CISM: Core Components of an Information Security Risk Management Program
Which TWO of the following are key components of an information risk management program, as defined by ISACA? (Select exactly two.)
Quick Answer
The answer is risk appetite and risk assessment methodology. These two are defined by ISACA as core components of an information risk management program because the program must first establish the organization’s risk appetite—the amount of risk it is willing to accept—and then apply a formal risk assessment methodology to identify, analyze, and evaluate risks against that appetite. On the Certified Information Security Manager CISM exam, this distinction tests your understanding of program-level governance versus operational controls; common traps include confusing data classification or vulnerability scanning as program components when they are actually supporting activities within governance or technical domains. A useful memory tip is to think of the risk management program as the “what and how much” framework: appetite sets the “how much” risk is tolerable, while the assessment methodology defines the “what” process for measuring it.
⚠ Common exam trap
CISM often tests whether candidates can separate core risk management program components (appetite/tolerance, assessment methodology) from supporting controls and response plans (BCP, data classification, vulnerability scanning) — the trap is picking operational controls that feel risk-related but are not structural components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk appetite and tolerance
ISACA defines risk appetite and tolerance (B) as key components because they establish the amount of risk an organization is willing to accept in pursuit of its objectives, providing the criteria against which risks are evaluated and prioritized. A risk assessment methodology (D) is also essential, as it defines the structured approach (e.g., identifying, analyzing, and evaluating risks per frameworks like ISO 31000 or NIST RMF) used to determine likelihood and impact consistently across the enterprise. Together, these two elements form the governance and analytical backbone of an information risk management program. By contrast, a business continuity plan (A) is a response/recovery capability, a data classification scheme (C) is a supporting control/inventory tool, and vulnerability scanning (E) is a technical detection activity — all valuable, but none are the core program components ISACA identifies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Business continuity plan
Why it's wrong here
A business continuity plan is an IT and resilience deliverable that responds to realised risk, not a component of the risk management programme itself. It is tempting because continuity planning depends on risk assessment output, and it would be correct if the question asked which plans mitigate operational disruption.
- ✓
Risk appetite and tolerance
Why this is correct
ISACA defines risk appetite and tolerance as core programme components: they express how much risk the organisation is willing to pursue or retain, and they bound every subsequent assessment, treatment and acceptance decision within the risk management framework.
- ✗
Data classification scheme
Why it's wrong here
Data classification is a supporting control that informs risk assessment, not one of ISACA's stated programme components covering governance, assessment, treatment and monitoring. It is tempting because classification drives how risk is handled, and it would be correct if the question asked how information is categorised for protection.
- ✓
Risk assessment methodology
Why this is correct
A structured risk assessment methodology is a core ISACA component because it defines how assets, threats and vulnerabilities are identified, analysed and evaluated against defined risk criteria. This satisfies the stem's requirement for a key program component by ensuring consistent, repeatable risk determination that underpins subsequent treatment decisions across the organisation.
- ✗
Vulnerability scanning process
Why it's wrong here
Vulnerability scanning is a technical control that feeds risk identification, not one of ISACA's programme components such as governance, risk assessment or treatment. It is tempting because scan output supplies likelihood and impact data, and scanning would be the correct answer to a question about identifying technical weaknesses.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CISM
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are essential components of an information security risk management framework?
hard- A.Incident response planning
- ✓ B.Risk identification
- C.Compliance auditing
- ✓ D.Risk assessment
- ✓ E.Risk treatment
Why B: Risk identification (B) is essential because the framework must first determine which threats, vulnerabilities, and assets exist before any risk can be analyzed or managed. Risk assessment (D) is essential because it evaluates the identified risks by determining likelihood and impact, often through qualitative or quantitative methods, to prioritize them. Risk treatment (E) is essential because it defines how the organization will respond to assessed risks through mitigation, transfer, acceptance, or avoidance, completing the core risk management cycle. Incident response planning (A) is a reactive operational capability that supports risk management but is not one of the core framework components, and compliance auditing (C) is a assurance activity that verifies adherence to controls or regulations rather than a foundational risk management process.
Variation 2. Which of the following are key components of an Information Security Risk Management program? (Select TWO.)
medium- ✓ A.Establishing a risk management framework
- B.Conducting vulnerability scanning
- ✓ C.Performing risk assessment and treatment
- D.Performing internal audits
Why A: A is correct because establishing a risk management framework is the foundational component of an Information Security Risk Management program. It defines the policies, procedures, and governance structure for identifying, assessing, and treating risks, aligning with standards like ISO 31000 or NIST SP 800-39. Without a framework, risk management activities lack consistency and accountability.
Variation 3. Which of the following are key components of an information security risk management program? (Select TWO)
medium- ✓ A.Risk assessment
- B.Vulnerability scanning
- ✓ C.Risk treatment
- D.Incident response
Why A: Risk assessment is a core component of an information security risk management program because it systematically identifies, analyzes, and evaluates risks to information assets. It provides the foundational understanding of threats, vulnerabilities, and impacts necessary for informed decision-making. Without a formal risk assessment, the program lacks the data needed to prioritize and justify security investments.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.