Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Isaca Certified in Risk and Information Systems Control CRISC Question # 240 Topic 25 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 240 Topic 25 Discussion

CRISC Exam Topic 25 Question 240 Discussion:
Question #: 240
Topic #: 25

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?


A.

Escalate the non-cooperation to management


B.

Exclude applicable controls from the assessment.


C.

Review the supplier's contractual obligations.


D.

Request risk acceptance from the business process owner.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.