What is the Most Important Objective When Recommending Controls?
Which of the following is the MOST important objective when recommending controls?
Community Votes
80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding that security controls exist to mitigate risk to an acceptable threshold, often tricking candidates into prioritizing operational continuity or cost over risk reduction.
Recommending information security controls primarily aims to reduce organizational risk to an acceptable level aligned with business objectives. Community consensus and official guidance confirm that risk reduction, not cost approval or process minimization, is the paramount objective.
Option D (Minimizing the impact to business processes) is frequently chosen because candidates confuse operational resilience with risk management, overlooking that controls must first address the underlying risk exposure before optimizing business impact.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security controls function as risk treatment mechanisms designed to lower inherent vulnerabilities and threats to a manageable state. CISM frameworks mandate that management’s foremost duty is aligning security investments with the organization’s defined risk appetite. Consequently, recommending controls must prioritize achieving this acceptable risk threshold above all secondary factors.Why the Other Options Are Wrong
Option A focuses on financial approval, which remains a procedural step rather than the strategic purpose of controls. Option B addresses process alignment but fails to define the ultimate protective outcome. Option D conflates impact mitigation with risk reduction, treating symptoms rather than the root cause of potential loss.Community Comment Notes
Top-voted discussions emphasize that risk appetite establishes the boundary for acceptable exposure, making risk reduction the logical endpoint. Contributors clarify that while minimizing business disruption matters, it operates strictly within the limits set by acceptable risk levels. As noted in high-ranking comments, the goal is actively reducing risk to that predefined threshold, validating option C.Official Reference
Exam Strategy
Always evaluate control recommendations through a risk lens first: identify the threat, assess the risk, then determine if controls bring it to an acceptable level. If an option sounds operationally convenient but ignores risk thresholds, it is likely a distractor.
Frequently Asked Questions
Why isn't minimizing business impact the top priority?
Impact reduction is a secondary benefit; controls must first treat the underlying risk to meet the organization's risk appetite.
How does risk appetite influence control selection?
Risk appetite sets the maximum tolerable loss, guiding managers to choose controls that bring residual risk below that defined threshold.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →