Courseiva
Information Security Risk ManagementmediumMultiple ChoiceObjective-mapped

CISM Information Security Risk Management Practice Question

An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?

⚠ Common exam trap

Many exam-takers confuse the order of the ISO 27005 phases, often jumping to risk treatment (selecting controls) or documentation (updating the register) before completing the mandatory risk analysis step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Analyze the likelihood and impact of the vulnerability being exploited.

According to ISO 27005, after risk identification (including discovering a new vulnerability), the next step is risk analysis, which involves assessing the likelihood and impact of the vulnerability being exploited. This analysis is required before any decision on risk treatment (e.g., mitigation, acceptance) can be made. Option C correctly identifies this sequential step in the ISO 27005 risk management process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Escalate the vulnerability to senior management for acceptance.

    Why it's wrong here

    Risk acceptance occurs after risk evaluation and treatment planning.

  • Update the risk register with the new vulnerability.

    Why it's wrong here

    Updating the risk register is part of risk identification and documentation, but the next step is risk analysis.

  • Analyze the likelihood and impact of the vulnerability being exploited.

    Why this is correct

    After risk identification, the next step is risk analysis to determine the level of risk.

  • Select and implement controls to mitigate the vulnerability.

    Why it's wrong here

    Controls are selected in the risk treatment phase, which comes after risk analysis and evaluation.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.