List of questions
Related questions
Question 896 - CISA discussion
Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management is adequately balancing the needs of the business with the need to manage risk?
A.
A communication plan exists for informing parties impacted by the risk.
B.
Potential impact and likelihood are adequately documented.
C.
Identified risk is reported into the organization's risk committee.
D.
Established criteria exist for accepting and approving risk.
Your answer:
0 comments
Sorted by
Leave a comment first