QuestionQ1768

Risk Response and Reporting

Which of the following is MOST important for an IT risk practitioner to update after risk-mitigation action plans have been verified as complete?

  • A Risk rating
  • B Control inventory
  • C Risk impact
  • D Control ownership
Explanation

Once mitigation actions are complete and verified, the residual level of exposure may have changed. Updating the risk rating ensures the risk record reflects the current likelihood and impact after the treatment measures are in place.

Community Discussion

No comments yet. Be the first to start the discussion!