CISM Information Security Risk Management Practice Question
An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?
⚠ Common exam trap
The trap here is jumping to a project recovery action such as reassignment or vendor negotiation, when the immediate obligation is to restore accurate risk reporting to the body that approved the treatment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the risk register to reflect the increased residual risk and report the treatment shortfall to the risk committee.
Risk treatment plans are approved on the basis of projected residual risk, so slippage changes the factual basis of that approval. The security manager must first update the risk register and notify the risk committee, enabling it to decide whether to fund acceleration, accept the higher exposure temporarily, or mandate compensating controls. Execution and vendor actions come after risk visibility is restored.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request an extension of the original project timeline from the vendor and continue monitoring.
Why it's wrong here
A vendor timeline extension addresses scheduling but does nothing to inform the risk committee that the exposure it accepted treatment for remains substantially unmitigated. Continuing to monitor without disclosure leaves governance operating on stale assumptions. Vendor negotiations may be part of the eventual response, but they follow, not precede, the obligation to report the changed risk position to the accountable body.
- ✓
Update the risk register to reflect the increased residual risk and report the treatment shortfall to the risk committee.
Why this is correct
When an approved treatment is not progressing, the residual risk is higher than the committee believed when it accepted the plan. The security manager's first duty is to restore accurate risk visibility by updating the register and informing the same governance body that approved the treatment. This keeps decision-makers able to re-evaluate acceptance, reallocate resources, or approve interim compensating controls based on current facts.
- ✗
Close the original risk entry and open a new one describing the delayed identity governance implementation.
Why it's wrong here
Reframing the risk as an implementation delay shifts the register entry from the underlying business exposure to a project management issue. The committee approved treatment for excessive access privileges, and that exposure still exists. Closing and reopening entries fragments the risk history, breaks trend reporting, and hides the fact that a previously accepted treatment is failing, which undermines the integrity of the risk register.
- ✗
Reassign the identity governance project to the security team so it can be completed faster.
Why it's wrong here
Unilaterally taking over a cross-functional project ignores the staffing, budget, and dependency realities that caused the delay, and the security team may lack the integration and change-management capacity the platform requires. Before any resourcing change, the governance body needs to know that residual risk has increased. Acting first on execution details without restoring accurate reporting inverts the correct order of risk management activities.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.