Isaca Certified in Risk and Information Systems Control CRISC Question # 132 Topic 14 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 132 Topic 14 Discussion

CRISC Exam Topic 14 Question 132 Discussion:
Question #: 132
Topic #: 14

During a risk assessment, a risk practitioner learns that an IT risk factor is adequately mitigated by compensating controls in an associated business process. Which of the following would enable the MOST effective management of the residual risk?


A.

Schedule periodic reviews of the compensating controls' effectiveness.


B.

Report the use of compensating controls to senior management.


C.

Recommend additional IT controls to further reduce residual risk.


D.

Request that ownership of the compensating controls is reassigned to IT


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.