CRISC Exam Question 111
An IT operations team implements disaster recovery controls based on decisions from application owners regarding the level of resiliency needed. Who is the risk owner in this scenario?
CRISC Exam Question 112
Which of the following is the MAIN purpose of monitoring risk?
CRISC Exam Question 113
Which of the following is the PRIMARY objective for automating controls?
CRISC Exam Question 114
What is the BEST recommendation to reduce the risk associated with potential system compromise when a vendor stops releasing security patches and updates for a business-critical legacy system?
CRISC Exam Question 115
During a risk assessment, a risk practitioner learns that an IT risk factor is adequately mitigated by compensating controls in an associated business process. Which of the following would enable the MOST effective management of the residual risk?
