List of questions
Related questions
Question 481 - CRISC discussion
An organization is unable to implement a multi-factor authentication requirement until the next fiscal year due to budget constraints. Consequently, a policy exception must be submitted. Which of the following is MOST important to include in the analysis of the exception?
A.
Sections of the policy that may justify not implementing the requirement
B.
Risk associated with the inability to implement the requirement
C.
Budget justification to implement the new requirement during the current year
D.
Industry best practices with respect to implementation of the proposed control
Your answer:
0 comments
Sorted by
Leave a comment first