CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 315: CISA: Certified Information Systems Auditor

During an audit of an organization's risk management practices, an IS auditor finds several documented IT risk acceptances have not been renewed in a timely manner after the assigned expiration date. When assessing the severity of this finding, which mitigating factor would MOST significantly minimize the associated i…

Nội dung câu hỏi

During an audit of an organization's risk management practices, an IS auditor finds several documented IT risk acceptances have not been renewed in a timely manner after the assigned expiration date. When assessing the severity of this finding, which mitigating factor would MOST significantly minimize the associated impact?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. There are documented compensating controls over the business processes.
  2. B. The risk acceptances with issues reflect a small percentage of the total population.
  3. C. The business environment has not significantly changed since the risk acceptances were approved. — đáp án hiện tại
  4. D. The risk acceptances were previously reviewed and approved by appropriate senior management.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề