Courseiva

CISM Information Security Risk Management Practice Question

Which of the following best describes the difference between risk appetite and risk tolerance?

⚠ Common exam trap

Watch out — candidates often confuse risk appetite with risk tolerance by assuming they are synonyms or that one is a subset of the other in a purely quantitative sense, when in fact appetite is the strategic boundary and tolerance is the tactical wiggle room within that boundary for specific objectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk appetite is the amount of risk an organization is willing to accept, while risk tolerance is the acceptable variation around that appetite for specific objectives

Ly distinguishes risk appetite as the broad, strategic level of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance is the specific, measurable deviation allowed from that appetite for individual objectives or risks. This aligns with the ISACA CISM Review Manual, which defines risk appetite as the 'amount of risk an entity is willing to accept in pursuit of its mission' and risk tolerance as the 'acceptable level of variation relative to the achievement of objectives.' Understanding this distinction is critical for establishing proper risk management thresholds and ensuring that security controls are aligned with business goals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk appetite is the maximum risk tolerance

    Why it's wrong here

    Appetite is the amount and type of risk an organisation is willing to pursue to meet objectives, not a maximum tolerance figure. It is tempting because tolerance is a measurable deviation limit around appetite, so treating appetite as the ceiling conflates the strategic statement with its operational threshold.

  • ✗

    Risk tolerance is the total risk, and risk appetite is the residual risk

    Why it's wrong here

    Risk appetite is the total risk an organisation is willing to pursue for reward; tolerance is the acceptable deviation around that appetite, not residual risk. Residual risk is what remains after controls. The option swaps the definitions, confusing tolerance with post-treatment exposure.

  • ✓

    Risk appetite is the amount of risk an organization is willing to accept, while risk tolerance is the acceptable variation around that appetite for specific objectives

    Why this is correct

    Risk appetite sets the aggregate level of risk the organisation chooses to pursue, whereas risk tolerance defines the acceptable deviation from that level for specific objectives. The distinction is scope: appetite is enterprise-wide and directional, tolerance is objective-specific and bounded.

  • ✗

    Risk appetite is qualitative, and risk tolerance is quantitative

    Why it's wrong here

    Both appetite and tolerance can be expressed qualitatively or quantitatively; the axis of difference is not measurement type but scope — appetite is the aggregate level sought, tolerance the permissible variation around it. Framing it as qualitative versus quantitative misstates that relationship.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISM

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A risk manager is establishing risk appetite for a new product line. Which of the following best describes the relationship between risk appetite and risk tolerance?

hard
  • A.Risk appetite and tolerance are interchangeable terms
  • B.Risk appetite is set by regulatory bodies; tolerance is set by the board
  • C.Risk appetite is the specific limit for each risk; tolerance is the overall willingness to accept risk
  • ✓ D.Risk appetite is the general approach to risk; tolerance defines acceptable variation in performance

Why D: Risk appetite is the broad, high-level amount of risk an organization is willing to accept in pursuit of its objectives, while risk tolerance translates that appetite into specific, measurable boundaries for individual risks. Option D correctly captures this relationship: appetite is the general approach, and tolerance defines the acceptable variation in performance metrics (e.g., a 5% deviation in revenue targets). This distinction is critical for aligning risk management with business strategy in information security risk management.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.