List of questions
Related questions
Question 433 - CRISC discussion
A risk practitioner is reviewing a vendor contract and finds there is no clause to control privileged access to the organization's systems by vendor employees. Which of the following is the risk practitioner's BEST course of action?
A.
Contact the control owner to determine if a gap in controls exists.
B.
Add this concern to the risk register and highlight it for management review.
C.
Report this concern to the contracts department for further action.
D.
Document this concern as a threat and conduct an impact analysis.
Your answer:
0 comments
Sorted by
Leave a comment first