Question 379:
A risk assessment should be conducted:
Answer options:
A. once a year for each business process and subprocess. B. every three to six months for critical business processes. C. by external parties to maintain objectivity. D. annually or whenever there is a significant change.