CISM · Question #696
An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following…
The correct answer is C. Risk levels may be elevated beyond acceptable limits. Replacing key controls with weaker compensating controls directly threatens the organization's risk posture - if the resulting risk level exceeds the board-approved risk appetite, the exception is fundamentally illegitimate regardless of efficiency gains, making elevated risk…
Question
An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?
Options
- AThe compensating controls are not automated
- BRisk reports to senior management may be inaccurate
- CRisk levels may be elevated beyond acceptable limits
- DNoncompliance with regulatory requirements may result
How the community answered
(56 responses)- A5% (3)
- B21% (12)
- C66% (37)
- D7% (4)
Explanation
Replacing key controls with weaker compensating controls directly threatens the organization's risk posture - if the resulting risk level exceeds the board-approved risk appetite, the exception is fundamentally illegitimate regardless of efficiency gains, making elevated risk the greatest concern.
Why the distractors fall short:
- A - Whether compensating controls are automated is a secondary implementation detail; a manual control can still be effective, so this alone isn't the biggest concern.
- B - Inaccurate risk reporting is a real problem, but it's a symptom or consequence of the core issue, not the issue itself; if risk levels were acceptable, reporting accuracy would matter far less.
- D - Regulatory noncompliance is serious, but it's a specific downstream consequence of elevated risk, not every exception necessarily triggers a compliance violation.
Memory tip: Think of it as the root vs. branch rule - C is the root problem (risk exceeds tolerance), while B and D are branches growing from that root. On exam questions about risk management exceptions, always anchor your answer to the risk appetite framework first; everything else flows from whether risk stays within acceptable limits.
Topics
Community Discussion
No community discussion yet for this question.