Courseiva

CISM Information Security Risk Management Practice Question

Which THREE of the following are essential components of an information security risk management framework?

⚠ Common exam trap

Many candidates confuse operational security processes (like incident response) or compliance activities (like auditing) with the core risk management framework components, which are strictly risk identification, risk assessment, and risk treatment as defined by ISACA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk identification

Risk identification (B) is essential because the framework must first determine which threats, vulnerabilities, and assets exist before any risk can be analyzed or managed. Risk assessment (D) is essential because it evaluates the identified risks by determining likelihood and impact, often through qualitative or quantitative methods, to prioritize them. Risk treatment (E) is essential because it defines how the organization will respond to assessed risks through mitigation, transfer, acceptance, or avoidance, completing the core risk management cycle. Incident response planning (A) is a reactive operational capability that supports risk management but is not one of the core framework components, and compliance auditing (C) is a assurance activity that verifies adherence to controls or regulations rather than a foundational risk management process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident response planning

    Why it's wrong here

    Incident response planning executes after a risk materialises; it does not identify, analyse, evaluate or treat risk, so it sits outside the framework's core components. It is tempting because response capability reduces realised impact, and it belongs in the broader security programme, not the risk management framework itself.

  • ✓

    Risk identification

    Why this is correct

    Risk identification establishes which threats, vulnerabilities and assets fall within scope, feeding every later stage. This satisfies the framework requirement by ensuring exposures are discovered and recorded before analysis, treatment or monitoring can meaningfully occur.

  • ✗

    Compliance auditing

    Why it's wrong here

    Compliance auditing verifies adherence to controls and standards after implementation; it does not identify, assess or treat risk, so it is not a core framework component. It is tempting because audit findings feed risk registers, and it is correct where assurance over control operation is the objective.

  • ✓

    Risk assessment

    Why this is correct

    Risk assessment analyses identified risks for likelihood and impact, producing the prioritised view that drives treatment decisions. This satisfies the framework requirement by converting raw identification output into comparable, decision-ready information aligned with the organisation's risk criteria.

  • ✓

    Risk treatment

    Why this is correct

    Risk treatment is an essential component because it defines how the organisation selects and implements responses—avoidance, mitigation, transfer or acceptance—to identified risks. Without it, assessment and evaluation produce no actionable outcome, leaving the framework unable to reduce risk to acceptable levels.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.