ExamGecko
Question list
Search
Search

Question 282 - CISM discussion

Report
Export

Which of the following is the BEST course of action if the business activity residual risk is lower than the acceptable risk level?

A.
Monitor the effectiveness of controls
Answers
A.
Monitor the effectiveness of controls
B.
Update the risk assessment framework
Answers
B.
Update the risk assessment framework
C.
Review the inherent risk level
Answers
C.
Review the inherent risk level
D.
Review the risk probability and impact
Answers
D.
Review the risk probability and impact
Suggested answer: A

Explanation:

If the residual risk of the business activity is lower than the acceptable risk level, it means that the existing controls are effectively mitigating the identified risks. In this case, the best course of action is to monitor the effectiveness of the controls and ensure they remain effective. The information security manager should review and test the controls periodically to ensure that they continue to provide adequate protection. It is also essential to update the risk assessment framework to reflect changes in the business environment or risk landscape.

asked 01/10/2024
Vojtech Danek
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first