Information Security Risk Management

Worth 20% of the ISACA CISM (CISM) exam. CertClue has 307 questions on this objective.

What this objective covers

Information Risk Fundamentals and Core Terminology

Risk in CISM terms is the combination of the likelihood that a threat exploits a vulnerability and the business impact if it does. Every word in that sentence carries weight in the exam. A threat is outside your control; a vulnerability is a weakness you can remediate; an asset is what has value to the business; impact is expressed in business consequence, not technical severity. Inherent risk is the exposure before controls, residual risk is what remains after them, and residual risk is what governance actually decides about. Controls never reduce risk to zero, so the target is always residual risk within appetite rather than elimination. Understanding this vocabulary precisely is what lets you spot the wrong answer that treats a vulnerability scan result as a risk, or that reports technical severity to a business owner who needs business impact.

Exam tip. A vulnerability is not a risk and technical severity is not business impact. When a scenario reports a scan finding, the next step is to assess its business impact and likelihood, not to remediate the highest CVSS score first.

Risk Appetite, Risk Tolerance and Risk Capacity

Appetite, tolerance and capacity are three different limits and the exam separates them deliberately. Risk appetite is the broad level of risk the organisation is willing to take in pursuit of its objectives, and it is set by the board and executive management as a business decision. Risk tolerance is the acceptable variation around that appetite for a specific risk or objective, usually stated as a threshold. Risk capacity is the maximum exposure the organisation could absorb before it becomes unviable, which is a matter of financial and operational fact rather than preference. Appetite should never exceed capacity. Without a stated appetite the security manager has no reference point: every risk looks like it needs treatment, prioritisation becomes arbitrary and there is no defensible basis for saying a risk is acceptable. Establishing appetite is therefore one of the earliest governance dependencies of a risk programme.

Exam tip. If a scenario says risks cannot be prioritised or that every finding is escalated, the missing element is a defined risk appetite, not a better assessment tool.

Asset Identification, Valuation and Information Classification

You cannot assess risk to something you have not identified, so risk management begins with an accurate inventory of information assets and the business processes that depend on them. Valuation is the step that lets you compare risks: an asset's value is what its loss would cost the business in revenue, disruption, obligation or reputation, not what it cost to buy. Classification then translates that value into a handling requirement so that controls scale to sensitivity instead of being applied uniformly. The data owner assigns classification, the security manager defines the scheme and handling rules, and custodians implement them. Classification schemes fail when they have too many levels, when handling requirements are not defined for each level, or when nobody is accountable for labelling. Keep the scheme small enough that people can apply it without thinking hard.

Exam tip. The first step in protecting information is knowing what you hold and what it is worth to the business. Expect the correct answer to identify and classify assets before selecting any control.

Qualitative and Quantitative Risk Analysis

Qualitative analysis rates likelihood and impact on descriptive scales such as high, medium and low, often plotted on a heat map. It is fast, needs no loss data and works for reputational or regulatory impacts that resist a monetary figure, but it is subjective and cannot be used directly in a cost-benefit calculation. Quantitative analysis puts monetary values on exposure using single loss expectancy and annualised loss expectancy, which makes it directly comparable with the cost of a control, but it depends on data quality and can convey false precision. Most organisations use a hybrid: qualitative triage across the estate, then quantitative analysis on the small number of risks that justify significant spend. The exam expects you to know the formulas and, more importantly, to pick the method that matches the decision being made.

Exam tip. Choose the method by the decision. If the question is whether a control is worth its cost, you need quantitative output; if it is which of two hundred findings to look at first, qualitative triage is the efficient answer.

Risk Treatment Options and Cost-Benefit Analysis

There are four treatment options and the exam tests whether you can match a scenario to the right one. Mitigation reduces likelihood or impact through controls. Avoidance removes the exposure entirely by not doing the activity, which is the only option that eliminates the risk but also forfeits the associated benefit. Transfer or sharing moves financial consequence to another party through insurance or contract, and it never moves accountability, which stays with the organisation. Acceptance means the business owner knowingly retains the risk, and it is legitimate when residual risk is within appetite. The cost-benefit test governs mitigation: a control should not cost more than the expected loss it prevents. Compare the annualised loss expectancy before and after the control against the annualised cost of the control, including operational and staffing cost, not just purchase price.

