nerdexam
Isaca

CISM · Question #59

Which of the following would BEST fulfill a board of directors' request for a concise overview of information security risk facing the business?

The correct answer is C. Risk heat map. A risk heat map best fulfills a board's request for a concise overview of information security risk by visually representing risk levels based on likelihood and impact.

Submitted by certguy· Apr 18, 2026Information Security Risk Management

Question

Which of the following would BEST fulfill a board of directors' request for a concise overview of information security risk facing the business?

Options

  • ABusiness impact analysis (BIA)
  • BBalanced scorecard
  • CRisk heat map
  • DRisk scenario summary

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    13% (5)
  • C
    79% (31)
  • D
    3% (1)

Why each option

A risk heat map best fulfills a board's request for a concise overview of information security risk by visually representing risk levels based on likelihood and impact.

ABusiness impact analysis (BIA)

A Business Impact Analysis (BIA) details the impact of disruptions on business processes but is typically a detailed report, not a concise overview of *all* security risks.

BBalanced scorecard

A balanced scorecard is a strategic performance management tool that measures various aspects of an organization, not specifically focused on a concise overview of security risk.

CRisk heat mapCorrect

A risk heat map is the best tool for providing a board of directors with a concise overview of information security risk because it visually presents the severity and likelihood of various risks. This graphical representation allows for quick comprehension of the most critical risks, enabling the board to prioritize concerns and make informed strategic decisions regarding risk treatment.

DRisk scenario summary

A risk scenario summary, while useful, is often more detailed and less immediately digestible than the visual aggregation provided by a heat map for a board-level overview.

Concept tested: Risk reporting for executive management

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/risk-management-overview

Topics

#Risk reporting#Executive communication#Risk visualization#Information security risk

Community Discussion

No community discussion yet for this question.

Full CISM Practice