CISM Information Security Program Practice Question
An organization's information security program has a risk management process that identifies and assesses risks. However, the CISO notices that risk treatment decisions are often delayed, and some high-risk items remain unaddressed for months. Which of the following is the MOST likely root cause?
⚠ Common exam trap
The trap here is blaming the risk assessment methodology or lack of a register, when the real issue is often unclear ownership and decision rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk treatment responsibilities and decision authorities are not clearly defined.
The most likely root cause is that risk treatment responsibilities and decision authorities are not clearly defined. Effective risk management requires that each risk has an owner who is accountable for treatment decisions, and that decision-making authority is established. Without this clarity, risks may be assessed but not acted upon, causing delays and leaving high-risk items unaddressed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The risk assessment methodology is not quantitative.
Why it's wrong here
While quantitative methods can provide more objective data, the use of qualitative or semi-quantitative methods does not inherently cause delays in risk treatment. Many effective programs use qualitative assessments. The delay is more likely due to unclear ownership or decision-making processes rather than the assessment method itself.
- ✓
Risk treatment responsibilities and decision authorities are not clearly defined.
Why this is correct
When it is unclear who is responsible for making risk treatment decisions and who owns the risk, decisions can stall. Clear definition of roles, responsibilities, and decision authorities (e.g., risk owners, steering committee) ensures timely action. Without this, even well-assessed risks may languish because no one feels accountable for the next step.
- ✗
The organization lacks a formal risk register.
Why it's wrong here
A risk register is a tool for tracking risks, but its absence alone does not cause delays if other mechanisms exist. The core issue is accountability and decision-making. A register without assigned owners and escalation paths will not accelerate treatment. Thus, the lack of a register is less critical than the lack of defined responsibilities.
- ✗
Senior management does not review the risk assessment results.
Why it's wrong here
Senior management review is important for prioritization and resource allocation, but if responsibilities are clearly defined, treatment decisions can proceed without constant executive involvement. The primary failure is likely at the operational level where risk owners are not empowered or identified, leading to bottlenecks even with management oversight.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.