CISM · domain
Information Security Risk Management
CISM Domain 2 covers risk identification, analysis, evaluation, treatment, and monitoring aligned to organizational risk appetite and tolerance. Questions test quantitative methods like SLE, ARO, and ALE, qualitative heat maps, control selection, residual risk calculation, and communicating risk to senior leadership. Expect scenario-based judgment calls on ownership, acceptance, and escalation rather than pure definitions.
Focused practice
Practice Information Security Risk Management questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Information Security Risk Management
You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.
Calculating SLE, ARO, and ALE to justify or reject a safeguard's cost
Distinguishing inherent risk, residual risk, risk appetite, and risk tolerance
Assigning risk ownership to business process owners, not information security
Selecting risk treatment: mitigate, transfer, avoid, or accept with approval
Watch out for
Common Information Security Risk Management exam traps
- ▸Confusing risk appetite (desired level) with risk tolerance (acceptable deviation) and applying them interchangeably in scenario answers
- ▸Treating residual risk as zero after controls are implemented instead of recalculating likelihood and impact
- ▸Assuming information security owns business risk; accountability stays with the business process or asset owner
Question index
All Information Security Risk Management questions (122)
Click any question to see the full explanation, or start a practice session above.
After implementing controls, an organization reassesses a risk and finds that the residual risk level exceeds the established risk tolerance. What is the most appropriate next step?
Medium2A global manufacturing firm is expanding into a new region where data residency laws differ significantly from its home country. The CISO must present a risk treatment plan to the board. Which of the following is the MOST appropriate FIRST step in aligning risk treatment with the organization's risk appetite?
Medium3An information security manager is reviewing a risk assessment for a core banking application. The assessment shows a high likelihood of insider misuse of privileged accounts and a high impact on regulatory compliance. The application owner proposes adding database activity monitoring, but the budget is limited and the control would take nine months to deploy. Which of the following is the MOST appropriate immediate action?
Hard4An organization's risk management policy requires a quantitative risk assessment for all new projects. The project team estimates that a data breach could occur once every 5 years with an average loss of $2 million. What is the annualized loss expectancy (ALE)?
Hard5Which THREE of the following are essential components of an information security risk management framework?
Hard6An organization calculates that the single loss expectancy (SLE) for a server failure is $10,000, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Medium7A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?
Hard8Which TWO of the following are key components of an information security risk assessment? (Choose two.)
Easy9A security manager is building a risk register for a newly deployed customer relationship management platform. Which TWO of the following entries are most appropriate to record as risks rather than as controls or assets? (Choose two.)
Medium10An organization is conducting a risk assessment for a new cloud-based HR system. Which THREE of the following are key considerations when evaluating the inherent risk?
Hard11A global financial services firm uses a Monte Carlo simulation model to quantify the potential financial impact of cyber events. The model inputs include historical loss data, threat intelligence, and control effectiveness. Over the past year, the model has consistently underestimated actual losses by an average of 40%. The risk manager suspects model risk but the quantitative team argues the model is peer-reviewed. The board is concerned about the accuracy of risk reporting. What is the best course of action for the risk manager?
Hard12An organization has a risk appetite that allows for a maximum residual risk level of 'medium' for all operational risks. A new project introduces a risk with inherent risk level 'high' and control effectiveness rated as 'partially effective'. The risk owner proposes to accept the risk. As the CISM, what is the best course of action?
Hard13A large retail chain with hundreds of stores uses point-of-sale (POS) systems that run an outdated operating system. The annual risk assessment identified this as a high-risk issue because the OS is no longer patched and has known vulnerabilities. The business unit manager opposes replacing all POS systems immediately due to cost and potential disruption to operations. As the risk manager, you need to recommend a risk response that balances risk reduction with business continuity. Which strategy is most appropriate?
Medium14An organization is implementing a quantitative risk analysis for a critical application. The asset value is $2,000,000. The exposure factor (EF) is 0.25, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
Hard15A healthcare insurer's third-party risk manager learns that a critical claims-processing vendor has been acquired by a foreign parent company subject to different data protection laws. The vendor contract contains no change-of-control clause. What should the risk manager do FIRST?
Medium16A security analyst is identifying assets to include in a risk assessment for a new e-commerce platform. The platform will process credit card payments and store customer personal information. Which of the following should be considered the MOST critical asset to protect?
Easy17A hospital’s CISO is reviewing a critical clinical application that cannot be patched due to vendor certification constraints. The risk of exploitation is assessed as high. The hospital has implemented network segmentation and enhanced monitoring as compensating controls. Which of the following is the MOST appropriate next step to manage this risk?
Hard18An information security manager is reviewing a risk register that contains a risk with a risk score of 20 (likelihood 5, impact 4). The risk owner proposes to accept the risk because the cost of mitigation exceeds the potential loss. Which of the following should the security manager do NEXT?
Hard19A security manager is presenting risk analysis results to the board. Which of the following should the manager include to effectively communicate risk? (Select THREE)
Hard20Which TWO of the following are examples of risk mitigation controls? (Choose two.)
Easy21A healthcare insurer is completing its annual enterprise risk assessment. The CISO has compiled a list of 40 information security risks, each scored for likelihood and impact. The CIO asks which risks should be escalated to the board's risk committee for formal acceptance. What is the MOST appropriate criterion for selecting which risks to escalate?
Medium22A retail company has a risk register that includes a risk related to point-of-sale (POS) malware. The risk owner has decided to implement an endpoint detection and response (EDR) solution to reduce the risk. Which risk treatment strategy is being applied?
Easy23Which role is primarily responsible for ensuring that information security risks are identified, assessed, and managed within a business unit?
Easy24A global insurer completes an annual enterprise risk assessment and reports its top information security risk as a residual risk score of 16 (5x3 on a 5x5 matrix) after applying a data loss prevention solution and security awareness training. The board has stated that any residual risk above 12 must be escalated for a formal risk treatment decision. The CISO is asked to present options at the next risk committee meeting. Which of the following is the MOST appropriate action for the CISO to take FIRST?
Hard25An information security manager is advising a business unit that wants to launch a customer-facing mobile application in a market with new data protection regulations. The unit's leadership prefers to launch quickly and address compliance later. Which action BEST aligns with effective information security risk management?
Hard26An organization has implemented a risk management framework based on ISO 27005. During the risk identification phase, a new vulnerability is discovered in a critical business application that could lead to a data breach. According to ISO 27005, which of the following is the NEXT step the organization should take?
Medium27A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?
Medium28A software company is entering a market that requires compliance with a new data protection regulation. The CISO must present a risk-based implementation plan to the executive committee. Which of the following BEST demonstrates alignment between the security program and the organization's compliance obligations?
Medium29An organization has recently experienced a data breach due to a misconfigured database. The root cause was a lack of proper change management. As part of the risk management process, what should the organization do NEXT after implementing corrective controls?
Easy30A regional hospital is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). During an internal audit, it was discovered that patient electronic health records (EHRs) are transmitted over the internet without encryption. The risk manager has been asked to recommend a risk treatment. Which action should be prioritized to address this finding?
Easy31A risk manager is updating the organization's risk assessment methodology. The current approach uses a qualitative scale (High/Medium/Low) for likelihood and impact. Senior management wants a more objective and consistent way to compare risks across different business units. Which of the following should the risk manager implement to BEST meet this requirement?
Hard32A healthcare organization's risk register shows a critical patient-records system with an annualized loss expectancy (ALE) of $2,400,000. A proposed control costs $300,000 per year and is estimated to reduce the ALE to $400,000. The CISO must present the strongest financial justification to the executive committee. Which of the following is the MOST appropriate metric to present?
Medium33Which TWO of the following are common approaches to information security risk assessment?
Medium34A risk manager is aggregating risks across the enterprise and finds that multiple individual risks, each with low impact and low probability, could combine to create a significant risk. What is the best approach to address this?
Hard35An information security manager is calculating the annualized loss expectancy for a data center outage. The facility has a single point of failure, and a full outage is estimated to occur once every 25 years with a loss of $4,000,000 per event. A redundant power and cooling project would cost $900,000 and reduce the frequency to once every 100 years. What is the expected annual risk reduction, and how should the manager interpret it?
Hard36During a risk assessment, an organization identifies that its legacy payment system has a high likelihood of exploitation due to unpatched vulnerabilities. The system is critical for daily operations. Which risk treatment option should the organization PRIMARILY consider?
Medium37Which of the following is the primary purpose of communicating risk assessment results to senior management?
Easy38A global manufacturing firm is establishing a formal risk management program. The CISO has been asked to ensure that risk assessment outputs are consistently comparable across business units and over time. Which TWO of the following practices BEST support this objective? (Choose two.)
Hard39A software company is entering a new market that requires compliance with a strict data protection law. The CISO must determine whether the current security program can meet the law’s requirements. Which of the following should be the FIRST step?
Medium40A multinational organization is evaluating its risk appetite for a new cloud-based customer relationship management (CRM) system. The system will store personal data across multiple jurisdictions with varying data protection laws. The risk committee has set a risk appetite statement that allows only low residual risk. Which of the following controls is MOST critical to ensure compliance with the risk appetite?
Hard41An information security manager is integrating risk management with the organization's enterprise risk management (ERM) program. The ERM director asks how information security risk should be reported alongside financial and operational risks. Which of the following is the MOST appropriate approach?
Medium42A small accounting firm with 50 employees recently suffered a ransomware attack that encrypted all client data on its file server. The firm had no backup strategy, and the attackers demanded a ransom for decryption. The firm paid the ransom, but many clients left due to loss of trust. The firm’s owner has now hired you as a part-time risk manager. Your first task is to develop a risk management program. What is the most appropriate initial step?
Easy43Match each risk management term to its definition.
Medium44An organization has implemented a new web application that processes sensitive customer data. The risk assessment identified a high likelihood of SQL injection attacks due to insufficient input validation. Which of the following is the BEST risk treatment strategy?
Medium45Which of the following best describes residual risk?
Easy46A mid-sized manufacturing firm has decided to transfer the risk of a ransomware attack on its production network by purchasing a cyber insurance policy. The policy includes a $1 million coverage limit and a $50,000 deductible. Six months later, a ransomware incident causes $400,000 in recovery costs. The insurer approves the claim. What is the organization's financial responsibility for this incident?
Easy47In a risk assessment, a CISM calculates the annualized loss expectancy (ALE) for a specific threat. The single loss expectancy (SLE) is $50,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE, and which risk response is most cost-effective if a control costs $12,000 per year and reduces ARO to 0.05?
Hard48An information security manager at a multinational bank is reviewing the risk assessment methodology. The bank operates in multiple jurisdictions with different regulatory requirements. The manager wants to ensure the methodology produces consistent and comparable risk results across all business units. Which of the following is the MOST important characteristic of the risk assessment methodology?
Hard49During a risk assessment, the risk team identifies that a key vendor has access to sensitive data. The vendor's security posture is unclear. Which of the following is the BEST course of action?
Hard50Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)
Hard51A data breach has occurred exposing customer personal information. The risk manager needs to select a response to reduce the likelihood of similar incidents. Which risk response is most appropriate?
Easy52A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?
Medium53A healthcare insurer has completed an annual risk assessment. The CISO must present the results to the board and recommend a treatment strategy for a risk involving a legacy claims-processing application. The board has stated that it will not accept any risk that could result in a regulatory fine exceeding $1 million. Which of the following is the MOST appropriate action for the CISO to take FIRST?
Medium54An information security manager is updating the organization's risk register after a significant change in the threat landscape. The manager needs to ensure the register remains a useful tool for decision-making. Which TWO of the following activities are MOST important for maintaining the risk register's effectiveness? (Choose two.)
Medium55A retail company has a documented risk appetite stating that it will accept no more than a moderate level of risk to customer payment data. A recent assessment shows the payment environment carries a high residual risk after existing controls. What should the information security manager do FIRST?
Easy56An insurance company's risk committee has formally approved a risk treatment plan that relies on a new identity governance platform to reduce excessive access privileges. Six months into implementation, the project is 20 percent complete due to competing priorities. What should the information security manager do FIRST?
Easy57An information security manager is selecting a risk analysis methodology for a new enterprise resource planning (ERP) deployment. The organization has limited historical incident data, the deployment timeline is aggressive, and executives want a defensible ranking of risks within two weeks. Which approach is MOST appropriate?
Hard58Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
Hard59A company is assessing the risk of a critical system outage. The system has a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 4 hours. What is the most appropriate risk treatment?
Medium60An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?
Easy61A financial services firm is building a risk register for its information security program. The CISO wants to ensure the register supports effective risk treatment decisions. Which TWO of the following elements are MOST essential to include for each identified risk? (Choose two.)
Hard62A CISO is explaining the concept of risk appetite to a newly formed security steering committee. Which of the following BEST describes risk appetite?
Easy63Which TWO of the following are key components of a risk assessment report according to best practices? (Choose two.)
Medium64A company is implementing a risk management program and needs to identify the most critical assets. Which of the following is the BEST approach to prioritize assets for risk assessment?
Easy65A financial institution is implementing a new online banking platform. The risk assessment identified that the authentication module has a high likelihood of exploitation due to weak password policies. The risk owner has decided to implement multi-factor authentication (MFA) to reduce the risk. This is an example of which risk response strategy?
Medium66After a data breach, the risk manager discovers that the risk assessment for the affected system had not been updated for two years. The organization's risk management policy requires annual reviews. Which of the following is the MOST significant consequence of this noncompliance?
Hard67A retail company's risk register lists a vulnerability in its point-of-sale system that could expose customer payment card data. The Chief Information Security Officer (CISO) wants to ensure the risk is managed appropriately. Which of the following should be the FIRST step in the risk treatment process?
Easy68A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?
Hard69A global manufacturer is building a risk register for its operational technology (OT) environment. The CISO wants to ensure the register captures risk at the appropriate level and supports prioritization. Which TWO of the following practices BEST support an effective OT risk register? (Choose two.)
Hard70A multinational financial services company is implementing a new regulatory requirement that mandates enhanced encryption for all customer data in transit. The organization currently uses TLS 1.2, but the regulation requires TLS 1.3. The risk owner for the data transmission system is the head of network operations, who believes the current controls are sufficient and argues that upgrading will cause significant downtime and cost. The information security manager has assessed the risk as high due to potential regulatory fines and reputational damage. The risk owner refuses to accept the risk and insists on deferring the upgrade. The organization has a risk appetite statement that accepts moderate residual risk only after explicit approval from the CRO. The escalation process involves the risk management committee. What is the BEST course of action for the information security manager?
Easy71A company has a risk appetite that is 'low' for operational risks. A risk assessment recently identified that a high-speed trading platform has a residual risk rating of 'high' after controls are applied. The cost to further reduce the risk is $1 million, which exceeds the expected benefit. What is the most appropriate action for the risk owner?
Hard72A healthcare organization is evaluating a new telehealth platform that will process protected health information. The security manager has completed a risk assessment and identified several risks. The CISO asks which of the following is the MOST important factor when determining whether to accept, mitigate, transfer, or avoid a risk?
Hard73Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Easy74A financial institution is implementing a risk-based approach to prioritize its information security initiatives. The risk manager has completed a risk assessment and identified several risks with varying impact and likelihood. Which TWO of the following are the most important benefits of using the risk assessment results to determine the order of security projects?
Medium75A retail company is building an information security risk register to support its risk management program. The risk manager wants to ensure the register captures the information needed to track and report risks to senior management. Which TWO of the following are essential elements that should be included for each identified risk? (Choose two.)
Medium76You are the CISM for a mid-sized e-commerce company that processes credit card transactions. The company recently experienced a security incident where an attacker exploited a vulnerability in the web application to gain access to the customer database containing payment card information. The incident response team contained the breach, but the root cause analysis revealed that the vulnerability had been identified in a penetration test six months ago but was not remediated due to competing priorities. The company's risk management framework defines risk appetite as 'moderate' for information security risks. The board is concerned and has asked you to recommend improvements to prevent recurrence. The company has a limited budget and cannot implement all possible controls. Current environment: web application developed in-house, hosted on-premises, with a mix of virtual and physical servers. The security team consists of three people responsible for monitoring, incident response, and vulnerability management. The development team follows an agile methodology with bi-weekly sprints. The company has cyber liability insurance that covers breach response costs up to $2 million. Based on this scenario, what is the most effective course of action?
