ExamGecko
Question list
Search
Search

Related questions











Question 433 - CRISC discussion

Report
Export

A risk practitioner is reviewing a vendor contract and finds there is no clause to control privileged access to the organization's systems by vendor employees. Which of the following is the risk practitioner's BEST course of action?

A.
Contact the control owner to determine if a gap in controls exists.
Answers
A.
Contact the control owner to determine if a gap in controls exists.
B.
Add this concern to the risk register and highlight it for management review.
Answers
B.
Add this concern to the risk register and highlight it for management review.
C.
Report this concern to the contracts department for further action.
Answers
C.
Report this concern to the contracts department for further action.
D.
Document this concern as a threat and conduct an impact analysis.
Answers
D.
Document this concern as a threat and conduct an impact analysis.
Suggested answer: D
asked 18/09/2024
Trey Contello
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first