CISM - Information Security Risk Management - Section 2.1

Assess the emerging risk and threat landscape relevant to the organisation.

Assess the current threat landscape by consuming threat intelligence to identify emerging threats and the attack vectors most relevant to the organisation. Distinguish between strategic, operational, and tactical threat intelligence and recognise how each informs different levels of risk decision-making.

Threat intelligenceEmerging threatsThreat landscapeAttack vectors

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

An information security manager subscribes to several external threat intelligence feeds but finds that most alerts describe attacks irrelevant to the organisation's technologies and industry, overwhelming the small security team. What should the manager do first to make the threat intelligence genuinely useful for assessing emerging risk?

  • AAdd further commercial and open-source feeds to widen coverage and reduce the chance of missing a threat
  • BDeploy a security information and event management platform to correlate the incoming feed alerts automatically
  • CDefine intelligence requirements aligned to the organisation's assets, sector, and threat profile before consuming feeds Correct
  • DEscalate to management that current staffing is insufficient to process the volume of intelligence received
Threat intelligence becomes useful for assessing emerging risk only after intelligence requirements are defined against the organisation's assets, sector, and threat profile. Unscoped feeds generate noise that buries relevant signals and exhausts a small team. Defining intelligence requirements first, anchored to the organisation's assets, industry, and threat profile, lets the team filter and prioritise so the intelligence informs assessment of emerging risk rather than overwhelming the function.

Why A is wrong: More feeds promise broader coverage, which is tempting, but adding sources without requirements multiplies the irrelevant volume and worsens the overload the manager already faces.

Why B is wrong: Correlation tooling can help operationally and sounds efficient, but automating the handling of poorly targeted intelligence still processes the wrong inputs and does not address relevance.

Why C is correct: Defining intelligence requirements tied to the organisation's assets, sector, and threat profile filters out noise so the team can focus on threats that are genuinely relevant to emerging risk.

Why D is wrong: Flagging resource constraints may be legitimate, but seeking more staff to handle unfiltered noise treats a symptom and skips the cheaper, more effective step of scoping what intelligence is actually needed.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.