Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified Information Security Manager CISM Question # 308 Topic 31 Discussion

Isaca Certified Information Security Manager CISM Question # 308 Topic 31 Discussion

CISM Exam Topic 31 Question 308 Discussion:
Question #: 308
Topic #: 31

Which of the following is the BEST approach for governing noncompliance with security requirements?


A.

Base mandatory review and exception approvals on residual risk,


B.

Require users to acknowledge the acceptable use policy.


C.

Require the steering committee to review exception requests.


D.

Base mandatory review and exception approvals on inherent risk.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.