Domain 2 (20% weight) covers identifying, analyzing, and treating information security risk within the broader context of enterprise risk management. It overlaps conceptually with CISSP Domain 1's risk content but is tested from a program-management lens: less "what is SLE" and more "how does the security risk function integrate with and report to enterprise risk management."
Risk appetite vs. risk tolerance
Risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives (strategic, board-set). Risk tolerance is the acceptable variation around that appetite for a specific risk or metric (operational, more granular).
Risk register
The living inventory of identified risks, their assessed likelihood/impact, ownership, and treatment status: a core artifact CISM expects a security manager to maintain and report from, not just a theoretical concept.
Risk treatment options
The same four options as CISSP (avoid, mitigate, transfer, accept), but CISM emphasizes the business decision-making process and required sign-off/ownership behind each choice, not just defining the terms.
Emerging risk and threat landscape monitoring
CISM expects an ongoing, proactive process for identifying new and evolving risks (e.g., new technology adoption, threat intelligence, regulatory change), not just periodic point-in-time risk assessments.
Risk appetite vs. risk tolerance (again)
Appetite is the board-level strategic "how much risk overall." Tolerance is the operational-level "how much variance around a specific target is acceptable." Exam questions often describe a scenario and ask which term applies.
Inherent risk vs. residual risk
Inherent risk is the risk level before any controls are applied. Residual risk is what remains after controls are in place: the number that should be compared against risk appetite when deciding if further treatment is needed.
Practice D2 questions with instant feedback, free to start, no card required.
Start Free