nerdexam
Isaca

CISM · Question #502

Which of the following is the BEST way for an information security manager to identify emerging risk to an organization?

The correct answer is A. Subscribe to external threat intelligence sources.. Subscribing to external threat intelligence sources (A) is the best way to identify emerging risks because it provides proactive, real-time insight into new threats, vulnerabilities, and attack trends before they materialize internally - something no internal process can replicat

Submitted by cyberguy42· Apr 18, 2026Information Security Risk Management

Question

Which of the following is the BEST way for an information security manager to identify emerging risk to an organization?

Options

  • ASubscribe to external threat intelligence sources.
  • BConduct periodic testing of controls to ensure they meet control objectives.
  • CMaintain an up-to-date risk register with accountable owners.
  • DOrganize regular risk meetings with senior stakeholders.

How the community answered

(39 responses)
  • A
    85% (33)
  • B
    8% (3)
  • C
    5% (2)
  • D
    3% (1)

Explanation

Subscribing to external threat intelligence sources (A) is the best way to identify emerging risks because it provides proactive, real-time insight into new threats, vulnerabilities, and attack trends before they materialize internally - something no internal process can replicate for truly novel risks.

  • B is wrong because testing existing controls evaluates known risks and whether current defenses work - it doesn't surface threats you haven't yet accounted for.
  • C is wrong because a risk register documents risks already identified; it's a management tool, not a discovery mechanism for emerging threats.
  • D is wrong because stakeholder meetings rely on internal knowledge and perspectives, which lags behind the external threat landscape.

Memory tip: The word emerging is the key - think "outside-in." Only external intelligence feeds can tell you what's new in the wild. Internal activities (testing, registers, meetings) are all retrospective or internally-scoped by nature.

Topics

#Emerging Risk Identification#Threat Intelligence#Risk Monitoring#Security Risk Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice