CISM Information Security Risk Management Practice Question
An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?
⚠ Common exam trap
The trap here is treating a reduction from high to medium as sufficient, when the defined appetite for payment card systems is low residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the gap and recommend additional controls to bring residual risk within appetite.
Risk appetite defines the amount of risk the organization is willing to accept, and residual risk above that threshold requires treatment. The manager should document the deviation and recommend additional controls to reduce residual risk to a low level for the payment gateway, then present the options and costs to leadership for a decision consistent with governance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk by purchasing cyber insurance and take no further action.
Why it's wrong here
Insurance can transfer some financial impact but does not reduce the likelihood or fully address regulatory, contractual, and reputational consequences of a payment card breach. It is a treatment option that may complement controls, not a substitute for bringing residual risk within appetite. Relying on it alone would leave the organization outside its stated tolerance.
- ✗
Accept the residual risk because existing controls already reduce it from high to medium.
Why it's wrong here
Accepting the risk exceeds the stated appetite, which permits only low residual risk for payment card systems. The fact that controls reduced risk from high to medium does not make it acceptable. The manager must treat the gap between current and acceptable risk rather than declare victory based on improvement alone, because the organization has already defined its tolerance threshold.
- ✓
Document the gap and recommend additional controls to bring residual risk within appetite.
Why this is correct
When residual risk exceeds the defined appetite, the manager should document the deviation and propose treatment to close the gap. Recommending additional controls aligns the payment gateway with the organization's stated tolerance and gives leadership a clear decision point. This maintains the link between risk appetite, assessment results, and treatment planning, which is central to effective risk management.
- ✗
Revise the risk appetite statement so that medium residual risk becomes acceptable.
Why it's wrong here
Changing the appetite to match the current state inverts the purpose of a risk appetite statement and could weaken governance. Appetite should be set by leadership based on business objectives and obligations, not adjusted downward to avoid treatment work. Revising it solely to accommodate a known gap would undermine the credibility of the risk program and could increase regulatory exposure.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.