StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 1: Information security governance

Risk appetite, risk tolerance and aligning security with business objectives

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Risk appetite is the amount and type of risk an organization is willing to pursue or accept to achieve its objectives. It is set by the board and senior management, not by the security team. A bank might have a very low appetite for fraud losses but a moderate appetite for risk in launching new digital products. Appetite statements can be qualitative ('we will not accept risks that could cause a regulatory sanction') or quantitative ('no more than a defined amount of expected annual loss from cyber events'). Appetite is not the same everywhere in the business: it is usually stated per category of risk, such as financial, regulatory, operational and reputational.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan