Isaca Certified in Risk and Information Systems Control CRISC Question # 500 Topic 51 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 500 Topic 51 Discussion

CRISC Exam Topic 51 Question 500 Discussion:
Question #: 500
Topic #: 51

Business areas within an organization have engaged various cloud service providers directly without assistance from the IT department. What should the risk practitioner do?


A.

Recommend the IT department remove access to the cloud services.


B.

Engage with the business area managers to review controls applied.


C.

Escalate to the risk committee.


D.

Recommend a risk assessment be conducted.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.