CISM Information Risk Management 1 — Questions and Answers
Question 1: In the context of CISM, what is the CORRECT formula for calculating risk?
- Risk = Threat × Asset Value
- Risk = Likelihood × Impact (Correct answer)
- Risk = Vulnerability − Control
- Risk = Threat + Vulnerability + Impact
Correct answer: Risk = Likelihood × Impact
Risk is calculated as the product of the likelihood that a threat event will occur and the impact it would have on the organization.
Question 2: A CISM has identified a critical vulnerability but the cost of remediation exceeds the potential loss. The MOST appropriate risk response is:
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
When remediation costs exceed the potential impact, accepting the risk is the most cost-effective response, provided it falls within the organization's risk appetite.
Question 3: Which of the following is MOST important when prioritizing risks for treatment?
- The age of the vulnerability
- The vendor's severity rating
- The potential business impact and likelihood (Correct answer)
- The number of systems affected
Correct answer: The potential business impact and likelihood
Risks should be prioritized based on their potential business impact and likelihood of occurrence, not just technical severity or vendor ratings.
Question 4: What is the purpose of a risk register in information security management?
- To document all installed security software
- To record identified risks, their assessments, and treatment decisions (Correct answer)
- To list all employees with access to sensitive systems
- To track security incident response timelines
Correct answer: To record identified risks, their assessments, and treatment decisions
A risk register is a formal document that records identified risks, their assessed likelihood and impact, treatment options chosen, and residual risk levels.
Question 5: Which risk assessment approach assigns numerical values to probability and impact to calculate risk scores?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Delphi technique
- Scenario-based assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values (often monetary) to calculate risk scores, enabling objective comparison and cost-benefit analysis.
Question 6: A CISM is conducting a risk assessment and discovers a high likelihood threat with low potential impact. This risk should be:
- Immediately escalated to the board
- Evaluated in the context of the organization's risk appetite (Correct answer)
- Automatically mitigated regardless of cost
- Transferred to a third-party insurer
Correct answer: Evaluated in the context of the organization's risk appetite
All risks, regardless of their individual dimensions, must be evaluated against the organization's defined risk appetite before determining the appropriate response.
In the context of CISM, what is the CORRECT formula for calculating risk?