QuestionQ1439

Risk Response and Reporting

A risk practitioner discovers that department managers are attesting to application access reviews without actually conducting those reviews. Which of the following is the risk practitioner’s BEST recommendation?

  • A Redesign and relaunch the review process.
  • B Review role descriptions and job titles.
  • C Implement separation of duties.
  • D Invoke the incident response process.
Explanation

Application access reviews are a preventive and detective access-control process. Attestations made without performing the reviews mean the control is operating ineffectively; redesigning and relaunching the review process addresses the underlying control failure and supports meaningful, accurate attestations.

Community Discussion

No comments yet. Be the first to start the discussion!