Isaca Certified Information Security Manager CISM Question # 18 Topic 2 Discussion

Isaca Certified Information Security Manager CISM Question # 18 Topic 2 Discussion

CISM Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?


A.

Risk levels may be elevated beyond acceptable limits.


B.

Security audits may report more high-risk findings.


C.

The compensating controls may not be cost efficient.


D.

Noncompliance with industry best practices may result.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.