List of questions
Related questions
Question 550 - CISM discussion
Who has the PRIMARY authority to decide if additional risk treatments are required to mitigate an identified risk?
A.
Information security manager
B.
IT risk manager
C.
Internal auditor
D.
Risk owner
Your answer:
0 comments
Sorted by
Leave a comment first