Certified Information Security Manager (CISM)Information Security ProgramMedium

A CISO is tasked with integrating information security into the organization's enterprise risk management (ERM) framework. The primary goal is to ensure that security risks are evaluated and managed consistently with other enterprise-level risks. What is the MOST effective approach for the CISO to achieve this integration?

  1. AMandate that all business units conduct annual security risk assessments independently.
  2. BAdopt a common risk taxonomy and methodology for assessing and reporting risks across the enterprise.
  3. CDevelop a separate, highly detailed information security risk register for the CISO's team.
  4. DImplement new security technologies that automatically mitigate a wide range of cyber threats.
Show answer & explanation

Correct answer: B. Adopt a common risk taxonomy and methodology for assessing and reporting risks across the enterprise.

For consistent evaluation and management of security risks within the broader ERM framework, a common language (taxonomy) and process (methodology) are essential. This ensures security risks can be compared and prioritized alongside other business risks.

Why the other options are wrong

  • A. Independent assessments might lead to inconsistent results and make aggregation into a unified ERM framework challenging.
  • C. A separate risk register, while useful for the security team, would hinder integration into a unified ERM framework and make cross-enterprise comparison difficult.
  • D. New security technologies are operational controls, not a strategic approach for integrating risk management processes into an ERM framework.

ERM Integration

The process of embedding information security risk management into the broader Enterprise Risk Management (ERM) framework to ensure consistent identification, assessment, and treatment of security risks alongside other organizational risks.

  • Achieves a holistic view of risk.
  • Requires common language and methodology.
  • Facilitates risk prioritization and resource allocation.

Memory trick: To make security risks fit the enterprise puzzle, you need a common language and a shared rulebook.

More Information Security Program questions