CISM Information Security Risk Management Practice Question
Which THREE of the following are essential components of an information security risk management framework?
⚠ Common exam trap
Many candidates confuse operational security processes (like incident response) or compliance activities (like auditing) with the core risk management framework components, which are strictly risk identification, risk assessment, and risk treatment as defined by ISACA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk identification
Risk identification (B) is essential because the framework must first determine which threats, vulnerabilities, and assets exist before any risk can be analyzed or managed. Risk assessment (D) is essential because it evaluates the identified risks by determining likelihood and impact, often through qualitative or quantitative methods, to prioritize them. Risk treatment (E) is essential because it defines how the organization will respond to assessed risks through mitigation, transfer, acceptance, or avoidance, completing the core risk management cycle. Incident response planning (A) is a reactive operational capability that supports risk management but is not one of the core framework components, and compliance auditing (C) is a assurance activity that verifies adherence to controls or regulations rather than a foundational risk management process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incident response planning
Why it's wrong here
Incident response planning executes after a risk materialises; it does not identify, analyse, evaluate or treat risk, so it sits outside the framework's core components. It is tempting because response capability reduces realised impact, and it belongs in the broader security programme, not the risk management framework itself.
- ✓
Risk identification
Why this is correct
Risk identification establishes which threats, vulnerabilities and assets fall within scope, feeding every later stage. This satisfies the framework requirement by ensuring exposures are discovered and recorded before analysis, treatment or monitoring can meaningfully occur.
- ✗
Compliance auditing
Why it's wrong here
Compliance auditing verifies adherence to controls and standards after implementation; it does not identify, assess or treat risk, so it is not a core framework component. It is tempting because audit findings feed risk registers, and it is correct where assurance over control operation is the objective.
- ✓
Risk assessment
Why this is correct
Risk assessment analyses identified risks for likelihood and impact, producing the prioritised view that drives treatment decisions. This satisfies the framework requirement by converting raw identification output into comparable, decision-ready information aligned with the organisation's risk criteria.
- ✓
Risk treatment
Why this is correct
Risk treatment is an essential component because it defines how the organisation selects and implements responses—avoidance, mitigation, transfer or acceptance—to identified risks. Without it, assessment and evaluation produce no actionable outcome, leaving the framework unable to reduce risk to acceptable levels.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.