nerdexam
Isaca

CISM · Question #9

When integrating security risk management into an organization it is MOST important to ensure:

The correct answer is B. business units approve the risk management methodology. When integrating security risk management, it is most important to ensure that business units approve the risk management methodology, as this fosters organizational buy-in and practical application.

Submitted by asante_acc· Apr 18, 2026Information Security Governance

Question

When integrating security risk management into an organization it is MOST important to ensure:

Options

  • Athe risk management methodology follows an established framework.
  • Bbusiness units approve the risk management methodology.
  • Cthe risk treatment process is defined.
  • Dinformation security policies are documented and understood.

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    77% (36)
  • C
    4% (2)
  • D
    13% (6)

Why each option

When integrating security risk management, it is most important to ensure that business units approve the risk management methodology, as this fosters organizational buy-in and practical application.

Athe risk management methodology follows an established framework.

While following an established framework is a good practice for robustness, without business unit approval, even a well-structured methodology may not be effectively adopted or applied.

Bbusiness units approve the risk management methodology.Correct

Business unit approval of the risk management methodology ensures that the approach is practical, relevant to their operations, and integrated into their decision-making processes, leading to greater adoption and effectiveness across the organization. Without business unit buy-in, even a technically sound methodology may fail to be effectively implemented.

Cthe risk treatment process is defined.

Defining the risk treatment process is a crucial component of risk management, but it is a tactical detail that stems from an approved and integrated methodology.

Dinformation security policies are documented and understood.

Documenting and understanding information security policies are fundamental, but policies are part of the overall security program that risk management informs and supports; their existence alone doesn't ensure integrated risk management.

Concept tested: Risk management integration and buy-in

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf

Topics

#Risk Management Integration#Organizational Buy-in#Stakeholder Approval#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice