CISSP - Security and Risk Management - Section 1.9

Understand and apply risk management concepts including risk identification, assessment, response, control selection, and continuous monitoring.

Apply risk management concepts including threat and vulnerability identification, quantitative and qualitative risk assessment, risk response options, and control assessment to reduce organisational exposure. Design a continuous monitoring programme that tracks residual risk and triggers reassessment when the threat environment changes.

threat and vulnerability identificationrisk assessmentrisk responsecontrol assessmentcontinuous monitoring

Practice question for this objective

Free sampleSecurity and Risk Managementhard

A healthcare provider's annual internal audit reports that the security team is reporting control-effectiveness metrics monthly, but the metrics are drawn from the same monitoring data used to operate the controls and have not been independently corroborated. The audit committee has asked the CISO how to address the finding without doubling the monitoring workload. What is the BEST response?

  • AReplace the monthly metrics with an annual third-party control assessment, on the basis that external assurance provides stronger evidence than internal monitoring.
  • BDirect the security operations team to dual-key all metric submissions so that two analysts must agree before figures are released to the audit committee.
  • CIntroduce periodic independent assessment of a sampled subset of the monitored controls, with the sample and frequency informed by risk and reported alongside the operational metrics. Correct
  • DTreat the finding as accepted risk after documenting that the monitoring tooling is configured according to vendor best practice and reviewed by the CISO.
Apply control assessment principles by layering risk-informed independent assurance on top of continuous monitoring rather than substituting one for the other. Effective control assessment, as framed by NIST SP 800-53A and the ISO/IEC 27001 internal audit requirement, separates the operation of a control from the assurance over its effectiveness. Continuous monitoring remains valuable for timeliness, but independent sampled assessment provides the corroborating evidence that closes the segregation gap without duplicating the entire monitoring effort. Sample size and frequency should be driven by the risk of the underlying controls.

Why A is wrong: Swapping continuous monitoring for an annual external assessment trades timeliness for independence and weakens the organisation's ability to detect control drift between assessments. The audit finding is about corroboration, not about the cadence of monitoring.

Why B is wrong: Dual-keying within the same team improves data integrity but does not introduce independence. The audit finding is that the operators of the control are also the source of the assurance evidence, which a second analyst in the same function does not resolve.

Why C is correct: Layering risk-informed independent assessment on top of operational monitoring directly addresses the corroboration gap without duplicating the full workload. It is the management-led answer that preserves continuous monitoring while satisfying the audit principle that assurance evidence should not be produced solely by the function operating the control.

Why D is wrong: Accepting the finding on the basis of tooling configuration confuses operational hygiene with independent assurance, and risk acceptance without addressing the underlying gap would likely be rejected by the audit committee. It is a defensible-sounding but second-best response.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security and Risk Management objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.