ExamGecko
Question list
Search
Search

Related questions











Question 1015 - CRISC discussion

Report
Export

During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?

A.
Escalate the non-cooperation to management
Answers
A.
Escalate the non-cooperation to management
B.
Exclude applicable controls from the assessment.
Answers
B.
Exclude applicable controls from the assessment.
C.
Review the supplier's contractual obligations.
Answers
C.
Review the supplier's contractual obligations.
D.
Request risk acceptance from the business process owner.
Answers
D.
Request risk acceptance from the business process owner.
Suggested answer: C
asked 18/09/2024
Jana Rutrich
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first