CISM Information Security Program Practice Question
An organization's security program includes a risk assessment process. Which step should be performed FIRST?
⚠ Common exam trap
It's easy for candidates to confuse 'identify assets' as the first step because it seems intuitive, but CISM emphasizes that context must be set first to ensure the assessment is scoped and relevant, not just a generic inventory exercise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish the risk assessment context
Establishing the risk assessment context (C) is the first step because it defines the scope, objectives, and criteria for the assessment, ensuring alignment with organizational goals and risk appetite. Without this foundational step, subsequent activities like asset identification or risk calculation lack direction and may produce irrelevant or misleading results. In the CISM framework, context setting precedes all technical analysis to ensure the assessment is meaningful and actionable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identify assets and their value
Why it's wrong here
Identifying assets and their value is a component of risk assessment, but the process begins by establishing scope, objectives and context so the assessment aligns with business goals. It is tempting because asset inventory underpins analysis, yet without defined context the assessment lacks direction.
- ✗
Calculate the level of risk
Why it's wrong here
Calculating risk requires identified assets, threats and vulnerabilities as inputs; with none established, any likelihood or impact figure is unfounded. Quantifying risk is genuinely useful once asset valuation and threat identification are complete, which is why it appears plausible, but it cannot precede the inventory step the stem demands.
- ✓
Establish the risk assessment context
Why this is correct
Establishing the risk assessment context defines scope, objectives, criteria and assumptions before any identification or analysis occurs. Without this framing, subsequent risk identification and evaluation lack consistent boundaries, making the context step the necessary first action.
- ✗
Determine the likelihood of threats
Why it's wrong here
Likelihood cannot be assessed before the assets, threats and existing controls are identified; it is an input to later analysis. It is tempting because likelihood feels foundational, and would be correct once threat identification and vulnerability assessment have established the risk scenarios to rate.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.