List of questions
Related questions
Question 1289 - CISSP discussion
What action should be taken by a business line that is unwilling to accept the residual risk in a system after implementing compensating controls?
A.
Notify the audit committee of the situation.
B.
Purchase insurance to cover the residual risk.
C.
Implement operational safeguards.
D.
Find another business line willing to accept the residual risk.
Your answer:
0 comments
Sorted by
Leave a comment first