Exam tip. Transfer never moves accountability, and acceptance is only valid when the named business owner documents it and residual risk is within appetite. Any option in which the security manager accepts risk is wrong.

The Risk Register and Tracking Risk Ownership

The risk register is the operational record of the risk programme and the single artefact an auditor asks for first. Each entry describes the risk in business terms, records inherent and residual ratings, names the risk owner, states the chosen treatment with a target date, and carries a review date. A register that lists technical findings without owners or dates is a to-do list, not a risk register. The value comes from what the register enables: aggregating exposure to compare against appetite, identifying where the same root cause drives several risks, evidencing that decisions were made deliberately, and giving governance a reliable view. Registers decay quickly, so they need a defined refresh cycle and clear triggers for adding, updating and closing entries. A risk is closed when the exposure genuinely no longer exists, not when the remediation ticket is closed.

Exam tip. When a scenario shows risks that are recorded but never treated, look for the missing business risk owner or the missing target date. Adding more detail to the assessment does not create accountability.

Risk Monitoring, Indicators and Reassessment Triggers

Risk assessment is a snapshot; risk monitoring is what keeps it true. The environment changes constantly through new systems, new suppliers, reorganisations, new threat activity and control degradation, so a register reviewed once a year is wrong for most of the year. Monitoring combines a scheduled reassessment cycle with event-driven triggers that force an out-of-cycle review, plus key risk indicators with defined thresholds that give early warning before an exposure becomes an incident. A good indicator is measurable, tied to a specific risk, has an agreed threshold and escalation route, and would actually change someone's behaviour when it moves. Control effectiveness is monitored alongside indicators, because a control that has silently stopped working turns an accepted residual risk into a much larger real one without anybody deciding to accept it.

Exam tip. A significant change to the business, the technology estate or the supplier base should trigger a risk reassessment rather than waiting for the annual cycle. Look for that trigger in the scenario.

Third-Party and Supply Chain Risk Management

Outsourcing a process transfers the work, never the accountability. The organisation remains answerable for information handled on its behalf, so third-party risk is managed across the whole relationship lifecycle rather than at signature. Before selection, assess criticality and the sensitivity of the data involved, and let that determine the depth of due diligence. At contracting, secure the terms that make ongoing management possible: security requirements, the right to audit or receive independent assurance reports, incident notification obligations with defined timeframes, subcontractor controls, data location and handling requirements, and return or destruction of data at exit. During the relationship, monitor performance and assurance evidence rather than trusting the initial assessment indefinitely. At exit, recover or securely destroy data and revoke access. Fourth-party risk, where your supplier depends on their own suppliers, is a routine exam theme.

Exam tip. The most effective time to influence third-party security is before the contract is signed, because audit rights, notification duties and exit terms are difficult to obtain afterwards.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. The enterprise risk management function maintains a corporate risk register that contains no information security entries at all. What is the MOST significant consequence of this omission?

  • A. External auditors will be unable to complete their fieldwork on the enterprise risk process
  • B. Security risk will not be weighed against other enterprise risks when resources are allocatedcorrect
  • C. Security incidents will take longer to detect and contain, because no one is monitoring for them
  • D. The security team will lose visibility of vulnerability scanning data held by the enterprise function

The corporate register is where the organization compares risks and decides where money and attention go, so an absent security entry means security competes for nothing and is funded by argument rather than by ranking. Slower detection sounds serious but it is an operational symptom that depends on monitoring tooling, not on whether a register entry exists, and the exam is testing whether you understand that the register drives resource decisions.

2. An organization implements multifactor authentication to reduce the likelihood of account compromise. Which treatment option does this represent?

  • A. Acceptance
  • B. Transfer
  • C. Mitigationcorrect
  • D. Avoidance

Applying a control that lowers the likelihood or impact of an event while continuing the activity is mitigation. Avoidance is the option most often confused here, but avoidance would mean discontinuing remote access altogether rather than making it harder to abuse.

Work the whole objective

The full ISACA CISM bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISACA CISM practice test

The other ISACA CISM objectives