StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 2: Information security risk management

Risk registers, key risk indicators and risk monitoring

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A risk register is the central record of an organization's identified risks. It lets the organization see its exposure in one place, track treatment and report consistently. Without one, risks live in scattered spreadsheets, audit reports and people's memories, and leadership cannot tell whether exposure is rising or falling. The register is also the evidence that risk management actually happens, which auditors and regulators often ask to see. Each entry typically includes a unique ID, the risk scenario, the risk owner, inherent likelihood and impact, existing controls and their owners, residual rating, the chosen response, treatment actions with owners and due dates, status, linked KRIs and the next review date. A simplified entry might look like this:

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan