Isaca Certified in Risk and Information Systems Control CRISC Question # 206 Topic 21 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 206 Topic 21 Discussion

CRISC Exam Topic 21 Question 206 Discussion:
Question #: 206
Topic #: 21

A multinational company needs to implement a new centralized security system. The risk practitioner has identified a conflict between the organization's data-handling policy and local privacy regulations. Which of the following would be the BEST recommendation?


A.

Request a policy exception from senior management.


B.

Comply with the organizational policy.


C.

Report the noncompliance to the local regulatory agency.


D.

Request an exception from the local regulatory agency.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.