← All Study Guides

D2: Information Security Risk Management

CISM (ISACA) study guide

CISM D2: Information Security Risk Management

Domain 2 (20% weight) covers information security risk assessment (the emerging risk and threat landscape, vulnerability and control deficiency analysis, risk assessment and analysis) and risk response (treatment options, risk and control ownership, monitoring and reporting), within the broader context of enterprise risk management. It shares vocabulary with CISSP Domain 1's risk content, but study it from a program-management lens: less "what is SLE" and more "how does the security risk function integrate with and report to enterprise risk management."

Key Concepts
  • Risk appetite vs. risk tolerance

    Risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives (strategic, set by the board and senior leadership). Risk tolerance is the acceptable variation management will allow for a specific risk or objective (operational, more granular, often set at the program or component level).

  • Risk register

    The living inventory of identified risks: a description of each risk, its likelihood and impact, mitigation strategies, risk owners and a priority ranking. It is the main vehicle for tracking and communicating cybersecurity risk to enterprise risk management decision-makers, so a security manager is expected to maintain it and report from it, not treat it as a theoretical concept.

  • Risk treatment options

    The same four options as CISSP (accept, transfer, mitigate, avoid). Beyond defining the terms, know the decision behind each: acceptance is made according to the appetite and tolerance senior management has set, and the risk owner holds the authority and accountability for the risk-based decision.

  • Emerging risk and threat landscape monitoring

    Risk identification is an ongoing, proactive process for new and evolving risks (e.g., new technology adoption, threat intelligence, regulatory change), not just periodic point-in-time assessments: stay aware of changes to the risk landscape through alerts, threat feeds and publications, and consider changing business, legal and regulatory environments.

Confusable Pairs
  • Risk appetite vs. risk tolerance (again)

    Appetite is the strategic "how much risk overall," defined by the governing body. Tolerance is the operational "how much variation around a specific objective or risk is acceptable," set by management. When a scenario describes a board-level statement about overall risk, that is appetite; an acceptable range for a particular risk or metric is tolerance.

  • Inherent risk vs. residual risk

    Inherent risk is the risk level in the absence of any management action such as controls. Residual risk is what remains after the risk response: it should be at or below the target residual risk, and risk response aims to bring residual risk within risk appetite limits. That is the comparison that decides whether further treatment is needed.

Sources
  1. [1]
  2. [2]
  3. [3]
  4. [4]
  5. [5]
  6. [6]
  7. [7]
  8. [8]
  9. [9]
  10. [10]
  11. [11]
  12. [12]
  13. [13]
  14. [14]
  15. [15]

Practice D2 questions with instant feedback, free to start, no card required.

Start Free
Your cookie choices
We use essential cookies to run this site, and, only with your consent, advertising cookies from Google, LinkedIn, and Reddit to measure ad performance. See our for details.