Courseiva

CISM Information Security Risk Management Practice Question

Which THREE of the following are common challenges when implementing a risk management program in an organization? (Choose three.)

⚠ Common exam trap

ISACA CISM often tests the distinction between implementation challenges (e.g., lack of support, resistance, quantification difficulty) and operational symptoms (e.g., too many controls), so candidates mistakenly select 'too many controls' because it sounds like a problem, but it is not a root challenge of program implementation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of senior management support

Option A (Lack of senior management support) is correct because a risk management program requires executive sponsorship, budget, and authority to enforce policies; without it, risk initiatives stall and risk ownership cannot be driven across the organization. Option B (Inability to quantify risks in financial terms) is correct because translating technical or operational risk into monetary values (e.g., ALE = SLE × ARO) is difficult and often subjective, which hampers cost-benefit justification of controls and prioritization. Option D (Resistance to change from business units) is correct because risk management typically introduces new processes, ownership, and controls that business units may perceive as bureaucratic overhead, slowing adoption. Option C is not a standard challenge in itself; implementing too many controls too quickly is a symptom of poor phasing rather than a recognized common implementation challenge. Option E is not a common challenge; a well-defined risk appetite is generally desirable, and the issue is more often an undefined or misaligned appetite, not one that is overly detailed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Lack of senior management support

    Why this is correct

    Risk management programmes require governance sponsorship to allocate budget, enforce policy and resolve cross-functional conflicts. Absent senior management support, assessments stall, treatment plans go unfunded, and business units treat risk activities as optional rather than mandated.

  • ✓

    Inability to quantify risks in financial terms

    Why this is correct

    Many risk assessments rely on qualitative scales because reliable financial loss data, actuarial history or modelling expertise are unavailable. This makes cost-benefit justification of treatments difficult, since expected losses cannot be compared directly against control expenditure.

  • ✗

    Too many controls implemented too quickly

    Why it's wrong here

    Implementing too many controls too quickly is a programme execution pitfall, not one of the recognised implementation challenges such as lack of executive sponsorship, unclear ownership, or insufficient resources. It is tempting because control overload does cause real project strain, and would be the correct choice in a question about control deployment sequencing.

  • ✓

    Resistance to change from business units

    Why this is correct

    Risk management alters established workflows, ownership and reporting lines, so business units often resist perceived additional bureaucracy or loss of autonomy. This change resistance delays adoption and undermines the consistent application the programme depends on.

  • ✗

    Overly detailed risk appetite

    Why it's wrong here

    An overly detailed risk appetite is a documentation quality issue, not a common implementation challenge like absent executive support, unclear roles, or poor risk culture. It is tempting because excessive granularity does hinder appetite statements, and would be the right answer to a question about risk appetite statement design rather than programme implementation.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.