CRISC Exam Question 676

If preventive controls cannot be implemented due to technology limitations, which of the following should be done FIRST to reduce risk?
  • CRISC Exam Question 677

    An organization has outsourced a critical process involving highly regulated data to a third party with servers located in a foreign country. Who is accountable for the confidentiality of this data?
  • CRISC Exam Question 678

    Which of the following is the GREATEST benefit when enterprise risk management (ERM) provides oversight of IT risk management?
  • CRISC Exam Question 679

    A risk practitioner has observed that risk owners have approved a high number of exceptions to the information security policy. Which of the following should be the risk practitioner's GREATEST concern?
  • CRISC Exam Question 680

    Which of the following is the GREATEST benefit of having a mature enterprise architecture (EA) in place?