CISM - Information Security Risk Management (20% of the exam) - Section 2.4

Evaluate and select appropriate risk treatment and risk response options in accordance with the organisation's risk appetite.

Evaluate the four risk treatment options - risk mitigation, risk transfer, risk acceptance, and risk avoidance - and select the response that best matches the organisation's documented risk appetite. Recognise that residual risk remaining after treatment must be formally accepted by an appropriate risk owner.

Risk treatmentRisk acceptanceRisk transferRisk mitigation

Practice question for this objective

Free sampleInformation Security Risk Managementmedium

A retailer plans to launch a feature that stores customers' biometric templates to speed up sign-in. Assessment shows the resulting residual risk exceeds the board's risk appetite, no available control brings it within appetite, and the feature delivers only a marginal convenience benefit. The information security manager must recommend a risk response. Which response is most appropriate?

  • ARecommend layering every available control on the biometric store and accepting whatever residual risk remains, on the basis that thorough mitigation is the responsible engineering choice for sensitive data.
  • BRecommend not proceeding with biometric storage and meeting the sign-in goal another way, because the risk cannot be brought within appetite and the benefit does not justify carrying an out-of-appetite exposure. Correct
  • CRecommend transferring the exposure to a specialist biometric processor under contract, so the residual risk becomes the processor's responsibility and the feature can launch as planned.
  • DRecommend launching the feature now and revisiting the exposure at the next annual risk review, treating the gap as a temporary deviation that monitoring will keep under control until then.
When no control brings residual risk within appetite and the benefit is marginal, avoidance is the only response that respects the organisation's risk appetite. Avoidance means not undertaking or discontinuing the activity that creates the risk. It is the correct treatment when mitigation cannot reach appetite, transfer leaves accountability in place, and acceptance would breach appetite. Because the convenience benefit is marginal, removing the biometric storage rather than carrying an out-of-appetite exposure is the response that aligns with appetite and managerial accountability.

Why A is wrong: Tempting because stacking controls looks diligent and biometric data clearly warrants strong protection; it is wrong because the assessment already shows no control combination reaches appetite, so accepting the remainder still breaches appetite.

Why B is correct: Correct because when no control reduces the residual risk to within appetite and the benefit is marginal, avoidance by removing the risky activity is the only response that keeps the organisation within its stated appetite.

Why C is wrong: Tempting because outsourcing the processing appears to shift the burden to a specialist; it is wrong because the retailer stays accountable for customers' biometric data and the residual risk still exceeds its own appetite.

Why D is wrong: Tempting because deferring with monitoring feels pragmatic for a new feature; it is wrong because monitoring an exposure that already exceeds appetite does not reduce it, so the organisation knowingly operates out of appetite.

See more CISM practice questions, answers explained.

Exam traps in Information Security Risk Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISM bank for this domain.

  • Acceptance is appropriate for any risk the security team judges too costly to control, decided informally to avoid governance delay.

    Why it is wrong: Speed is tempting, but acceptance decided informally by the security team bypasses the accountable owner and removes the documented approval that legitimate acceptance requires.

  • Allow the security manager to informally tolerate the exposure until the replacement project is funded, since the gap is already known to the team.

    Why it is wrong: Informal toleration is tempting because the risk is already understood, but acceptance must be a documented decision made by the accountable owner, not an undocumented choice by the security function, or accountability and visibility are lost.

  • The owner's name is entered in the risk register alongside the residual rating and refreshed whenever the register is reissued

    Why it is wrong: Tempting because a named entry looks like ownership, but recording a name alone is nominal and does not evidence that the owner actively decided to accept the exposure.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.