Home › Certifications › CISM › Information Security Risk Management
80 multiple-choice questions and 28 flashcards on Information Security Risk Management, about 20% of the CISM bank. Every one carries a written rationale.
Information Security Risk Management is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 80 of the bank's 400 multiple-choice questions — roughly 20% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
6 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
After implementing a control, the risk that remains is termed:
Answer: C — Residual risk
Residual risk = post-control. Inherent = pre-control. Secondary risk = risk introduced by the control itself. Residual must fit within risk appetite or trigger further action.
What should be done FIRST in the risk management process?
Answer: C — Identify and inventory assets with the threats and vulnerabilities that apply to them
C applies the life cycle: identify assets, threats and vulnerabilities, then assess likelihood and impact, then treat, then monitor. You cannot protect or prioritize what you have not enumerated. A is the classic managerially wrong answer, jumping to treatment on intuition and misdirecting spend. B is a treatment option, not a first step, and transfers only part of the loss. D abandons management judgment to events. E can inform target state but presumes a current-state inventory already exists.
An enterprise decides to accept a risk that exceeds its documented appetite because remediation would delay a strategic product launch. The security manager should ensure that:
Answer: A — the acceptance is time-bound, formally authorised at the appropriate level and monitored
A) Correct — a deliberate excursion above appetite is legitimate when it is authorised at the right level, bounded in time and actively monitored, which keeps the exception visible and reversible. B) Rewriting appetite to fit one decision destroys the boundary's value for every future decision. C) Suppressing reporting on an out-of-appetite risk is the opposite of what monitoring requires. D) Imposing controls that override a considered business decision substitutes the manager's judgment for the risk owner's.
A critical supplier subcontracts data processing to another firm. The MOST appropriate risk management response is to:
Answer: C — require disclosure of subcontractors and flow-down of control requirements
C) Correct - accountability does not transfer down the chain, so the manageable lever is contractual visibility plus flow-down of requirements enforced through the direct supplier. A) Blanket prohibition is often commercially unworkable and pushes the practice underground. B) Absence of privity does not remove the enterprise's exposure or its regulatory accountability. D) Approaching the subcontractor directly bypasses the contractual route and is unlikely to be honoured.
A proposed control costs 150,000 per year and reduces the annualised loss expectancy of a risk from 120,000 to 20,000. The MOST appropriate recommendation is to:
Answer: D — present the negative return to the risk owner and let them decide on treatment
D) Correct — the control costs more than the loss it avoids, but the treatment decision belongs to the risk owner, who may weigh factors such as regulatory or reputational consequence the ALE does not capture. A) Reducing exposure is not sufficient justification when the annual cost exceeds the annual benefit. B) A discount might change the arithmetic but presumes the decision before the economics support it. C) A cheaper partial control is often sensible, yet selecting it unilaterally still substitutes the manager's judgment for the owner's.
When presenting a significant risk to a non-technical audit committee, the security manager should LEAD with:
Answer: A — the business consequence and the decision requested
A) Correct - a governance body's time is spent making decisions, so the consequence in business terms and the specific ask should come first, with technical detail available to support it. B) Leading with mechanism forces the committee to translate before it can act. C) Framework mapping supports compliance discussion but does not convey business consequence. D) Peer tooling comparison is a supporting argument that rarely answers the decision at hand.
4 cards from the 28 in this chapter.
Red team vs blue team?
Red: attacks. Blue: defends. Purple team combines for collaboration.
SLE formula?
Single Loss Expectancy = Asset Value × Exposure Factor.
Inherent vs residual risk?
Inherent: before controls. Residual: after controls applied.
Give the classic quantitative risk formulas for single and annualised loss.
SLE = asset value x exposure factor. ALE = SLE x annualised rate of occurrence. The value of a control is the reduction in ALE it produces, compared against its annualised cost — a control costing more than the ALE reduction is not justified on risk grounds alone.
These are a sample. The full Information Security Risk Management chapter runs 108 items with per-chapter progress tracking, on the web and in the iOS app.