Isaca Certified Information Security Manager CISM Question # 80 Topic 9 Discussion

Isaca Certified Information Security Manager CISM Question # 80 Topic 9 Discussion

CISM Exam Topic 9 Question 80 Discussion:
Question #: 80
Topic #: 9

Which of the following is the BEST approach for governing noncompliance with security requirements?


A.

Base mandatory review and exception approvals on residual risk,


B.

Require users to acknowledge the acceptable use policy.


C.

Require the steering committee to review exception requests.


D.

Base mandatory review and exception approvals on inherent risk.


Get Premium CISM Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.