CRISC Exam Question 516

Of the following, who should be responsible for determining the inherent risk rating of an application?
  • CRISC Exam Question 517

    Which of the following should be the MAIN consideration when validating an organization's risk appetite?
  • CRISC Exam Question 518

    A large organization recently restructured the IT department and has decided to outsource certain functions.
    What action should the control owners in the IT department take?
  • CRISC Exam Question 519

    Which of the following is the BEST course of action to help reduce the probability of an incident recurring?
  • CRISC Exam Question 520

    An IT department has organized training sessions to improve user awareness of organizational information security policies. Which of the following is the BEST key performance indicator (KPI) to reflect effectiveness of the training?