List of questions
Related questions
Question 984 - CISA discussion
An IS auditor is reviewing enterprise governance and finds there is no defined organizational structure for technology risk governance. Which of the following is the GREATEST concern with this lack of structure?
A.
Software developers may adopt inappropriate technology.
B.
Project managers may accept technology risks exceeding the organization's risk appetite.
C.
Key decision-making entities for technology risk have not been identified
D.
There is no clear approval entity for organizational security standards.
Your answer:
0 comments
Sorted by
Leave a comment first