CISM Information Risk Management 2 — Questions and Answers
Question 1: Which of the following BEST describes 'inherent risk' in information security?
- Risk remaining after controls are applied
- Risk that exists before any controls are implemented (Correct answer)
- Risk transferred to a third party via insurance
- Risk associated with third-party vendors only
Correct answer: Risk that exists before any controls are implemented
Inherent risk is the level of risk that exists naturally before any controls or mitigations are put in place.
Question 2: What is 'residual risk' in information security risk management?
- The original risk before any assessment is performed
- The risk that remains after controls have been applied (Correct answer)
- The risk associated with legacy systems only
- The risk transferred to cyber insurance policies
Correct answer: The risk that remains after controls have been applied
Residual risk is the amount of risk that remains after security controls have been implemented to reduce or manage the inherent risk.
Question 3: A CISM is evaluating third-party vendors. Which risk is MOST relevant to this activity?
- Reputational risk
- Supply chain and third-party risk (Correct answer)
- Market risk
- Liquidity risk
Correct answer: Supply chain and third-party risk
Third-party vendors introduce supply chain and vendor risk, where weaknesses in vendor security posture can compromise the organization's own security.
Question 4: Which of the following BEST describes the purpose of a Business Impact Analysis (BIA)?
- To identify all network vulnerabilities in the organization
- To determine critical business processes and the impact of their disruption (Correct answer)
- To calculate the cost of deploying new security technologies
- To assess employee compliance with security policies
Correct answer: To determine critical business processes and the impact of their disruption
A BIA identifies critical business processes, their dependencies, and the potential impact of disruption, which informs risk prioritization and continuity planning.
Question 5: An organization is considering purchasing cyber liability insurance. From a risk management perspective, this is an example of:
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Purchasing cyber liability insurance transfers the financial consequences of a security event to a third-party insurer.
Question 6: Which of the following is a KEY component of an effective risk communication strategy?
- Using technical jargon to demonstrate expertise
- Translating risk findings into business terms for stakeholders (Correct answer)
- Restricting risk reports to IT and security teams only
- Publishing raw vulnerability data on the intranet
Correct answer: Translating risk findings into business terms for stakeholders
Effective risk communication requires translating technical findings into business-relevant language so that stakeholders can make informed decisions.
Which of the following BEST describes 'inherent risk' in information security?