nerdexam
Isaca

CISM · Question #103

When reporting information security risk to senior management, it is MOST important to include:

The correct answer is D. residual risk.. When reporting information security risk to senior management, it is most crucial to communicate the residual risk, as this represents the current level of risk remaining after controls have been implemented.

Submitted by helene.fr· Apr 18, 2026Information Security Risk Management

Question

When reporting information security risk to senior management, it is MOST important to include:

Options

  • Acontrol risk.
  • Binherent risk.
  • Cdetection risk.
  • Dresidual risk.

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    5% (1)
  • D
    81% (17)

Why each option

When reporting information security risk to senior management, it is most crucial to communicate the residual risk, as this represents the current level of risk remaining after controls have been implemented.

Acontrol risk.

Control risk refers to the risk that a control fails to prevent or detect a misstatement, which is an input to assessing inherent and residual risk, but not the final picture for management.

Binherent risk.

Inherent risk is the risk before any controls are put in place, which is useful for initial assessment but doesn't reflect the current state for management decision-making.

Cdetection risk.

Detection risk is the risk that an auditor will not detect a material misstatement, primarily relevant to audit processes rather than the ongoing operational risk reporting to management.

Dresidual risk.Correct

When reporting information security risk to senior management, it is most important to include residual risk because this figure represents the current level of risk remaining after all implemented controls have been considered. Senior management needs to understand the actual exposure and potential impact to the business that persists, enabling them to make informed decisions about further mitigation or risk acceptance.

Concept tested: Risk reporting to senior management

Topics

#Residual risk#Risk reporting#Senior management communication#Information security risk management

Community Discussion

No community discussion yet for this question.

Full CISM Practice