StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 2: Information security risk management

Risk assessment methods: qualitative, quantitative and semi-quantitative

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Risk assessment identifies risks, analyzes their likelihood and impact, and evaluates them against the organization's criteria so they can be prioritized. The purpose is to choose and fund controls in proportion to risk. There are three broad ways to analyze risk: qualitative, quantitative and semi-quantitative. The CISM exam expects you to know how each works, its strengths and weaknesses, and when each fits. Whatever the method, a good assessment follows the same steps: define scope and criteria; identify assets and their value, threats, vulnerabilities and existing controls; estimate likelihood and impact; evaluate the results against appetite; and record them with owners. It is repeated periodically and whenever significant change occurs.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan