CISM Information Security Risk Management Practice Question
Which TWO of the following are key components of an information security risk assessment? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse risk assessment activities (threat and asset identification) with downstream risk management steps like policy creation or control implementation, leading them to select options that are part of the broader risk management lifecycle but not the assessment itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat identification
Asset identification (E) is a foundational component of a risk assessment because you cannot evaluate risk without first knowing which information assets, systems, and data require protection and what value they hold to the organization. Threat identification (A) is equally essential, since risk is derived from identifying the threats (e.g., malware, insider abuse, natural disasters) that could exploit vulnerabilities and cause harm to those assets. Together, asset and threat identification feed into the core risk formula (risk = likelihood × impact), enabling analysts to prioritize risks and recommend treatment. The other options do not belong: security policy development (B) is a governance/risk-treatment output, incident response planning (C) is a reactive capability built after risks are understood, and control implementation (D) is a risk-mitigation activity that follows the assessment rather than forming part of it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Threat identification
Why this is correct
Threat identification enumerates the sources and actors capable of exploiting vulnerabilities, forming the input that lets assessors determine which risks apply to each asset. Without it, likelihood estimates and subsequent risk calculations lack any credible basis.
- ✗
Security policy development
Why it's wrong here
Policy development sets organisational direction and requirements, which occurs before or after assessment rather than within it. It is tempting because policies govern the risk programme, yet the assessment components are identifying assets, threats, vulnerabilities and evaluating likelihood and impact; policy authorisation is a governance output, not an assessment input.
- ✗
Incident response planning
Why it's wrong here
Incident response planning defines actions taken after an event materialises, whereas risk assessment estimates likelihood and impact beforehand. It is tempting because both concern adverse events, but response planning belongs to the treatment and readiness phase; the assessment components are asset, threat and vulnerability identification with impact evaluation.
- ✗
Control implementation
Why it's wrong here
Control implementation executes selected treatments, which follows assessment rather than forming part of it. It is tempting because controls address identified risks, but assessment only identifies, analyses and evaluates risk; choosing and deploying controls is the treatment stage, so this sits downstream of the two required components.
- ✓
Asset identification
Why this is correct
Asset identification establishes what has value and therefore what requires protection, scoping the assessment so threats and vulnerabilities are evaluated against defined information assets rather than abstract categories. It underpins every subsequent likelihood and impact judgement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.