List of questions
Related questions
Question 487 - CGEIT discussion
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
A.
Organizational responsibility for IT risk management is not clearly defined.
B.
None of the members of the IT risk management team have risk management-related certifications.
C.
Only a few key risk indicators (KRIs) identified by the IT risk management team are being monitored and the rest will be on a phased schedule.
Your answer:
0 comments
Sorted by
Leave a comment first