List of questions
Question 1167 - CRISC discussion
One of an organization's key IT systems cannot be patched because the patches interfere with critical business application functionalities. Which of the following would be the risk practitioner's BEST recommendation?
A.
Additional mitigating controls should be identified.
B.
The system should not be used until the application is changed
C.
The organization's IT risk appetite should be adjusted.
D.
The associated IT risk should be accepted by management.
Your answer:
0 comments
Sorted by
Leave a comment first