List of questions
Question 225 - CRISC discussion
What should a risk practitioner do FIRST upon learning a risk treatment owner has implemented a different control than what was specified in the IT risk action plan?
A.
Seek approval from the control owner.
B.
Update the action plan in the risk register.
C.
Reassess the risk level associated with the new control.
D.
Validate that the control has an established testing method.
Your answer:
0 comments
Sorted by
Leave a comment first