nerdexam
Isaca

CISM · Question #487

An application system audit revealed the same security weakness identified in a previous audit with risk acceptance due to expire. From a risk management perspective, which of the following is the…

The correct answer is D. Raise the observation to the business risk owner to discuss risk treatment options. Why D is correct: When a previously accepted risk resurfaces with its acceptance period expiring, the information security manager's role is not to unilaterally decide the treatment - it's to escalate to the business risk owner, who has the authority and accountability to…

Submitted by sofia.br· Apr 18, 2026Information Security Risk Management

Question

An application system audit revealed the same security weakness identified in a previous audit with risk acceptance due to expire. From a risk management perspective, which of the following is the information security manager's BEST course of action?

Options

  • AUpdate the existing finding in the risk register with the risk acceptance period extended.
  • BCreate a new entry in the risk register and close the previous risk finding.
  • CTransfer the risk to an insurance policy and close the risk finding.
  • DRaise the observation to the business risk owner to discuss risk treatment options.

How the community answered

(14 responses)
  • A
    7% (1)
  • C
    14% (2)
  • D
    79% (11)

Explanation

Why D is correct: When a previously accepted risk resurfaces with its acceptance period expiring, the information security manager's role is not to unilaterally decide the treatment - it's to escalate to the business risk owner, who has the authority and accountability to decide how the risk should be handled (accept again, mitigate, transfer, or avoid). Raising the observation ensures proper governance and informed decision-making before the acceptance window closes.

Why the distractors are wrong:

  • A is wrong because extending the acceptance period is a business decision, not one the security manager makes alone - and doing so without stakeholder input bypasses governance.
  • B is wrong because closing a prior finding and creating a new one adds confusion without adding value; the risk lineage and history should be preserved, not fragmented.
  • C is wrong because transferring risk to insurance is one possible treatment option, but the security manager cannot choose it unilaterally - that's the risk owner's call, and it prematurely closes the finding.

Memory tip: Think of the security manager as an advisor, not a decision-maker for business risk. Whenever a risk needs treatment, the answer almost always involves escalating to the risk owner - the person with both the authority and the accountability to accept consequences.

Topics

#Risk Management Process#Risk Acceptance#Risk Owner#Information Security Manager Responsibilities

Community Discussion

No community discussion yet for this question.

Full CISM Practice