nerdexam
Isaca

CISM · Question #106

What is the BEST way for an information security manager to improve the effectiveness of risk management in an organization that currently manages risk at the departmental level?

The correct answer is D. Propose that security risk be integrated under a common risk register. To improve risk management effectiveness from a departmental level, an organization should integrate security risk under a common risk register, enabling a holistic view and centralized management.

Submitted by parkjh· Apr 18, 2026Information Security Governance

Question

What is the BEST way for an information security manager to improve the effectiveness of risk management in an organization that currently manages risk at the departmental level?

Options

  • ADeploy security risk management software in all departments.
  • BDetermine whether the organization has defined its risk tolerance and risk appetite.
  • CSubscribe to external risk reports relevant to each department.
  • DPropose that security risk be integrated under a common risk register.

How the community answered

(59 responses)
  • A
    3% (2)
  • B
    10% (6)
  • C
    5% (3)
  • D
    81% (48)

Why each option

To improve risk management effectiveness from a departmental level, an organization should integrate security risk under a common risk register, enabling a holistic view and centralized management.

ADeploy security risk management software in all departments.

Deploying risk management software might standardize tools but doesn't inherently integrate departmental risk management or improve its effectiveness at an organizational level without a unified approach.

BDetermine whether the organization has defined its risk tolerance and risk appetite.

While defining risk tolerance and appetite is critical for effective risk management, it is a foundational policy step that should precede or accompany the integration of risk, rather than the "BEST way" to improve effectiveness from departmental to organizational.

CSubscribe to external risk reports relevant to each department.

Subscribing to external risk reports provides valuable context but doesn't directly address the organizational challenge of fragmented, departmental risk management.

DPropose that security risk be integrated under a common risk register.Correct

Integrating security risk into a common risk register allows for a comprehensive, enterprise-wide view of risks, fostering consistency in risk assessment and treatment across departments. This approach moves beyond siloed departmental risk management, enabling centralized oversight, prioritization, and resource allocation based on the organization's overall risk appetite.

Concept tested: Enterprise risk management integration

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Risk Management Integration#Enterprise Risk Management#Common Risk Register#Organizational Risk Strategy

Community Discussion

No community discussion yet for this question.

Full CISM Practice