated, and prioritized alongside other risk types. This gives executives a unified view while preserving enough detail for ownership and treatment decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Express security risks in business impact terms and integrate them into the enterprise risk register using common scales.

    Why this is correct

    Translating security risk into business impact, such as revenue loss, regulatory penalty, or service disruption, and recording it on the enterprise's common scales allows ERM to compare and aggregate it with other risk types. This integration supports enterprise prioritization and gives executives a coherent view of total risk exposure.

  • ✗

    Convert all security risks into a single aggregate score and report only that score to ERM.

    Why it's wrong here

    Collapsing diverse risks into one score destroys the detail ERM needs to prioritize and assign ownership. An aggregate figure cannot show which specific exposures drive the total, whether they are increasing or decreasing, or which treatments are most cost-effective. Aggregation without underlying detail also makes the number difficult to audit or defend.

  • ✗

    Report security risks separately to the CISO only, keeping ERM focused on financial and operational risks.

    Why it's wrong here

    Isolating security risk from ERM prevents the organization from seeing how cyber exposure interacts with financial and operational risk, and it denies ERM the information needed for enterprise-level prioritization. Modern ERM frameworks expect technology and cyber risk to be represented within the enterprise profile, not managed in a separate silo.

  • ✗

    Report only risks that have already materialized as incidents so ERM deals with confirmed events.

    Why it's wrong here

    Restricting reporting to realized incidents makes the process reactive and removes the forward-looking perspective that risk management exists to provide. ERM needs leading indicators and assessed exposures to allocate resources before losses occur. Incident-only reporting also skews the enterprise view toward recent events rather than underlying likelihood and impact.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.