Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 18 Topic 2 Discussion

Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 18 Topic 2 Discussion

CTPRP Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

Which statement BEST describes the use of risk based decisioning in prioritizing gaps identified at a critical vendor when defining the corrective action plan?


A.

The assessor determined that gaps should be analyzed, documented, reviewed for compensating controls, and submitted to the business owner to approve risk treatment plan


B.

The assessor decided that the critical gaps should be discussed in the closing meeting so that the vendor can begin to implement corrective actions immediately


C.

The assessor concluded that all gaps should be logged and treated as high severity findings since the assessment was performed on a critical vendor


D.

The assessor determined that all gaps should be logged and communicated that if the gaps were corrected immediately they would not need to be included in the findings report


Get Premium CTPRP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.