Practice questions

CISM (ISACA): Practice Questions

By The Exam Atlas Editorial Team · Verified 2026-05-31

Ten original concept-check questions on core CISM ideas. Choose an answer to reveal the explanation. Answer as a risk-focused security manager, not a technician.

  1. Compared with CISSP, CISM is most focused on:

  2. The primary goal of information security governance is to:

  3. 'Risk appetite' is best described as:

  4. When an identified risk exceeds the organisation's risk appetite, the security manager should FIRST:

  5. The primary purpose of a Business Impact Analysis (BIA) is to:

  6. A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:

  7. 'Residual risk' is the risk that remains:

  8. When establishing a new security programme, the BEST first step is to:

  9. During a serious incident, the security manager's priority is to:

  10. Third-party (vendor) risk should be managed by:

Sources