QuestionQ1541
GovernanceAn organization implemented a preventive control that locks user accounts after three failed login attempts. This practice has been shown to be ineffective, and a modification to the control-threshold value has been recommended. Who should authorize this threshold change?
- A Control owner
- B IT security manager
- C Risk owner
- D IT system owner
Community Discussion