List of questions
Related questions
Question 609 - CRISC discussion
An organization has implemented a preventive control to lock user accounts after three unsuccessful login attempts. This practice has been proven to be unproductive, and a change in the control threshold value has been recommended. Who should authorize changing this threshold?
A.
Risk owner
B.
IT security manager
C.
IT system owner
D.
Control owner
Your answer:
0 comments
Sorted by
Leave a comment first