Last updated:
CISSP decision trap
Who should make a CISSP risk treatment decision?
Direct answer
Accountable business risk owners choose acceptance, avoidance, transfer, or mitigation within delegated authority; security professionals assess, advise, design, and monitor controls. Separate recommendation and implementation from the authority to accept residual business exposure. First, identify the named risk owner, delegated thresholds, business impact, and residual risk, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
risk treatment decisions: a practical decision framework
| Check | How to use it |
|---|---|
| Objective | Separate recommendation and implementation from the authority to accept residual business exposure. |
| First move | identify the named risk owner, delegated thresholds, business impact, and residual risk |
| Common trap | Allowing the security manager, assessor, or control operator to accept risk merely because they understand it technically. |
risk treatment decisions in practice
A security architect proposes compensating controls for a legacy service, but material residual risk remains above the team’s delegated threshold.
The architect documents options and residual exposure; the accountable business authority decides treatment or escalates according to governance.
What matters most for risk treatment decisions
Separate recommendation and implementation from the authority to accept residual business exposure.
Accountable business risk owners choose acceptance, avoidance, transfer, or mitigation within delegated authority; security professionals assess, advise, design, and monitor controls. The useful question is not whether an isolated fact looks familiar, but whether you can apply it under the actor, authority, objective, qualifier, and constraints in the scenario.
How to work on risk treatment decisions
identify the named risk owner, delegated thresholds, business impact, and residual risk
For risk treatment decisions, state the rule before opening the rationale. Compare the authority, timing, scope, and objective assumed by every option, then record the exact fact that makes the tempting choice weaker.
- Name the actor and the authority that actor holds.
- Underline the qualifier and the required business or security outcome.
- Check sequence, scope, constraints, and residual risk before choosing.
The mistake that distorts risk treatment decisions
Allowing the security manager, assessor, or control operator to accept risk merely because they understand it technically.
This error can survive repeated question practice when review stops at the correct letter. Rework the item until you can state the transferable rule without quoting the stem.
How to know the risk treatment decisions rule transfers
The architect documents options and residual exposure; the accountable business authority decides treatment or escalates according to governance.
Retest risk treatment decisions with a changed actor, qualifier, constraint, or domain context. Keep the result only when the same reasoning survives unfamiliar wording and you can explain what evidence would make another option stronger.
- Use an unfamiliar scenario rather than a repeated item.
- Record confidence before opening the explanation.
- Name the evidence that would reverse the decision.
Sources and fact check
Source checked: 2026-08-24
- CertArc is an independent exam-preparation platform and is not affiliated with or endorsed by ISC2.
- CertArc uses original practice questions, not live or recalled exam items, and does not reproduce the CISSP CAT algorithm.
- Practice performance is study evidence, not a pass prediction or guarantee.
Frequently asked questions
Who should make a CISSP risk treatment decision?
Accountable business risk owners choose acceptance, avoidance, transfer, or mitigation within delegated authority; security professionals assess, advise, design, and monitor controls. Separate recommendation and implementation from the authority to accept residual business exposure. First, identify the named risk owner, delegated thresholds, business impact, and residual risk, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
Which clue matters most in risk treatment decisions questions?
Separate recommendation and implementation from the authority to accept residual business exposure. The decisive clue is usually the fact that changes authority, sequence, scope, or the required outcome.
Why does the tempting answer lose in risk treatment decisions?
Allowing the security manager, assessor, or control operator to accept risk merely because they understand it technically. Compare the tempting option with the stem's actor, timing, authority, and objective before reviewing the correct letter.
How should I practise risk treatment decisions without memorizing?
Identify the named risk owner, delegated thresholds, business impact, and residual risk Then change one material fact and explain whether the answer should change.
Does one correct risk treatment decisions answer prove mastery?
No. Mastery requires the rule to survive unfamiliar wording, different actors, cross-domain context, and a strong distractor.