List of questions
Question 1015 - CRISC discussion
During a risk assessment, a key external technology supplier refuses to provide control design and effectiveness information, citing confidentiality concerns. What should the risk practitioner do NEXT?
A.
Escalate the non-cooperation to management
B.
Exclude applicable controls from the assessment.
C.
Review the supplier's contractual obligations.
D.
Request risk acceptance from the business process owner.
Your answer:
0 comments
Sorted by
Leave a comment first