nerdexam
Isaca

CISA · Question #127

Which of the following issues identified during a formal review of an organization's information security policies presents the GREATEST potential risk to the organization?

The correct answer is C. The policies are not aligned with the information security risk appetite.. The greatest risk to an organization is when information security policies are not aligned with its defined risk appetite, as this means controls may not adequately address the risks the organization is willing to accept or mitigate.

Submitted by luis.pe· Apr 18, 2026Governance and Management of IT

Question

Which of the following issues identified during a formal review of an organization's information security policies presents the GREATEST potential risk to the organization?

Options

  • AThe policies have not been reviewed by the risk management committee.
  • BThe policies are not based on industry best practices for information security.
  • CThe policies are not aligned with the information security risk appetite.
  • DThe policies are not available to key risk stakeholders.

How the community answered

(55 responses)
  • A
    5% (3)
  • B
    24% (13)
  • C
    62% (34)
  • D
    9% (5)

Why each option

The greatest risk to an organization is when information security policies are not aligned with its defined risk appetite, as this means controls may not adequately address the risks the organization is willing to accept or mitigate.

AThe policies have not been reviewed by the risk management committee.

While policies should ideally be reviewed by a risk management committee, a lack of review, while a weakness, is less critical than the fundamental misalignment with the organization's risk tolerance.

BThe policies are not based on industry best practices for information security.

Not being based on industry best practices can lead to weaknesses, but best practices are a guide; the ultimate measure of policy effectiveness is its alignment with the organization's unique risk profile and appetite.

CThe policies are not aligned with the information security risk appetite.Correct

Information security policies should be a direct reflection of the organization's information security risk appetite, which defines the level of risk the organization is willing to accept. If policies are not aligned with this appetite, the controls implemented may be insufficient or excessive, failing to protect critical assets appropriately or imposing unnecessary burdens, leading to either unmanaged risks or inefficient resource allocation.

DThe policies are not available to key risk stakeholders.

Policies not being available to key stakeholders is a significant communication and awareness issue, but it's secondary to the policies themselves being fundamentally misaligned with the organization's risk tolerance.

Concept tested: Information security policy alignment with risk appetite

Topics

#Information security policies#Risk appetite#IT governance#Risk management

Community Discussion

No community discussion yet for this question.

Full CISA Practice