List of questions
Question 1136 - CRISC discussion
During a risk assessment, a risk practitioner learns that an IT risk factor is adequately mitigated by compensating controls in an associated business process. Which of the following would enable the MOST effective management of the residual risk?
A.
Schedule periodic reviews of the compensating controls' effectiveness.
B.
Report the use of compensating controls to senior management.
C.
Recommend additional IT controls to further reduce residual risk.
D.
Request that ownership of the compensating controls is reassigned to IT
Your answer:
0 comments
Sorted by
Leave a comment first