Courseiva

CISM Information Security Risk Management Practice Question

An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?

⚠ Common exam trap

A common mix-up: candidates think the risk owner's acceptance is sufficient, but CISM emphasizes that risk acceptance must be within the risk appetite; otherwise, it is a violation of governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Insist on additional controls to reduce residual risk to at least 'medium'.

The organization's risk appetite mandates that residual risk must be at 'medium' or lower. With an inherent risk of 'high' and controls rated 'partially effective', the residual risk remains above the acceptable threshold. Therefore, the best course is to insist on additional controls to bring residual risk down to at least 'medium', ensuring compliance with the risk appetite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the risk since the risk owner has agreed.

    Why it's wrong here

    The risk owner cannot unilaterally accept risk exceeding the stated appetite; partially effective controls leave residual risk likely above medium, so the CISM must escalate to senior management for a formal exception decision. It is tempting because owners normally accept operational risks, and acceptance would be correct where residual risk already sits within appetite.

  • ✗

    Transfer the risk to an insurance company.

    Why it's wrong here

    Insurance transfers financial consequence, not the operational risk itself; residual risk remains above the 'medium' ceiling and the risk owner still owns it. Transfer suits low-frequency, high-severity losses where the exposure is insurable and quantified, not an unmitigated high inherent risk with partially effective controls.

  • ✓

    Insist on additional controls to reduce residual risk to at least 'medium'.

    Why this is correct

    Residual risk equals inherent risk adjusted by control effectiveness. Partially effective controls on a high inherent risk likely leave residual risk above the mandated medium ceiling, so acceptance breaches risk appetite and additional controls are required.

  • ✗

    Recommend revising the risk appetite to accommodate this risk.

    Why it's wrong here

    Revising the risk appetite to fit a single project inverts governance: appetite is set by leadership and drives decisions, not the reverse. Residual risk here stays above the 'medium' ceiling because controls are only partially effective. Changing appetite is legitimate only through formal periodic review, not to sanction one project's acceptance.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.