List of questions
Related questions
Question 410 - CRISC discussion
A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner's GREATEST concern?
A.
Security policies are being reviewed infrequently.
B.
Controls are not operating efficiently.
C.
Vulnerabilities are not being mitigated
D.
Aggregate risk is approaching the tolerance threshold
Your answer:
0 comments
Sorted by
Leave a comment first