nerdexam
Isaca

CISM · Question #925

Which of the following should be of GREATEST concern to an information security manager when establishing a set of key risk indicators (KRIs)?

The correct answer is C. The impact of security risk on organizational objectives is not well understood. KRIs must reflect what matters most to the business and provide actionable insight. If the impact of security risk on organizational objectives is not understood, the organization cannot select meaningful KRIs or set appropriate thresholds, making this the greatest concern.

Submitted by certguy· Apr 18, 2026Information Security Governance

Question

Which of the following should be of GREATEST concern to an information security manager when establishing a set of key risk indicators (KRIs)?

Options

  • AAnnual loss expectancy (ALE) has not yet been determined.
  • BThe organization has no historical data on previous risk events.
  • CThe impact of security risk on organizational objectives is not well understood.
  • DSeveral business functions have been outsourced to third-party vendors.

How the community answered

(53 responses)
  • A
    21% (11)
  • B
    4% (2)
  • C
    62% (33)
  • D
    13% (7)

Explanation

KRIs must reflect what matters most to the business and provide actionable insight. If the impact of security risk on organizational objectives is not understood, the organization cannot select meaningful KRIs or set appropriate thresholds, making this the greatest concern.

Topics

#Key Risk Indicators (KRIs)#Risk Management Alignment#Organizational Objectives#Information Security Governance

Community Discussion

No community discussion yet for this question.

Full CISM Practice