CISM Information Security Risk Management Practice Question
An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?
⚠ Common exam trap
The trap here is assuming that the security manager can simply approve risk acceptance or that any treatment can be applied without proper validation and authority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the cost-benefit analysis and ensure the risk is accepted by the appropriate authority.
Before a risk can be accepted, the cost-benefit analysis must be validated, and acceptance must be authorized by the appropriate level of management based on the risk score. The security manager's role is to facilitate this process, ensuring that the decision is informed and within governance. Thus, validating the analysis and obtaining proper authorization is the correct next step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approve the risk acceptance and document it in the risk register.
Why it's wrong here
Approving risk acceptance without further review may violate the organization's risk management policy, which typically requires acceptance by the appropriate authority based on risk level. The security manager may not have the authority to accept a high risk. Additionally, the cost-benefit analysis should be validated. This action bypasses governance and could leave the organization exposed to unacceptable risk.
- ✓
Validate the cost-benefit analysis and ensure the risk is accepted by the appropriate authority.
Why this is correct
Risk acceptance decisions must be based on a valid cost-benefit analysis and approved by the authority whose level matches the risk. The security manager should verify the analysis and escalate for acceptance. This ensures due diligence and proper governance. Only after validation and authorization should the risk be marked as accepted in the register. This step is critical before any acceptance is finalized.
- ✗
Transfer the risk by purchasing cyber insurance.
Why it's wrong here
Risk transfer is an alternative treatment, but the risk owner proposed acceptance. The security manager should not substitute a different treatment without evaluating its feasibility and cost. Insurance may not cover the full impact and could be more expensive than acceptance. The next step is to validate the acceptance proposal, not to unilaterally transfer the risk.
- ✗
Implement compensating controls to reduce the risk to an acceptable level.
Why it's wrong here
Implementing compensating controls may be appropriate if mitigation is chosen, but the risk owner proposed acceptance. The security manager should not unilaterally change the treatment decision without proper evaluation and approval. Compensating controls also incur costs that may not be justified if acceptance is ultimately approved. This action preempts the risk treatment decision process.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.