Isaca Certified in Risk and Information Systems Control CRISC Question # 426 Topic 43 Discussion
CRISC Exam Topic 43 Question 426 Discussion:
Question #: 426
Topic #: 43
An organization plans to provide specific cloud security training for the IT team to help manage risks associated with cloud technology. This response is considered risk:
Risk mitigation involves implementing measures to reduce either the likelihood or impact of a risk.
By providing targeted training, the organization increases staff capability, thereby reducing the likelihood of misconfigurations or compliance errors in cloud usage.
ISACA defines mitigation as:
“Implementing controls or training to reduce exposure to risk within acceptable levels.”
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit