Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Isaca Certified in Risk and Information Systems Control CRISC Question # 208 Topic 21 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 208 Topic 21 Discussion

CRISC Exam Topic 21 Question 208 Discussion:
Question #: 208
Topic #: 21

Which of the following should be the FIRST step when a company is made aware of new regulatory requirements impacting IT?


A.

Perform a gap analysis.


B.

Prioritize impact to the business units.


C.

Perform a risk assessment.


D.

Review the risk tolerance and appetite.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.