ExamGecko
Question list
Search
Search

Related questions











Question 225 - CRISC discussion

Report
Export

What should a risk practitioner do FIRST upon learning a risk treatment owner has implemented a different control than what was specified in the IT risk action plan?

A.
Seek approval from the control owner.
Answers
A.
Seek approval from the control owner.
B.
Update the action plan in the risk register.
Answers
B.
Update the action plan in the risk register.
C.
Reassess the risk level associated with the new control.
Answers
C.
Reassess the risk level associated with the new control.
D.
Validate that the control has an established testing method.
Answers
D.
Validate that the control has an established testing method.
Suggested answer: C
asked 18/09/2024
Luis Raul Juarez Cosio
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first