Best way to improve departmental risk management effectiveness?

Information Risk Management
Answer Correct answer: D — Propose that security risk be integrated under a common risk register.

What is the BEST way for an information security manager to improve the effectiveness of risk management in an organization that currently manages risk at the departmental level?

  1. Deploy security risk management software in all departments.
  2. Determine whether the organization has defined its risk tolerance and risk appetite.
  3. Subscribe to external risk reports relevant to each department.
  4. Propose that security risk be integrated under a common risk register. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the transition from siloed to enterprise-wide risk management, where the trap is choosing a tool (A) or external data (C) instead of addressing the structural need for centralization (D).

To improve risk management effectiveness in an organization using departmental silos, integrating risks into a common register is the best approach. The community agrees this centralization fosters better coordination and holistic assessment.

A common mistake is selecting option A (deploying software), thinking technology solves process issues, but software cannot fix the lack of a unified view without a common register.

Community Discussion (3 comments)

Josef4CISM 👍 1 Selected: D
Its D to avoid duplication if efforts and achieving efficiency gains by applying measures organization wide. B is also very important to have a common ground of risk appetite.
ServerBrain 👍 1 Selected: D
D. Propose that security risk be integrated under a common risk register.
Booict 👍 2
D - Centralizing risk information fosters better coordination, visibility, and holistic risk assessment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option D is correct because a common risk register provides a centralized, holistic view of risks across the organization. This breaks down silos, prevents duplicate efforts, and allows for better aggregation and prioritization of risks at the enterprise level.

Why the Other Options Are Wrong

Option A is incorrect because deploying software in silos merely automates fragmented processes without solving the lack of integration. Option B is important for governance but is a prerequisite step rather than the immediate action to integrate disparate departmental risks. Option C is incorrect because external reports do not address the internal fragmentation of risk data.

Community Comment Notes

Commenters emphasize that centralization avoids duplication of efforts and achieves efficiency gains by applying measures organization-wide. They also note that while defining risk appetite (B) is valuable, integrating the register (D) is the direct solution to the departmental management problem.

Official Reference

Exam Strategy

When questions mention 'departmental level' or 'silos,' look for answers involving centralization, integration, or enterprise-wide views. Tools (software) are rarely the 'best' answer compared to process improvements like a common register.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide