What is the Most Important Objective When Recommending Controls?

Risk Management
Answer Correct answer: C — Prioritize reducing organizational risk to an acceptable level aligned with established risk appetite when evaluating and recommending security controls.

Which of the following is the MOST important objective when recommending controls?

  1. Ensuring implementation costs are approved
  2. Identifying business processes the controls can support
  3. Reducing the risk to an acceptable level Correct Answer
  4. Minimizing the impact to business processes

Community Votes

C
80%
D
20%

80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding that security controls exist to mitigate risk to an acceptable threshold, often tricking candidates into prioritizing operational continuity or cost over risk reduction.

Recommending information security controls primarily aims to reduce organizational risk to an acceptable level aligned with business objectives. Community consensus and official guidance confirm that risk reduction, not cost approval or process minimization, is the paramount objective.

Option D (Minimizing the impact to business processes) is frequently chosen because candidates confuse operational resilience with risk management, overlooking that controls must first address the underlying risk exposure before optimizing business impact.

Community Discussion (3 comments)

fac161f 👍 1 Selected: C
Minimizing impact to a buisness process is about Risk Appetite. Risk appetite does define acceptable risk but the goal should be "Reducing" risk to that acceptable level. The correct answer is C .
ATT5832 👍 3 Selected: C
Answer - C
ServerBrain 👍 1 Selected: D
D. Minimizing the impact to business processes

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security controls function as risk treatment mechanisms designed to lower inherent vulnerabilities and threats to a manageable state. CISM frameworks mandate that management’s foremost duty is aligning security investments with the organization’s defined risk appetite. Consequently, recommending controls must prioritize achieving this acceptable risk threshold above all secondary factors.

Why the Other Options Are Wrong

Option A focuses on financial approval, which remains a procedural step rather than the strategic purpose of controls. Option B addresses process alignment but fails to define the ultimate protective outcome. Option D conflates impact mitigation with risk reduction, treating symptoms rather than the root cause of potential loss.

Community Comment Notes

Top-voted discussions emphasize that risk appetite establishes the boundary for acceptable exposure, making risk reduction the logical endpoint. Contributors clarify that while minimizing business disruption matters, it operates strictly within the limits set by acceptable risk levels. As noted in high-ranking comments, the goal is actively reducing risk to that predefined threshold, validating option C.

Official Reference

Exam Strategy

Always evaluate control recommendations through a risk lens first: identify the threat, assess the risk, then determine if controls bring it to an acceptable level. If an option sounds operationally convenient but ignores risk thresholds, it is likely a distractor.

Frequently Asked Questions

Why isn't minimizing business impact the top priority?

Impact reduction is a secondary benefit; controls must first treat the underlying risk to meet the organization's risk appetite.

How does risk appetite influence control selection?

Risk appetite sets the maximum tolerable loss, guiding managers to choose controls that bring residual risk below that defined threshold.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide