Isaca Certified in Risk and Information Systems Control CRISC Question # 413 Topic 42 Discussion
CRISC Exam Topic 42 Question 413 Discussion:
Question #: 413
Topic #: 42
An organization wants to develop a strategy to mitigate the risk associated with unethical actions by stakeholders. Which of the following should be done FIRST?
A.
Provide incentives for whistleblowers to report unethical actions
B.
Communicate sanctions and penalties for unethical actions
The first step in establishing an ethical governance culture is tocreate a clear and formal policyoutlining acceptable behavior and consequences for violations.
ISACA guidance:
“Developing and approving an enterprise code of ethics or ethical policy establishes the foundation for enforcing ethical conduct and guiding all subsequent training and enforcement activities.”
Training and enforcement follow policy creation.
Therefore,D. Create a policy regarding ethical behavioris correct.
CRISC Reference:Domain 1 – IT Risk Governance, Topic: Ethics and Governance Policies.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit