List of questions
Question 256 - CRISC discussion
An organization with a large number of applications wants to establish a security risk assessment program. Which of the following would provide the MOST useful information when determining the frequency of risk assessments?
A.
Feedback from end users
B.
Results of a benchmark analysis
C.
Recommendations from internal audit
D.
Prioritization from business owners
Your answer:
0 comments
Sorted by
Leave a comment first