Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified in Risk and Information Systems Control CRISC Question # 93 Topic 10 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 93 Topic 10 Discussion

CRISC Exam Topic 10 Question 93 Discussion:
Question #: 93
Topic #: 10

An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner ' s FIRST course of action?


A.

Determine whether the impact is outside the risk appetite.


B.

Request a formal acceptance of risk from senior management.


C.

Report the ineffective control for inclusion in the next audit report.


D.

Deploy a compensating control to address the identified deficiencies.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.