nerdexam
Isaca

CISM · Question #485

The selection of security controls should be PRIMARILY linked to:

The correct answer is A. the risk appetite of the organization. Security controls exist to bring risk down to a level the organization is willing to accept-its risk appetite. Controls should be selected and calibrated based on whether they address the specific risks that fall outside that tolerance. Regulatory requirements (B) establish…

Submitted by zhang_li· Apr 18, 2026Information Security Governance

Question

The selection of security controls should be PRIMARILY linked to:

Options

  • Athe risk appetite of the organization.
  • Bregulatory requirements.
  • Cfindings from external auditors.
  • Dvulnerability assessment results.

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    7% (2)
  • D
    3% (1)

Explanation

Security controls exist to bring risk down to a level the organization is willing to accept-its risk appetite. Controls should be selected and calibrated based on whether they address the specific risks that fall outside that tolerance. Regulatory requirements (B) establish minimum baselines but do not capture the full scope of organizational risk. External audit findings (C) identify gaps but are reactive and narrow. Vulnerability assessments (D) reveal technical weaknesses but are one input among many. Risk appetite is the primary driver because it integrates business context, strategic objectives, and tolerance for potential loss into control selection decisions.

Topics

#Risk Appetite#Security Controls#Risk Management#Control Selection

Community Discussion

No community discussion yet for this question.

Full CISM Practice