Isaca Certified Information Systems Auditor CISA Question # 134 Topic 14 Discussion

Isaca Certified Information Systems Auditor CISA Question # 134 Topic 14 Discussion

CISA Exam Topic 14 Question 134 Discussion:
Question #: 134
Topic #: 14

During an audit of an organization's risk management practices, an IS auditor finds several documented IT risk acceptances have not been renewed in a timely manner after the assigned expiration date When assessing the seventy of this finding, which mitigating factor would MOST significantly minimize the associated impact?


A.

There are documented compensating controls over the business processes.


B.

The risk acceptances were previously reviewed and approved by appropriate senior management


C.

The business environment has not significantly changed since the risk acceptances were approved.


D.

The risk acceptances with issues reflect a small percentage of the total population


Get Premium CISA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.