ExamGecko
Question list
Search
Search

Related questions











Question 404 - CISA discussion

Report
Export

During an audit of an organization's risk management practices, an IS auditor finds several documented IT risk acceptances have not been renewed in a timely manner after the assigned expiration date When assessing the seventy of this finding, which mitigating factor would MOST significantly minimize the associated impact?

A.
There are documented compensating controls over the business processes.
Answers
A.
There are documented compensating controls over the business processes.
B.
The risk acceptances were previously reviewed and approved by appropriate senior management
Answers
B.
The risk acceptances were previously reviewed and approved by appropriate senior management
C.
The business environment has not significantly changed since the risk acceptances were approved.
Answers
C.
The business environment has not significantly changed since the risk acceptances were approved.
D.
The risk acceptances with issues reflect a small percentage of the total population
Answers
D.
The risk acceptances with issues reflect a small percentage of the total population
Suggested answer: A

Explanation:

The mitigating factor that would most significantly minimize the impact of not renewing IT risk acceptances in a timely manner is having documented compensating controls over the business processes. Compensating controls are alternative controls that reduce or eliminate the risk when the primary control is not feasible or cost-effective. The other factors, such as previous approval by senior management, unchanged business environment, and small percentage of issues, do not mitigate the risk as effectively as compensating controls.Reference:ISACA CISA Review Manual 27th Edition Chapter 1

asked 18/09/2024
Carlo Hearne
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first