CISM - Information Security Program - Section 3.6

Design and select information security controls appropriate to identified risks and business requirements.

Design and select information security controls by matching preventive controls, detective controls, and corrective controls to the specific risks and business requirements they address. Weigh cost, feasibility, and residual risk to justify control selection decisions and avoid over-controlling low-risk areas.

Control designPreventive controlsDetective controlsControl selection

Practice question for this objective

Free sampleInformation Security Programhard

During design of a new control set, an information security manager identifies a risk whose residual level, after the controls already planned, sits clearly within the board-approved risk appetite. A project team nonetheless proposes adding a further costly preventive control to drive the risk lower still. What principle should most influence the manager's recommendation?

  • AAdditional control should always be added when a credible option exists, since lower residual risk is invariably preferable for the organisation.
  • BAdditional control should be selected whenever the proposing project team requests it, because the team understands its own operational exposure best.
  • CAdditional control should be added if the chosen vendor can bundle it cheaply, since marginal cost makes the extra reduction effectively free to deploy.
  • DAdditional control is justified only where risk exceeds appetite, so a control that drives risk below appetite without further benefit should not be selected. Correct
Further controls are warranted only where residual risk exceeds appetite; reducing risk already within appetite is over-control and should be avoided. Risk appetite defines how much risk the organisation accepts. Once residual risk falls within appetite the control objective is met, and adding further controls spends resources and adds operational burden for no benefit the business has asked for, which is poor governance discipline.

Why A is wrong: Driving residual risk ever lower sounds prudent, but treating more control as always better ignores cost and risk appetite, leading to spend that the business cannot justify against the benefit gained.

Why B is wrong: Deferring to the team's local knowledge is tempting, but control decisions must be governed against enterprise risk appetite and cost, not granted on request, or spending drifts beyond what the risk warrants.

Why C is wrong: A cheap bundle makes extra control look like easy value, but even low-cost controls add operational and assurance burden, and stacking control on a risk already within appetite still yields no benefit that justifies the effort.

Why D is correct: Controls exist to bring risk within appetite; once residual risk already sits within appetite, spending more to reduce it further is over-control that consumes resources without a corresponding business benefit.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.