Courseiva

CISM Information Security Program Practice Question

An organization's security program includes a risk assessment process. Which step should be performed FIRST?

⚠ Common exam trap

It's easy for candidates to confuse 'identify assets' as the first step because it seems intuitive, but CISM emphasizes that context must be set first to ensure the assessment is scoped and relevant, not just a generic inventory exercise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish the risk assessment context

Establishing the risk assessment context (C) is the first step because it defines the scope, objectives, and criteria for the assessment, ensuring alignment with organizational goals and risk appetite. Without this foundational step, subsequent activities like asset identification or risk calculation lack direction and may produce irrelevant or misleading results. In the CISM framework, context setting precedes all technical analysis to ensure the assessment is meaningful and actionable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identify assets and their value

    Why it's wrong here

    Identifying assets and their value is a component of risk assessment, but the process begins by establishing scope, objectives and context so the assessment aligns with business goals. It is tempting because asset inventory underpins analysis, yet without defined context the assessment lacks direction.

  • ✗

    Calculate the level of risk

    Why it's wrong here

    Calculating risk requires identified assets, threats and vulnerabilities as inputs; with none established, any likelihood or impact figure is unfounded. Quantifying risk is genuinely useful once asset valuation and threat identification are complete, which is why it appears plausible, but it cannot precede the inventory step the stem demands.

  • ✓

    Establish the risk assessment context

    Why this is correct

    Establishing the risk assessment context defines scope, objectives, criteria and assumptions before any identification or analysis occurs. Without this framing, subsequent risk identification and evaluation lack consistent boundaries, making the context step the necessary first action.

  • ✗

    Determine the likelihood of threats

    Why it's wrong here

    Likelihood cannot be assessed before the assets, threats and existing controls are identified; it is an input to later analysis. It is tempting because likelihood feels foundational, and would be correct once threat identification and vulnerability assessment have established the risk scenarios to rate.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.