Isaca Certified in Risk and Information Systems Control CRISC Question # 276 Topic 28 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 276 Topic 28 Discussion

CRISC Exam Topic 28 Question 276 Discussion:
Question #: 276
Topic #: 28

An organization is considering outsourcing user administration controls tor a critical system. The potential vendor has offered to perform quarterly sett-audits of its controls instead of having annual independent audits. Which of the following should be of GREATEST concern to me risk practitioner?


A.

The controls may not be properly tested


B.

The vendor will not ensure against control failure


C.

The vendor will not achieve best practices


D.

Lack of a risk-based approach to access control


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.