CISM - Information Security Risk Management - Section 2.6

Monitor and report on information security risk, including non-compliance and changes in the risk profile, to key stakeholders.

Monitor the organisation's risk profile using key risk indicators (KRIs) and report changes in risk posture, non-compliance events, and emerging exposures to key stakeholders. Tailor risk reporting content and format to the audience, distinguishing between operational-level detail and the summary view appropriate for executive and board communication.

Risk reportingKRIsRisk appetiteStakeholder communication

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

An information security manager is designing the risk reporting package for a multinational organisation in which the board, business unit heads, and operational technology teams all receive the same monthly information security risk update. Several recipients have complained that the report is either too detailed or too high level. What is the MOST effective way to address this?

  • AStandardise on a single highly detailed report for every recipient so that all stakeholders see identical data and no group can claim it was given incomplete information.
  • BReduce the report to a single overall risk rating for the organisation so that every audience receives a brief, easily understood summary each month.
  • CTailor the content and level of aggregation of the risk report to each audience, giving the board appetite and trend summaries while operational teams receive granular indicator detail. Correct
  • DSurvey all recipients and adopt whichever single format the majority prefers, then apply that one format uniformly across the whole stakeholder list.
Tailor information security risk reporting to the decision-making needs of each stakeholder audience rather than issuing one uniform report. Different stakeholders make different decisions, so the same risk information must be aggregated, framed, and detailed differently for the board, business owners, and operational teams; audience segmentation is the principle that makes risk reporting actionable.

Why A is wrong: It is tempting because one consistent dataset seems fair and defensible, but burying executives in operational detail obscures the decisions they must make and does not solve the complaint that the report is too detailed for some.

Why B is wrong: It is tempting as a way to satisfy those who find the report too long, but collapsing everything to one rating strips out the indicator detail that operational teams need to act, so it fails half the audience.

Why C is correct: Correct: effective risk communication matches the depth, framing, and metrics to each stakeholder group's decision-making needs, so segmenting the report by audience resolves both the too-detailed and too-high-level complaints.

Why D is wrong: It is tempting because consulting recipients sounds stakeholder-centric, but a majority-vote single format still forces one level of detail on groups with genuinely different needs, leaving the minority underserved.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.