StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 2: Information security risk management

Risk scenarios, likelihood and impact

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A risk scenario is a short, realistic description of how a loss could happen. It connects the pieces of risk into a story that business managers can understand: a threat (who or what), acting through a vulnerability (how), against an asset (what is affected), with a business consequence (why it matters). 'A criminal group phishes a finance employee, uses the stolen credentials to change a supplier's bank details, and diverts a 250,000 payment' is a scenario. 'Phishing' by itself is not; it is only a threat technique. Scenarios are the bridge between technical findings and business decisions.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan