ISO 31000 Risk Treatment Decision Based on Risk Appetite
An organization uses the ISO 31000 risk management framework. During the risk evaluation phase, it determines that a certain risk has a low likelihood but very high impact. The organization's risk appetite is moderate. Which of the following is the MOST appropriate risk treatment decision?
Quick Answer
The answer is to mitigate the risk by implementing controls to reduce impact. This is correct because the ISO 31000 risk treatment decision must align with the organization’s risk appetite, which in this case is moderate. Even though the likelihood is low, the very high impact exceeds a moderate appetite, so simply accepting or transferring the risk would leave the organization exposed to a potentially catastrophic event. On the Certified Information Security Manager CISM exam, this scenario tests your ability to apply the risk evaluation phase of ISO 31000, where the residual risk after treatment must fall within the stated appetite. A common trap is to choose acceptance for low-likelihood risks, but the CISM framework emphasizes that impact severity overrides probability when appetite is moderate. Remember the memory tip: “High impact, moderate appetite—mitigate, don’t accept the fright.”
⚠ Common exam trap
The trap here is that candidates mistakenly equate low likelihood with low overall risk, leading them to choose acceptance (Option A), but CISM tests that risk appetite must be explicitly considered—a very high impact can still exceed appetite even if likelihood is low.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the risk by implementing controls to reduce impact
ISO 31000's risk evaluation phase requires aligning treatment decisions with the organization's risk appetite. With a moderate risk appetite, a low-likelihood but very-high-impact risk cannot simply be accepted (as it exceeds appetite), nor is avoidance necessary since the likelihood is low. Mitigation through controls that reduce the impact is the most balanced approach, bringing the residual risk within the moderate appetite threshold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk due to low likelihood
Why it's wrong here
Acceptance leaves a very high impact unmitigated, which exceeds a moderate risk appetite that weighs impact, not likelihood alone. It tempts because acceptance suits low-impact risks within tolerance, where monitoring suffices and no treatment cost is justified.
- ✗
Avoid the risk by discontinuing the activity that generates it
Why it's wrong here
Avoidance eliminates the activity entirely, which is disproportionate when likelihood is low and ISO 31000 favours treating the impact while retaining the benefit. It tempts because avoidance suits risks whose potential impact is intolerable and no control can reduce it.
- ✗
Transfer the risk through insurance
Why it's wrong here
Insurance compensates financial loss but does not reduce the very high impact itself, and residual reputational or regulatory exposure remains outside a moderate appetite. It tempts because transfer suits high-severity, low-frequency risks where financial loss is the primary consequence.
- ✓
Mitigate the risk by implementing controls to reduce impact
Why this is correct
Low likelihood with very high impact exceeds a moderate appetite because the potential consequence is severe. Reducing impact through controls lowers the residual severity to an acceptable level, whereas acceptance or transfer would leave the organisation exposed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid risk treatment options according to ISO 31000? (Choose two.)
medium- ✓ A.Risk avoidance
- B.Risk measurement
- C.Risk identification
- D.Risk communication
- ✓ E.Risk retention
Why A: According to ISO 31000, risk treatment options include avoiding the risk by deciding not to start or continue the activity that gives rise to it, which is why option A (Risk avoidance) is correct. ISO 31000 also recognizes retaining the risk by informed decision, which is option E (Risk retention), as a valid treatment option when the risk is accepted and no further action is taken. Options B (Risk measurement), C (Risk identification), and D (Risk communication) are not treatment options; they are elements of the risk assessment and communication processes within the ISO 31000 framework, not ways of modifying risk.
Variation 2. Which THREE of the following are valid risk treatment options according to ISO 31000? (Select exactly three.)
medium- A.Risk elimination
- ✓ B.Risk transfer (sharing)
- ✓ C.Risk avoidance
- ✓ D.Risk mitigation (reduction)
- E.Risk deferral
Why B: According to ISO 31000, risk treatment options include avoiding the risk (Option C), which means deciding not to start or continue the activity that gives rise to the risk, thereby removing the exposure entirely. Option B, risk transfer (sharing), is also valid because it involves sharing the risk with another party, such as through insurance or contractual arrangements, while retaining some residual risk. Option D, risk mitigation (reduction), is correct because ISO 31000 recognizes modifying the likelihood and/or consequence of the risk to reduce it to an acceptable level. Option A, risk elimination, is not one of the standard ISO 31000 treatment categories; while avoidance can eliminate exposure, 'elimination' is not the named treatment option. Option E, risk deferral, is not a recognized ISO 31000 risk treatment option, as postponing a risk does not by itself treat it and ISO 31000 does not list deferral among its treatment choices.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.