nerdexam
Isaca

CISM · Question #492

A chief information security officer (CISO) has identified multiple critical risks with various financial, operational, and reputational impacts. Which of the following is the MOST effective…

The correct answer is C. Use the organization's risk criteria as a key factor in choosing risk treatment strategies. Using an organization's risk criteria as the foundation for risk treatment decisions ensures that chosen strategies are calibrated to what the organization has defined as acceptable risk - this is the definition of aligning with risk appetite. Risk criteria encode the…

Submitted by saadiq_pk· Apr 18, 2026Information Security Risk Management

Question

A chief information security officer (CISO) has identified multiple critical risks with various financial, operational, and reputational impacts. Which of the following is the MOST effective approach for selecting risk treatment options that align with the organization's risk appetite?

Options

  • AAllocate equal budget for treating all identified critical risks.
  • BPrioritize controls that can be implemented in the shortest time.
  • CUse the organization's risk criteria as a key factor in choosing risk treatment strategies.
  • DFocus solely on risks with the highest financial implications, including the cost of risk treatment.

How the community answered

(23 responses)
  • A
    13% (3)
  • B
    4% (1)
  • C
    74% (17)
  • D
    9% (2)

Explanation

Using an organization's risk criteria as the foundation for risk treatment decisions ensures that chosen strategies are calibrated to what the organization has defined as acceptable risk - this is the definition of aligning with risk appetite. Risk criteria encode the organization's values, thresholds, and tolerances, making them the authoritative guide for comparing and selecting among treatment options.

Why the distractors fail:

  • A is wrong because equal budget allocation ignores risk severity and priority - resources should be weighted toward risks that most exceed acceptable thresholds, not spread uniformly.
  • B is wrong because speed of implementation is an operational convenience, not a risk-alignment criterion; a fast control that doesn't address the right risk wastes resources.
  • D is wrong because focusing solely on financial impact ignores operational and reputational risks the CISO explicitly identified, and omitting non-financial criteria means decisions won't reflect the full risk appetite.

Memory tip: Think of risk criteria as the organization's rulebook for risk. Just as a referee uses the rulebook - not speed, budget, or one stat - to make calls, the CISO uses risk criteria to make fair, consistent treatment decisions. When you see "align with risk appetite," the answer will always point back to the defined criteria, not a single metric or convenience factor.

Topics

#risk treatment#risk appetite#risk criteria#risk management strategy

Community Discussion

No community discussion yet for this question.

Full CISM Practice