Isaca Certified in Risk and Information Systems Control CRISC Question # 216 Topic 22 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 216 Topic 22 Discussion

CRISC Exam Topic 22 Question 216 Discussion:
Question #: 216
Topic #: 22

Which of the following should be of GREATEST concern to a risk practitioner when determining the effectiveness of IT controls?


A.

Configuration updates do not follow formal change control.


B.

Operational staff perform control self-assessments.


C.

Controls are selected without a formal cost-benefit


D.

analysis-Management reviews security policies once every two years.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.