Isaca Certified in the Governance of Enterprise IT Exam CGEIT Question # 28 Topic 3 Discussion

Isaca Certified in the Governance of Enterprise IT Exam CGEIT Question # 28 Topic 3 Discussion

CGEIT Exam Topic 3 Question 28 Discussion:
Question #: 28
Topic #: 3

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.


A.

benchmark policy against industry best practice.


Get Premium CGEIT Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.