ExamQuestions.com

Register
Login
Certified Information Security Manager Exam Questions

Isaca

Certified Information Security Manager

293 / 500

Question 293:

An information security manager has completed a risk assessment and has determined the residual risk. Which of the following should be the NEXT step? 

Answer options:

A. Conduct an evaluation of controls
B. Determine if the risk is within the risk appetite
C. Implement countermeasures to mitigate risk
D. Classify all identified risks