Isaca Certified in Risk and Information Systems Control CRISC Question # 237 Topic 24 Discussion
CRISC Exam Topic 24 Question 237 Discussion:
Question #: 237
Topic #: 24
A risk practitioner has been asked to mark an identified control deficiency as remediated, despite concerns that the risk level is still too high. Which of the following is the BEST way to address this concern?
A.
Prepare a risk acceptance proposal for senior management's consideration.
B.
Review the organization's risk appetite and tolerance.
C.
Assess the residual risk against the organization's risk appetite.
D.
Recommend implementation of additional compensating controls.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit