ExamQuestions.com

Register
Login
Certified in Risk and Information Systems Control Exam Questions

Isaca

Certified in Risk and Information Systems Control

20 / 500

Question 20:

Which of the following is NOT true for risk management capability maturity level 1? 

Answer options:

A. There is an understanding that risk is important and needs to be managed, but it is viewed as a technical issue and the business primarily considers the downside of IT risk
B. Decisions involving risk lack credible information
C. Risk appetite and tolerance are applied only during episodic risk assessments
D. Risk management skills exist on an ad hoc basis, but are not actively developed