Courseiva

CISM Information Security Risk Management Practice Question

Which of the following is the primary purpose of communicating risk assessment results to senior management?

⚠ Common exam trap

Test-takers frequently confuse the operational goal of 'justifying the budget' (Option D) with the strategic governance purpose of 'enabling risk acceptance decisions,' but CISM emphasizes that risk communication to senior management is fundamentally about obtaining informed risk acceptance, not securing funding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To enable informed decision-making about risk acceptance

The primary purpose of communicating risk assessment results to senior management is to provide the necessary information for informed decision-making regarding risk acceptance, transfer, or mitigation. Senior management holds the authority to accept residual risk based on a clear understanding of the potential impact and likelihood, which is a core tenet of the CISM framework for information security risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To comply with regulatory requirements

    Why it's wrong here

    Regulatory compliance may accompany risk communication but is not its primary purpose; frameworks rarely mandate the specific act of reporting results upward. The purpose is enabling senior management to make informed risk-based decisions. Compliance-driven reporting would be correct where a regulation explicitly prescribes disclosure of assessment outcomes.

  • ✓

    To enable informed decision-making about risk acceptance

    Why this is correct

    Risk assessment results give senior management the likelihood and business impact figures needed to decide whether to accept, transfer, mitigate or avoid each risk. Communication therefore exists to support informed risk acceptance decisions at the level holding accountability for organisational risk.

  • ✗

    To assign blame for security failures

    Why it's wrong here

    Risk communication informs decision-making, not accountability for incidents; blame assignment undermines the open reporting that effective risk management depends on. Senior management needs exposure data to prioritise treatments and accept residual risk. Assigning blame would be relevant only in a disciplinary investigation following a confirmed policy breach.

  • ✗

    To justify the security budget

    Why it's wrong here

    Communicating results exists to inform risk-based decisions and prioritisation, not to secure funding. Budget justification is a downstream outcome that follows only once management understands exposure and appetite. Presenting findings primarily as a funding pitch skews the message toward cost rather than the residual risk requiring a decision.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.