ExamGecko
Question list
Search
Search

Question 90 - CISM discussion

Report
Export

Which of the following is the BEST approach for governing noncompliance with security requirements?

A.
Base mandatory review and exception approvals on residual risk,
Answers
A.
Base mandatory review and exception approvals on residual risk,
B.
Require users to acknowledge the acceptable use policy.
Answers
B.
Require users to acknowledge the acceptable use policy.
C.
Require the steering committee to review exception requests.
Answers
C.
Require the steering committee to review exception requests.
D.
Base mandatory review and exception approvals on inherent risk.
Answers
D.
Base mandatory review and exception approvals on inherent risk.
Suggested answer: A

Explanation:

= Residual risk is the risk that remains after applying security controls. It reflects the actual exposure of the organization to noncompliance issues. Therefore, basing mandatory review and exception approvals on residual risk is the best approach for governing noncompliance with security requirements. It ensures that the organization is aware of the potential impact and likelihood of noncompliance and can make informed decisions about accepting, mitigating, or transferring the risk.Reference= CISM Review Manual 15th Edition, page 78.

asked 01/10/2024
EDUARDO VIDAL
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first