List of questions
Question 152 - CRISC discussion
When reviewing management's IT control self-assessments, a risk practitioner noted an ineffective control that links to several low residual risk scenarios. What should be the NEXT course of action?
A.
Assess management's risk tolerance.
B.
Recommend management accept the low risk scenarios.
C.
Propose mitigating controls
D.
Re-evaluate the risk scenarios associated with the control
Your answer:
0 comments
Sorted by
Leave a comment first