Isaca Certified in Risk and Information Systems Control CRISC Question # 392 Topic 40 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 392 Topic 40 Discussion

CRISC Exam Topic 40 Question 392 Discussion:
Question #: 392
Topic #: 40

A risk practitioner is reviewing a vendor contract and finds there is no clause to control privileged access to the organization's systems by vendor employees. Which of the following is the risk practitioner's BEST course of action?


A.

Contact the control owner to determine if a gap in controls exists.


B.

Add this concern to the risk register and highlight it for management review.


C.

Report this concern to the contracts department for further action.


D.

Document this concern as a threat and conduct an impact analysis.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.