Isaca Certified in Risk and Information Systems Control CRISC Question # 287 Topic 29 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 287 Topic 29 Discussion

CRISC Exam Topic 29 Question 287 Discussion:
Question #: 287
Topic #: 29

An organization with a large number of applications wants to establish a security risk assessment program. Which of the following would provide the MOST useful information when determining the frequency of risk assessments?


A.

Feedback from end users


B.

Results of a benchmark analysis


C.

Recommendations from internal audit


D.

Prioritization from business owners


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.