nerdexam
Isaca

CISM · Question #650

While reviewing a business case, an information security manager has determined that the residual risk will be higher than the organization's risk tolerance. As a result, which of the following…

The correct answer is B. Mitigating actions. Mitigating actions (B) are the correct addition because when residual risk exceeds risk tolerance, the business case must show how that gap will be closed - mitigating actions directly reduce residual risk to bring it within acceptable limits, which is the security manager's…

Submitted by kevin_r· Apr 18, 2026Information Security Risk Management

Question

While reviewing a business case, an information security manager has determined that the residual risk will be higher than the organization’s risk tolerance. As a result, which of the following should be added to the business case?

Options

  • AAn adjusted risk appetite
  • BMitigating actions
  • CAn alternative business plan
  • DA cost-benefit analysis

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    83% (30)
  • C
    3% (1)
  • D
    8% (3)

Explanation

Mitigating actions (B) are the correct addition because when residual risk exceeds risk tolerance, the business case must show how that gap will be closed - mitigating actions directly reduce residual risk to bring it within acceptable limits, which is the security manager's responsibility to address before a business case can be approved.

A (Adjusted risk appetite) is wrong because risk appetite is an organizational-level policy decision set by leadership, not something an information security manager adjusts within a single business case to make the numbers work - that would be "lowering the bar" rather than solving the problem.

C (Alternative business plan) is wrong because replacing the entire plan is a last resort, not a standard response to a residual risk gap; the problem calls for addressing risk within the existing business case, not abandoning it.

D (A cost-benefit analysis) is wrong because cost-benefit analysis evaluates financial tradeoffs of a decision already made - it doesn't reduce risk or close the gap between residual risk and tolerance.

Memory tip: Think of residual risk as "leftover risk after controls." If the leftovers are too much, you don't change your appetite or throw away the meal - you mitigate (reduce) what's left.

Topics

#Risk management#Residual risk#Risk tolerance#Mitigation

Community Discussion

No community discussion yet for this question.

Full CISM Practice