CRISC Exam Question 116
Who is accountable for the process when an IT stakeholder operates a key control to address a risk scenario?
CRISC Exam Question 117
Which of the following should be determined FIRST when a new security vulnerability is made public?
CRISC Exam Question 118
An organization uses one centralized single sign-on (SSO) control to cover many applications. Which of the following is the BEST course of action when a new application is added to the environment after testing of the SSO control has been completed?
CRISC Exam Question 119
To define the risk management strategy which of the following MUST be set by the board of directors?
CRISC Exam Question 120
What is the BEST recommendation to reduce the risk associated with potential system compromise when a vendor stops releasing security patches and updates for a business-critical legacy system?
