The information security manager has determined that a risk exceeds risk appetite, yet the manager does not mitigate the risk. What is the MOST likely reason that management would consider this course of action appropriate?

🎲 Try a Random Question  |  Total Questions in Quiz: 730  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
Certified Information Security Manager (CISM) Test Prep Questions — practice the complete quiz, review flashcards, or try a random question.

ISACA CISM Exam syllabus in brief:

Information Security Governance    
A. Enterprise Governance
B. Information Security Strategy

Information Security Risk Management    
A. Information Security Risk Assessment
B. Information Security Risk Response

Information Security Program    
A. Information Security Program Development
B. Information Security Program Management

Incident Management    
A. Incident Management Readiness
B. Incident Management Operations


The information security manager has determined that a risk exceeds risk appetite, yet the manager does not mitigate the risk. What is the MOST likely reason that management would consider this course of action appropriate?






ADVERTISEMENT