Isaca Certified in Risk and Information Systems Control CRISC Question # 32 Topic 4 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 32 Topic 4 Discussion

CRISC Exam Topic 4 Question 32 Discussion:
Question #: 32
Topic #: 4

What should a risk practitioner do FIRST upon learning a risk treatment owner has implemented a different control than what was specified in the IT risk action plan?


A.

Seek approval from the control owner.


B.

Update the action plan in the risk register.


C.

Reassess the risk level associated with the new control.


D.

Validate that the control has an established testing method.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.