nerdexam
Isaca

CISM · Question #945

Which of the following is MOST important to consider when determining thresholds for key risk indicators (KRIs)?

The correct answer is D. Risk appetite. Risk appetite defines how much risk an organization is willing to accept, which makes it the foundational input for setting KRI thresholds - a threshold is essentially the quantified boundary between acceptable and unacceptable risk levels, so it must directly reflect what…

Submitted by femi9· Apr 18, 2026Information Security Risk Management

Question

Which of the following is MOST important to consider when determining thresholds for key risk indicators (KRIs)?

Options

  • AHistorical KRI data
  • BControl effectiveness
  • CThreat exposure
  • DRisk appetite

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    5% (3)
  • C
    12% (7)
  • D
    79% (46)

Explanation

Risk appetite defines how much risk an organization is willing to accept, which makes it the foundational input for setting KRI thresholds - a threshold is essentially the quantified boundary between acceptable and unacceptable risk levels, so it must directly reflect what leadership has decided to tolerate.

Why the distractors fall short:

  • A (Historical KRI data) - past data informs calibration but doesn't define what should be acceptable; history describes what was, not what should be tolerated.
  • B (Control effectiveness) - controls affect residual risk levels but don't determine the threshold at which you escalate or act; that decision flows from appetite.
  • C (Threat exposure) - understanding threats is part of risk assessment, but high threat exposure doesn't automatically change what your organization is willing to accept.

Memory tip: Think of KRI thresholds as a speed limit sign - the limit is set by policy (risk appetite), not by how fast cars have gone historically, how good the brakes are, or how icy the road is. Appetite = the line in the sand.

Topics

#Key Risk Indicators (KRIs)#Risk Appetite#Risk Thresholds#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CISM Practice