List of questions
Related questions
Question 582 - CRISC discussion
A service provider is managing a client's servers. During an audit of the service, a noncompliant control is discovered that will not be resolved before the next audit because the client cannot afford the downtime required to correct the issue. The service provider's MOST appropriate action would be to:
A.
develop a risk remediation plan overriding the client's decision
B.
make a note for this item in the next audit explaining the situation
C.
insist that the remediation occur for the benefit of other customers
D.
ask the client to document the formal risk acceptance for the provider
Your answer:
0 comments
Sorted by
Leave a comment first