List of questions
Related questions
Question 318 - CISM discussion
A risk owner has accepted a large amount of risk due to the high cost of controls. Which of the following should be the information security manager's PRIMARY focus in this situation?
A.
Establishing a strong ongoing risk monitoring process
B.
Presenting the risk profile for approval by the risk owner
C.
Conducting an independent review of risk responses
D.
Updating the information security standards to include the accepted risk
Your answer:
0 comments
Sorted by
Leave a comment first