by MTC Group, LLC
CISM D2: Information Security Risk Management
Domain 2 (20% weight) covers information security risk assessment (the emerging risk and threat landscape, vulnerability and control deficiency analysis, risk assessment and analysis) and risk response (treatment options, risk and control ownership, monitoring and reporting), within the broader context of enterprise risk management. It shares vocabulary with CISSP Domain 1's risk content, but study it from a program-management lens: less "what is SLE" and more "how does the security risk function integrate with and report to enterprise risk management."
Risk appetite vs. risk tolerance
Risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives (strategic, set by the board and senior leadership). Risk tolerance is the acceptable variation management will allow for a specific risk or objective (operational, more granular, often set at the program or component level).
Risk register
The living inventory of identified risks: a description of each risk, its likelihood and impact, mitigation strategies, risk owners and a priority ranking. It is the main vehicle for tracking and communicating cybersecurity risk to enterprise risk management decision-makers, so a security manager is expected to maintain it and report from it, not treat it as a theoretical concept.
Risk treatment options
The same four options as CISSP (accept, transfer, mitigate, avoid). Beyond defining the terms, know the decision behind each: acceptance is made according to the appetite and tolerance senior management has set, and the risk owner holds the authority and accountability for the risk-based decision.
Emerging risk and threat landscape monitoring
Risk identification is an ongoing, proactive process for new and evolving risks (e.g., new technology adoption, threat intelligence, regulatory change), not just periodic point-in-time assessments: stay aware of changes to the risk landscape through alerts, threat feeds and publications, and consider changing business, legal and regulatory environments.
Risk appetite vs. risk tolerance (again)
Appetite is the strategic "how much risk overall," defined by the governing body. Tolerance is the operational "how much variation around a specific objective or risk is acceptable," set by management. When a scenario describes a board-level statement about overall risk, that is appetite; an acceptable range for a particular risk or metric is tolerance.
Inherent risk vs. residual risk
Inherent risk is the risk level in the absence of any management action such as controls. Residual risk is what remains after the risk response: it should be at or below the target residual risk, and risk response aims to bring residual risk within risk appetite limits. That is the comparison that decides whether further treatment is needed.
- [1]
- [2]
- [3]
- [4]
- [5]
- [6]
- [7]
- [8]
- [9]
- [10]
- [11]
- [12]
- [13]
- [14]
- [15]
Practice D2 questions with instant feedback, free to start, no card required.
Start Free© 2026 MTC Group, LLC. All rights reserved. InfoSec ExamPrep™ and the InfoSec ExamPrep logo are trademarks of MTC Group, LLC.
For personal exam preparation only. Printed from examprep.mtcgroupllc.com.