Hard77A hospital's information security manager is assessing a radiology system that stores patient images on a vendor-managed cloud. The vendor reports a 99.9% uptime SLA and annual SOC 2 Type II reports, but the hospital's radiology staff continue to store local copies on unencrypted workstations for convenience. Which of the following is the MOST appropriate risk treatment for the risk introduced by the local copies?
Medium78During a risk assessment, a security manager discovers that the residual risk after implementing planned controls is still above the risk appetite threshold. What should the manager do NEXT?
Hard79After implementing controls, the residual risk is calculated to be at a level that slightly exceeds the risk appetite. The business owner argues that the cost of further mitigation outweighs the benefit. What is the most appropriate action for the risk manager?
Hard80A global insurance provider has completed a risk assessment for a new policyholder web portal. The risk treatment plan includes purchasing cyber insurance to transfer a portion of the financial impact. Which of the following is the PRIMARY consideration when evaluating this treatment option?
Medium81Order the steps for implementing a security awareness training program.
Medium82A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)
Medium83A security manager is conducting a risk assessment for a new cloud-based system. The system will store sensitive customer data. Which of the following should be the FIRST step in the risk assessment process?
Medium84Which of the following is the PRIMARY purpose of an information security risk assessment?
Easy85A global retailer is preparing to adopt a new cloud-based point-of-sale platform. The CISO must ensure the risk assessment approach is repeatable and comparable over time. Which of the following is the MOST important characteristic of the risk assessment methodology to achieve this?
Medium86An information security manager is implementing a risk management program. Which TWO of the following activities should be performed as part of the risk assessment process?
Medium87An organization selects a control to mitigate a risk, but after implementation, the risk level remains unchanged. What should the risk manager do first?
Medium88A risk assessment identifies that the organization's email system has a high likelihood of phishing attacks. The current controls include spam filtering and user awareness training. What should the organization do NEXT to manage this risk effectively?
Easy89Order the steps for implementing a data classification policy in an organization.
Medium90An organization is determining the risk treatment for a critical business process that has a high inherent risk. Which of the following is the MOST effective risk treatment strategy when the cost to mitigate exceeds the potential loss?
Easy91An information security manager has identified a risk with a high likelihood and high impact. The cost of mitigating the risk exceeds the potential loss. What is the MOST appropriate risk treatment strategy?
Medium92During a risk assessment, a company discovers that its data backup process is incomplete: backups are performed daily but stored onsite without encryption. The risk owner proposes to accept this risk due to low likelihood of a physical breach. Which of the following is the BEST reason to challenge this acceptance?
Medium93A risk manager is presenting risk treatment options to senior management. Which of the following is the BEST approach to communicate risk in a way that supports informed decision-making?
Easy94An organization's risk appetite statement says it will tolerate only low residual risk for systems processing payment card data. A recent assessment shows a payment gateway with medium residual risk after existing controls. What should the information security manager do NEXT?
Easy95A company is evaluating its risk management process. The CISM notices that risks are being assessed based on qualitative scales (low, medium, high) but decisions require quantitative data. What is the most effective action to improve the process?
Easy96A security manager is preparing a risk report for the board of directors. Which of the following should be included to best support strategic risk-based decisions?
Hard97A retail company's risk committee is reviewing the annual risk assessment. The CISO notes that the organization's stated risk appetite for customer data confidentiality is low, but a business unit wants to launch a loyalty program that shares purchase history with a third-party analytics provider. Which of the following should the CISO do FIRST?
Easy98During a risk assessment, a CISM identifies that the organization's data backup process has a single point of failure. The backup server is located in the same data center as the primary server. Which risk response is most appropriate?
Easy99A global manufacturing company is expanding its operations into a region with unstable political conditions. The CISO has been asked by the board to provide a recommendation on the risk associated with building a new data center in that region. Which of the following should the CISO do FIRST?
Medium100A company engages a third-party vendor to process customer data. Which of the following is the most critical step in managing the associated risk?
Easy101A security manager is selecting a risk analysis method for a new mobile banking feature. The team has limited historical data, and leadership wants a defensible view of which threats matter most before committing budget. Which approach BEST fits this situation?
Medium102Which THREE of the following are typical steps in a qualitative risk assessment?
Medium103A company is developing a risk treatment plan for a set of identified risks. One risk involves a third-party vendor that hosts critical data. The risk owner recommends accepting the risk. Which of the following conditions would BEST support this decision?
Medium104An information security manager is reviewing the organization's risk register and notices that a risk related to unpatched software has been assigned a risk score of 9 (on a scale of 1-10) with a note that the risk is 'accepted' because patching would disrupt a critical production system. Which of the following should the manager do NEXT?
Hard105Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
Medium106Which of the following are key components of an Information Security Risk Management program? (Select TWO.)
Medium107Match each business continuity term to its definition.
Medium108Which of the following is the PRIMARY reason for an information security manager to integrate risk management into the organization's enterprise risk management (ERM) framework?
Medium109A global retailer operates point-of-sale systems in 12 countries. The risk register shows a single entry titled 'Payment card data breach' with a likelihood of 4 and an impact of 5. A new CISO argues this entry is too coarse to support treatment decisions. Which action BEST improves the usefulness of the risk register for decision-making?
Hard110A company is implementing a risk management program and needs to define risk appetite. Which of the following is the MOST appropriate statement of risk appetite for a financial institution?
Medium111Which TWO of the following are risk treatment strategies as defined in ISO 27005?
Easy112Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
Medium113A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?
Hard114An information security manager is building a risk register for a newly formed risk management program. Which TWO of the following elements are essential components of each documented risk entry? (Choose two.)
Medium115A global insurance provider has just completed a quantitative risk assessment for a new claims-processing application. The assessment used the Annualized Loss Expectancy (ALE) formula and produced an ALE of $850,000 for the risk of a data breach. The vendor's proposed control has an Annualized Cost of the Safeguard (ACS) of $300,000 and a projected risk reduction of 60%. The CISO asks the information security manager to determine the cost-benefit of implementing this control. What is the net benefit (or loss) of the control?
Medium116Which of the following best describes the difference between risk appetite and risk tolerance?
Easy117A technology startup has grown rapidly and its risk management practices are informal. The CEO has a very high risk appetite and frequently overrides risk management recommendations to accelerate product launches. After a serious data breach involving customer payment information, the board of directors demands a formal risk management program. The risk manager is tasked with changing the risk culture. The startup has limited resources but must meet contractual obligations to protect customer data. What is the most effective first step?
Hard118A multinational corporation is expanding its cloud infrastructure across multiple regions. The risk team has identified that the shared responsibility model for cloud security is not well understood by business units. After a recent audit, several misconfigurations led to a data exposure incident that affected one region. The CISO wants to implement a risk management program that ensures consistent control across all regions. As the risk manager, what is the most effective course of action to reduce the risk of similar incidents?
Hard119A risk manager is evaluating a control that reduces the likelihood of a threat from high to low. The cost of the control is $100,000 annually. The expected loss without the control is $500,000 per year. Which of the following should the risk manager recommend?
Medium120A healthcare organization is conducting a risk assessment for a new telehealth platform that will process protected health information. The assessment team proposes using a qualitative approach because of tight deadlines. Which of the following is the MOST significant limitation of relying solely on qualitative risk assessment for this initiative?
Hard121A manufacturing company is integrating a newly acquired subsidiary into its enterprise risk management program. The CISO must establish controls to ensure risk assessments from the subsidiary are reliable. Which TWO of the following activities BEST provide assurance that the subsidiary's risk assessment results are trustworthy? (Choose two.)
Hard122An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?
HardOther domains
All CISM exam domains
Frequently asked questions
- What does the Information Security Risk Management domain cover on the CISM exam?
- You must quantify risk using SLE, ARO, and ALE, then compare residual risk against the stated appetite to recommend treatment. The single most important thing: risk decisions and acceptance belong to the business owner, while security advises, monitors, and reports.
- How many questions are in this domain?
- This page lists all 122 Information Security Risk Management questions in the CISM question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Information Security Risk Management questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.