Day 2 — Morning · Domain 2 (20%)

Risk Management — Part A

Risk is a business decision, not an IT decision. Part A builds the foundation: the risk management lifecycle, risk appetite and ownership, and how information assets are identified, classified, and valued — the inputs every risk decision depends on.

Session: Morning, Day 2 Duration: ~3 hrs Exam Weight: 20% (Domain 2) Knowledge Check: 7 Questions

Overview

Risk is owned by the business, informed by the assets

Domain 2 is where the manager’s judgment shows. The CISM treats risk as a continuous, business-owned discipline: the security manager identifies, analyzes, and recommends, but the business owns and accepts the risk. Part A lays the groundwork — what risk is and how the lifecycle works, how risk appetite and ownership are set and integrated with enterprise risk management, and how the organization identifies, classifies, and values its information assets. You cannot assess risk to an asset you have not identified, or protect it correctly without knowing what it is worth.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Risk & asset vocabulary

👈 Tap a card to flip it. These terms anchor every risk scenario on the exam.

Lesson Content

Study the material

1

Risk Management Foundations

Objectives 1-2 · lifecycle and appetite

Information risk is the chance that a threat exploits a vulnerability and harms an information asset — conceptually probability × impact. Managing it is a continuous lifecycle, not a project: identify → assess/analyze → treat → monitor & report, then repeat as conditions change.

  • Inherent risk is the exposure before controls; residual risk is what remains after them.
  • The business defines appetite (risk it will accept), tolerance (acceptable variation), and capacity (maximum it could absorb).
  • Risk is a business decision: security manages the process and advises; the business sets appetite and accepts residual risk.
  • A healthy risk culture, driven from the top, makes risk-aware decisions the norm rather than the exception.
💡 Exam TipWatch the verbs in risk questions: the security manager identifies, analyzes, recommends, and reports risk — the business owns and accepts it. An answer where security unilaterally accepts risk is almost always wrong.
2

Integrating Risk With the Enterprise

Objective 3 · risk and ERM

Information security risk does not stand alone — it is one input into enterprise risk management (ERM), which gives leadership a single, consolidated view of all business risk. Aligning to ERM keeps security risk in business language and on the board’s agenda.

  • The risk register records each risk with its owner, likelihood, impact, treatment, and status; the aggregate is the risk profile. (continues in Lesson 3 — analyzing & treating risk)
  • The risk owner is the business leader accountable for the risk; the control owner runs a specific mitigating control.
  • Risk reporting rolls up to leadership in terms of business impact — not raw vulnerability counts.
  • Integrating with ERM avoids security risk being managed in a silo and lets the board weigh it against other enterprise risks.
🔎 In practice

A vulnerability scan returns 4,000 findings. The manager does not hand the board 4,000 numbers — they translate them into a handful of business risks with owners and impact, and record them in the risk register. Governance wants decisions, not data dumps.

3

Identifying & Owning Information Assets

Objective 4 · asset ownership

Risk is always risk to an asset. Before anything can be assessed or protected, the organization must know what information assets it has and who owns them. An incomplete asset inventory is the root cause of blind-spot risk.

  • Information assets include data, applications, systems, and supporting people and processes — not just servers.
  • The data owner is a business role: they classify the data and authorize who may access it.
  • The custodian (often IT) implements and maintains the protection according to the owner’s classification.
  • A maintained asset inventory is the foundation of classification, valuation, and risk assessment.
💡 Exam TipOwnership questions are a favorite: the business data owner classifies data and approves access; IT, as custodian, only implements. An answer that puts IT or the security team in the classification/approval role is wrong.
4

Data Classification

Objective 5 · data classification

Classification assigns each information asset a sensitivity level based on the impact of its loss. Once classified, handling, storage, access, and protection requirements follow automatically — classification is what makes consistent protection scalable.

  • Typical schemes use tiers such as public, internal, confidential, restricted — simpler is better; too many tiers fail in practice.
  • Classification is driven by impact to confidentiality, integrity, and availability, judged in business terms.
  • Each level maps to defined handling rules (encryption, access, retention, disposal).
  • Over-classification wastes resources and breeds workarounds; under-classification leaves data exposed — both are governance failures.
🔎 In practice

A team marks everything ‘confidential’ to be safe. The result is alert fatigue, costly controls on trivial data, and staff ignoring the labels. The manager fixes the classification scheme and training — not by adding more technical controls.

5

Valuing Information Assets

Objective 5 · asset valuation

Valuation tells the organization how much protection an asset justifies and feeds directly into risk analysis and prioritization. The CISM cares less about a precise dollar figure than about valuing assets consistently in business terms.

  • Quantitative valuation expresses worth in money — replacement cost, lost revenue, regulatory fines, recovery cost.
  • Qualitative valuation rates business impact as high/medium/low when hard numbers are impractical.
  • Value should reflect business impact (including reputation and legal exposure), not just the technical cost of the asset.
  • Asset value and classification together drive how much to invest in protecting each asset — the most valuable, most sensitive assets get the most rigor.
💡 Exam TipThe point of valuation is prioritization: spend protection budget where the business impact is greatest. If a question pits an expensive control on a low-value asset against a proportionate control on a high-value one, choose proportionality.

Try it — value an asset and let it classify itself

Rate the business impact of losing an asset’s confidentiality, integrity, and availability, add its replacement cost and any regulatory exposure, and watch its classification and value fall out — because the classification follows the highest impact dimension, and protection should be proportionate to value.

Interactive · adjust & explore
Rate the impact of a loss

How bad is it if this asset’s… is compromised?

$400,000
The valuation
Data classification
Set by
Sensitivity
Est. value at risk
Protection level
🔎 In practice

Two rules the exam rewards: classification tracks the highest of the three impact dimensions (a low-confidentiality but availability-critical system is still highly classified), and protection is proportionate — a Restricted asset earns strong controls, but a Public one does not justify the same spend. Ownership sits with the business data owner, who assigns the classification.

Scored Knowledge Check

Test your risk foundations

Seven questions on risk and assets. Answer as the manager who advises the business and lets the business own the risk.

Q1.In CISM terms, information risk is BEST expressed as a function of:

Question 1 options
Correct: C. Risk is conceptually probability (likelihood the threat exploits the vulnerability) times impact (business harm if it does). Counts and costs are inputs, not the definition. Why the others fall short: A threat and vulnerability counts are inputs, not the definition; B asset and control cost don’t define risk; D compliance gaps are inputs, not risk itself.

Q2.Who is responsible for classifying an information asset and approving who may access it?

Question 2 options
Correct: D. Classification and access approval are business decisions made by the data owner. IT (the custodian) implements protection; security advises; audit evaluates. Why the others fall short: A the custodian implements protection but doesn’t classify; B the security manager advises; C the auditor provides assurance, not classification.

Q3.After controls are applied, some risk remains. Who is responsible for accepting that residual risk?

Question 3 options
Correct: B. Residual risk acceptance is a business decision owned by the risk owner / senior management. The security manager recommends; the business accepts. Why the others fall short: A the security manager advises, not accepts; C a control owner operates a control but doesn’t accept business risk; D IT implements controls.

Q4.What is the PRIMARY purpose of integrating information security risk into enterprise risk management (ERM)?

Question 4 options
Correct: A. ERM integration lets leadership weigh information risk alongside all other enterprise risks in one consolidated, business-language view — rather than managing security risk in a silo. Why the others fall short: B ERM doesn’t reduce the number of controls; C it doesn’t transfer risk to an insurer; D it doesn’t remove the need for a risk register.

Q5.Data classification levels should be determined PRIMARILY by:

Question 5 options
Correct: B. Classification is driven by the business impact of loss across confidentiality, integrity, and availability; handling and protection requirements then follow from the assigned level. Why the others fall short: A storage cost isn’t the basis; C the creating department doesn’t set the level; D data age isn’t the driver — business impact is.

Q6.An organization needs to express the worth of a customer database including likely fines and lost revenue from a breach. This is an example of:

Question 6 options
Correct: A. Expressing value in monetary terms — fines, lost revenue, recovery cost — is quantitative valuation. Qualitative valuation would rate impact as high/medium/low instead. Why the others fall short: B qualitative valuation uses relative high/medium/low, not dollar figures; C inherent risk isn’t a valuation method; D risk tolerance is a different concept.

Q7.Which of the following is the BEST first step before assessing risk to the organization’s information?

Question 7 options
Correct: C. You cannot assess risk to assets you have not identified. A current asset inventory with assigned ownership is the foundation for classification, valuation, and risk assessment. Why the others fall short: A buying a tool is premature; B framework selection comes later; D insurance is a treatment, not a first step — you must know the assets first.