mediumMultiple ChoiceObjective-mapped
CISM Practice Question: Has decided to adopt a risk-based approach to…
An organization has decided to adopt a risk-based approach to information security. What is the FIRST step the information security manager should take to implement this approach?
⚠ Common exam trap
It's easy for candidates to confuse the sequence of risk management activities, mistakenly believing that defining risk appetite or selecting a framework should come first, when in fact asset identification and risk assessment are the prerequisite steps that inform all other decisions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify and assess information assets and their associated threats and vulnerabilities.
The first step in implementing a risk-based approach is to identify and assess information assets along with their associated threats and vulnerabilities. This foundational activity provides the necessary context for all subsequent risk management decisions, including defining risk appetite, selecting a framework, and implementing controls. Without a clear understanding of what assets exist and what risks they face, any further steps would be based on assumptions rather than evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify and assess information assets and their associated threats and vulnerabilities.
Why this is correct
Risk identification and assessment form the foundation.
- ✗
Define the organization's risk appetite and risk tolerance levels.
Why it's wrong here
Risk appetite is defined by the board, often informed by initial risk understanding.
- ✗
Implement security controls based on industry best practices.
Why it's wrong here
Controls should be risk-driven, not based solely on best practices.
- ✗
Select a risk management framework such as ISO 31000 or NIST RMF.
Why it's wrong here
Framework selection occurs after understanding the organization's needs.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.