Risk is a business decision, not an IT decision. Part A builds the foundation: the risk management lifecycle, risk appetite and ownership, and how information assets are identified, classified, and valued — the inputs every risk decision depends on.
Risk is owned by the business, informed by the assets
Domain 2 is where the manager’s judgment shows. The CISM treats risk as a continuous, business-owned discipline: the security manager identifies, analyzes, and recommends, but the business owns and accepts the risk. Part A lays the groundwork — what risk is and how the lifecycle works, how risk appetite and ownership are set and integrated with enterprise risk management, and how the organization identifies, classifies, and values its information assets. You cannot assess risk to an asset you have not identified, or protect it correctly without knowing what it is worth.
Learning Objectives
By the end of this lesson you will be able to…
Describe information risk and the continuous risk management lifecycle. Bloom: Understand
Differentiate inherent and residual risk, and risk appetite, tolerance, and capacity. Bloom: Analyze
Distinguish risk owners from control owners and locate risk within enterprise risk management. Bloom: Analyze
Identify information assets and assign ownership (owner vs. custodian). Bloom: Remember
Classify and value information assets to drive protection and prioritize risk treatment.
Key Terms
Risk & asset vocabulary
👈 Tap a card to flip it. These terms anchor every risk scenario on the exam.
Lesson Content
Study the material
1
Risk Management Foundations
Objectives 1-2 · lifecycle and appetite
Information risk is the chance that a threat exploits a vulnerability and harms an information asset — conceptually probability × impact. Managing it is a continuous lifecycle, not a project: identify → assess/analyze → treat → monitor & report, then repeat as conditions change.
Inherent risk is the exposure before controls; residual risk is what remains after them.
The business defines appetite (risk it will accept), tolerance (acceptable variation), and capacity (maximum it could absorb).
Risk is a business decision: security manages the process and advises; the business sets appetite and accepts residual risk.
A healthy risk culture, driven from the top, makes risk-aware decisions the norm rather than the exception.
💡 Exam TipWatch the verbs in risk questions: the security manager identifies, analyzes, recommends, and reports risk — the business owns and accepts it. An answer where security unilaterally accepts risk is almost always wrong.
2
Integrating Risk With the Enterprise
Objective 3 · risk and ERM
Information security risk does not stand alone — it is one input into enterprise risk management (ERM), which gives leadership a single, consolidated view of all business risk. Aligning to ERM keeps security risk in business language and on the board’s agenda.
The risk register records each risk with its owner, likelihood, impact, treatment, and status; the aggregate is the risk profile. (continues in Lesson 3 — analyzing & treating risk)
The risk owner is the business leader accountable for the risk; the control owner runs a specific mitigating control.
Risk reporting rolls up to leadership in terms of business impact — not raw vulnerability counts.
Integrating with ERM avoids security risk being managed in a silo and lets the board weigh it against other enterprise risks.
🔎 In practice
A vulnerability scan returns 4,000 findings. The manager does not hand the board 4,000 numbers — they translate them into a handful of business risks with owners and impact, and record them in the risk register. Governance wants decisions, not data dumps.
3
Identifying & Owning Information Assets
Objective 4 · asset ownership
Risk is always risk to an asset. Before anything can be assessed or protected, the organization must know what information assets it has and who owns them. An incomplete asset inventory is the root cause of blind-spot risk.
Information assets include data, applications, systems, and supporting people and processes — not just servers.
The data owner is a business role: they classify the data and authorize who may access it.
The custodian (often IT) implements and maintains the protection according to the owner’s classification.
A maintained asset inventory is the foundation of classification, valuation, and risk assessment.
💡 Exam TipOwnership questions are a favorite: the business data owner classifies data and approves access; IT, as custodian, only implements. An answer that puts IT or the security team in the classification/approval role is wrong.
📚
Explore furtherRisk Management and Data Roles — interactive modules on the risk-management process and on data ownership, custodianship, and the roles that govern information assets.
Classification assigns each information asset a sensitivity level based on the impact of its loss. Once classified, handling, storage, access, and protection requirements follow automatically — classification is what makes consistent protection scalable.
Typical schemes use tiers such as public, internal, confidential, restricted — simpler is better; too many tiers fail in practice.
Classification is driven by impact to confidentiality, integrity, and availability, judged in business terms.
Each level maps to defined handling rules (encryption, access, retention, disposal).
Over-classification wastes resources and breeds workarounds; under-classification leaves data exposed — both are governance failures.
🔎 In practice
A team marks everything ‘confidential’ to be safe. The result is alert fatigue, costly controls on trivial data, and staff ignoring the labels. The manager fixes the classification scheme and training — not by adding more technical controls.
5
Valuing Information Assets
Objective 5 · asset valuation
Valuation tells the organization how much protection an asset justifies and feeds directly into risk analysis and prioritization. The CISM cares less about a precise dollar figure than about valuing assets consistently in business terms.
Quantitative valuation expresses worth in money — replacement cost, lost revenue, regulatory fines, recovery cost.
Qualitative valuation rates business impact as high/medium/low when hard numbers are impractical.
Value should reflect business impact (including reputation and legal exposure), not just the technical cost of the asset.
Asset value and classification together drive how much to invest in protecting each asset — the most valuable, most sensitive assets get the most rigor.
💡 Exam TipThe point of valuation is prioritization: spend protection budget where the business impact is greatest. If a question pits an expensive control on a low-value asset against a proportionate control on a high-value one, choose proportionality.
Try it — value an asset and let it classify itself
Rate the business impact of losing an asset’s confidentiality, integrity, and availability, add its replacement cost and any regulatory exposure, and watch its classification and value fall out — because the classification follows the highest impact dimension, and protection should be proportionate to value.
Interactive · adjust & explore
Rate the impact of a loss
How bad is it if this asset’s… is compromised?
$400,000
The valuation
Data classification
—
—
Set by
—
Sensitivity
—
Est. value at risk
—
Protection level
—
🔎 In practice
Two rules the exam rewards: classification tracks the highest of the three impact dimensions (a low-confidentiality but availability-critical system is still highly classified), and protection is proportionate — a Restricted asset earns strong controls, but a Public one does not justify the same spend. Ownership sits with the business data owner, who assigns the classification.
Scored Knowledge Check
Test your risk foundations
Seven questions on risk and assets. Answer as the manager who advises the business and lets the business own the risk.