QuestionQ1418
GovernanceA large organization recently reorganized its IT department and decided to outsource certain functions. What should the IT department’s control owners do?
- A Determine whether risk responses still effectively address risk.
- B Conduct risk classification for associated IT controls.
- C Perform vulnerability and threat assessments.
- D Analyze and update IT control assessments.
Community Discussion