New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Isaca Certified in Risk and Information Systems Control CRISC Question # 73 Topic 8 Discussion

Isaca Certified in Risk and Information Systems Control CRISC Question # 73 Topic 8 Discussion

CRISC Exam Topic 8 Question 73 Discussion:
Question #: 73
Topic #: 8

An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner's FIRST course of action?


A.

Determine whether the impact is outside the risk appetite.


B.

Request a formal acceptance of risk from senior management.


C.

Report the ineffective control for inclusion in the next audit report.


D.

Deploy a compensating control to address the identified deficiencies.


Get Premium CRISC Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.