List of questions
Related questions
Question 31 - CISM discussion
An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?
A.
Risk levels may be elevated beyond acceptable limits.
B.
Security audits may report more high-risk findings.
C.
The compensating controls may not be cost efficient.
D.
Noncompliance with industry best practices may result.
Your answer:
0 comments
Sorted by
Leave a comment first