Isaca Certified in Risk and Information Systems Control CRISC Question # 433 Topic 44 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 433 Topic 44 Discussion

CRISC Exam Topic 44 Question 433 Discussion:
Question #: 433
Topic #: 44

Which of the following should be the FIRST step when a company is made aware of new regulatory requirements impacting IT?


A.

Perform a gap analysis.


B.

Prioritize impact to the business units.


C.

Perform a risk assessment.


D.

Review the risk tolerance and appetite.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.