CISM - Information Security Risk Management - Section 2.4

Evaluate and select appropriate risk treatment and risk response options in accordance with the organisation's risk appetite.

Evaluate the four risk treatment options - risk mitigation, risk transfer, risk acceptance, and risk avoidance - and select the response that best matches the organisation's documented risk appetite. Recognise that residual risk remaining after treatment must be formally accepted by an appropriate risk owner.

Risk treatmentRisk acceptanceRisk transferRisk mitigation

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

A retailer plans to launch a feature that stores customers' biometric templates to speed up sign-in. Assessment shows the resulting residual risk exceeds the board's risk appetite, no available control brings it within appetite, and the feature delivers only a marginal convenience benefit. The information security manager must recommend a risk response. Which response is most appropriate?

  • ARecommend layering every available control on the biometric store and accepting whatever residual risk remains, on the basis that thorough mitigation is the responsible engineering choice for sensitive data.
  • BRecommend not proceeding with biometric storage and meeting the sign-in goal another way, because the risk cannot be brought within appetite and the benefit does not justify carrying an out-of-appetite exposure. Correct
  • CRecommend transferring the exposure to a specialist biometric processor under contract, so the residual risk becomes the processor's responsibility and the feature can launch as planned.
  • DRecommend launching the feature now and revisiting the exposure at the next annual risk review, treating the gap as a temporary deviation that monitoring will keep under control until then.
When no control brings residual risk within appetite and the benefit is marginal, avoidance is the only response that respects the organisation's risk appetite. Avoidance means not undertaking or discontinuing the activity that creates the risk. It is the correct treatment when mitigation cannot reach appetite, transfer leaves accountability in place, and acceptance would breach appetite. Because the convenience benefit is marginal, removing the biometric storage rather than carrying an out-of-appetite exposure is the response that aligns with appetite and managerial accountability.

Why A is wrong: Tempting because stacking controls looks diligent and biometric data clearly warrants strong protection; it is wrong because the assessment already shows no control combination reaches appetite, so accepting the remainder still breaches appetite.

Why B is correct: Correct because when no control reduces the residual risk to within appetite and the benefit is marginal, avoidance by removing the risky activity is the only response that keeps the organisation within its stated appetite.

Why C is wrong: Tempting because outsourcing the processing appears to shift the burden to a specialist; it is wrong because the retailer stays accountable for customers' biometric data and the residual risk still exceeds its own appetite.

Why D is wrong: Tempting because deferring with monitoring feels pragmatic for a new feature; it is wrong because monitoring an exposure that already exceeds appetite does not reduce it, so the organisation knowingly operates out of appetite.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Risk Management objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.