Courseiva

CISM Information Security Risk Management Practice Question

An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?

⚠ Common exam trap

The trap here is treating a reduction from high to medium as sufficient, when the defined appetite for payment card systems is low residual risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the gap and recommend additional controls to bring residual risk within appetite.

Risk appetite defines the amount of risk the organization is willing to accept, and residual risk above that threshold requires treatment. The manager should document the deviation and recommend additional controls to reduce residual risk to a low level for the payment gateway, then present the options and costs to leadership for a decision consistent with governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk by purchasing cyber insurance and take no further action.

    Why it's wrong here

    Insurance can transfer some financial impact but does not reduce the likelihood or fully address regulatory, contractual, and reputational consequences of a payment card breach. It is a treatment option that may complement controls, not a substitute for bringing residual risk within appetite. Relying on it alone would leave the organization outside its stated tolerance.

  • ✗

    Accept the residual risk because existing controls already reduce it from high to medium.

    Why it's wrong here

    Accepting the risk exceeds the stated appetite, which permits only low residual risk for payment card systems. The fact that controls reduced risk from high to medium does not make it acceptable. The manager must treat the gap between current and acceptable risk rather than declare victory based on improvement alone, because the organization has already defined its tolerance threshold.

  • ✓

    Document the gap and recommend additional controls to bring residual risk within appetite.

    Why this is correct

    When residual risk exceeds the defined appetite, the manager should document the deviation and propose treatment to close the gap. Recommending additional controls aligns the payment gateway with the organization's stated tolerance and gives leadership a clear decision point. This maintains the link between risk appetite, assessment results, and treatment planning, which is central to effective risk management.

  • ✗

    Revise the risk appetite statement so that medium residual risk becomes acceptable.

    Why it's wrong here

    Changing the appetite to match the current state inverts the purpose of a risk appetite statement and could weaken governance. Appetite should be set by leadership based on business objectives and obligations, not adjusted downward to avoid treatment work. Revising it solely to accommodate a known gap would undermine the credibility of the risk program and could increase regulatory exposure.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.