ExamQuestions.com

Register
Login
Certified in Risk and Information Systems Control Exam Questions

Isaca

Certified in Risk and Information Systems Control

447 / 500

Question 447:

An assessment of information security controls has identified ineffective controls. Which of the following should be the risk practitioner`s FIRST course of action? 

Answer options:

A. Deploy a compensating control to address the identified deficiencies
B. Report the ineffective control for inclusion in the next audit report
C. Determine if the impact is outside the risk appetite
D. Request a formal acceptance of risk from senior management