List of questions
Question 365 - CRISC discussion
Which of the following should be of GREATEST concern to a risk practitioner when determining the effectiveness of IT controls?
A.
Configuration updates do not follow formal change control.
B.
Operational staff perform control self-assessments.
C.
Controls are selected without a formal cost-benefit
D.
analysis-Management reviews security policies once every two years.
Your answer:
0 comments
Sorted by
Leave a comment first