The correct answer is D . In CRISC, the purpose of reviewing control assessment reports is to determine whether controls are effective in reducing risk exposure to an acceptable level. The uploaded CRISC notes state that the most important criterion when reviewing information security controls is ensuring that the controls are effectively addressing risk. They also state that effective control implementation primarily correlates with a decrease in residual risk.
A is more audit/compliance focused. B may happen after exceptions are identified, but it is not the main reason for reviewing reports. C focuses on efficiency, while CRISC prioritizes risk reduction and control effectiveness.
===========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit