CRISC Exam Question 291

Which of the following is MOST important when conducting a post-implementation review as part of the system development life cycle (SDLC)?
  • CRISC Exam Question 292

    A peer review of a risk assessment finds that a relevant threat community was not included. Mitigation of the risk will require substantial changes to a software application. Which of the following is the BEST course of action?
  • CRISC Exam Question 293

    A key risk indicator (KRI) threshold has reached the alert level, indicating data leakage incidents are highly probable. What should be the risk practitioner's FIRST course of action?
  • CRISC Exam Question 294

    A new policy has been published to forbid copying of data onto removable media. Which type of control has been implemented?
  • CRISC Exam Question 295

    A control process has been implemented in response to a new regulatory requirement, but has significantly reduced productivity. Which of the following is the BEST way to resolve this concern?