Isaca Certified in Risk and Information Systems Control CRISC Question # 439 Topic 44 Discussion
CRISC Exam Topic 44 Question 439 Discussion:
Question #: 439
Topic #: 44
Following a business continuity planning exercise, an organization decides to accept an identified risk associated with a critical business system. Which of the following should be done next?
A.
Document the decision-making process and considerations used
B.
Perform a business impact analysis (BIA) to assess the impact of the risk
C.
Develop a disaster recovery plan (DRP) and business continuity plan (BCP) to ensure resiliency
When a risk is accepted, it must be documented in the risk register—including rationale, alternatives evaluated, decision-makers, and contextual factors. This aligns with governance and audit accountability requirements in ISACA guidance.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit