Isaca Certified in Risk and Information Systems Control CRISC Question # 367 Topic 37 Discussion
CRISC Exam Topic 37 Question 367 Discussion:
Question #: 367
Topic #: 37
During the control evaluation phase of a risk assessment, it is noted that multiple controls are ineffective. Which of the following should be the risk practitioner ' s FIRST course of action?
A.
Compare the residual risk to the current risk appetite.
B.
Recommend risk remediation of the ineffective controls.
C.
Implement key control indicators (KCIs).
D.
Escalate the control failures to senior management.
The first step is to assess whether the ineffective controls result in residual risk exceeding the risk appetite. This establishes the urgency and priority of remediation efforts and ensures alignment with enterprise risk thresholds, reflecting principles ofRisk Assessment and Prioritization.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit