CISM Information Security Risk Management Practice Question
An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?
⚠ Common exam trap
The trap here is equating defensibility with quantitative precision, when in a data-poor, time-constrained situation a well-calibrated qualitative method is more defensible than fabricated numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A qualitative analysis using a defined likelihood and impact scale with calibrated subject matter expert judgment.
When historical loss data is scarce and results are needed quickly, a qualitative analysis with documented likelihood and impact scales and calibrated expert judgment is the most practical and defensible choice. It produces a consistent ranking without fabricating quantitative precision, and the documented scales allow reviewers to understand and challenge how each ERP risk was rated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A qualitative analysis using a defined likelihood and impact scale with calibrated subject matter expert judgment.
Why this is correct
Qualitative analysis with a defined likelihood and impact scale suits the limited historical data and the two-week window, because it relies on calibrated expert judgment rather than statistical loss data. It still produces a defensible, repeatable ranking of ERP risks when the scales and calibration criteria are documented, meeting the executives' need for prioritized results quickly.
- ✗
A quantitative analysis using annualized loss expectancy derived from industry breach cost benchmarks.
Why it's wrong here
Quantitative analysis depends on reliable frequency and loss data. Substituting generic industry breach benchmarks for the organization's own ERP loss history introduces significant estimation error, and building a defensible quantitative model within two weeks is unrealistic. The aggressive timeline and absence of historical data make this approach impractical here, even though it can be valuable in data-rich environments.
- ✗
A hybrid analysis that assigns monetary values to every identified ERP risk regardless of data availability.
Why it's wrong here
Forcing monetary values onto risks without supporting data creates false precision and undermines defensibility. A hybrid model is useful when some components are quantifiable, but assigning dollar figures to every risk when historical data is scarce means the ranking rests on invented numbers. That weakens rather than strengthens the executive presentation within the compressed two-week timeline.
- ✗
A control gap analysis mapped to ISO/IEC 27002 that ranks risks by the number of missing controls.
Why it's wrong here
A control gap analysis identifies missing safeguards, but the count of missing controls is not a measure of risk magnitude. A single missing control protecting critical ERP financial data may represent far greater risk than several gaps in low-value areas. This approach also does not incorporate likelihood or business impact, so it cannot deliver the defensible risk ranking executives requested.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.