CISM - Information Security Risk Management (20% of the exam) - Section 2.1

Assess the emerging risk and threat landscape relevant to the organisation.

Assess the current threat landscape by consuming threat intelligence to identify emerging threats and the attack vectors most relevant to the organisation. Distinguish between strategic, operational, and tactical threat intelligence and recognise how each informs different levels of risk decision-making.

Threat intelligenceEmerging threatsThreat landscapeAttack vectors

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

An information security manager subscribes to several external threat intelligence feeds but finds that most alerts describe attacks irrelevant to the organisation's technologies and industry, overwhelming the small security team. What should the manager do first to make the threat intelligence genuinely useful for assessing emerging risk?

  • AAdd further commercial and open-source feeds to widen coverage and reduce the chance of missing a threat
  • BDeploy a security information and event management platform to correlate the incoming feed alerts automatically
  • CDefine intelligence requirements aligned to the organisation's assets, sector, and threat profile before consuming feeds Correct
  • DEscalate to management that current staffing is insufficient to process the volume of intelligence received
Threat intelligence becomes useful for assessing emerging risk only after intelligence requirements are defined against the organisation's assets, sector, and threat profile. Unscoped feeds generate noise that buries relevant signals and exhausts a small team. Defining intelligence requirements first, anchored to the organisation's assets, industry, and threat profile, lets the team filter and prioritise so the intelligence informs assessment of emerging risk rather than overwhelming the function.

Why A is wrong: More feeds promise broader coverage, which is tempting, but adding sources without requirements multiplies the irrelevant volume and worsens the overload the manager already faces.

Why B is wrong: Correlation tooling can help operationally and sounds efficient, but automating the handling of poorly targeted intelligence still processes the wrong inputs and does not address relevance.

Why C is correct: Defining intelligence requirements tied to the organisation's assets, sector, and threat profile filters out noise so the team can focus on threats that are genuinely relevant to emerging risk.

Why D is wrong: Flagging resource constraints may be legitimate, but seeking more staff to handle unfiltered noise treats a symptom and skips the cheaper, more effective step of scoping what intelligence is actually needed.

See more CISM practice questions, answers explained.

Exam traps in Information Security Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Mandate that all generative artificial intelligence use cease until a full control framework has been documented

    Why it is wrong: A blanket ban appears to remove the exposure, but it drives the technology underground, ignores business need, and does nothing to keep the organisation's threat understanding current.

  • Forward the intelligence reports to the operational technology engineering team for their awareness and retention

    Why it is wrong: Sharing reports raises awareness, which is tempting because dissemination feels like action, but awareness alone does not re-evaluate exposure or trigger any prioritised treatment decision.

  • The count of open network ports and externally reachable services the new components introduce, ranked by their published common vulnerability scores.

    Why it is wrong: Tempting because it is concrete and measurable, but a port and score inventory describes technical findings without relating them to which attack vectors threaten the organisation's assets and objectives.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.